Solved Yealink T23G - Unable to Autoprovision

Status
Not open for further replies.

CTG2020

Bronze Partner
Basic Certified
Joined
Feb 13, 2020
Messages
30
Reaction score
4
Hello,

We are trying to remote autoprovision an Yealnik T23G on firmware on T23-44.83.0.95 and the 3CX being on 16.0.4.493. We can see the phone under the Events showing the following:

RPS request for Yealink T23G IP Phone of (Extn number) delivered successfully

The 3CX server sits in the cloud (UK) and the phones are sitting outside the country (Pakistan) if that makes any difference.

If you could please assist, thanks!
 
Hi,

You have to give us more details about what you mean by "does not auto-provision".

STUN phones require you to log in before provisioning takes place, and your PBX HTTPS port must be accessible to them.
 
Check you have unticked 'Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)' under options for the extension

Check your blacklist IP's to see if anything has been listed.
 
Hi,

You have to give us more details about what you mean by "does not auto-provision".

STUN phones require you to log in before provisioning takes place, and your PBX HTTPS port must be accessible to them.

I set the autoprovisioning URL via the web interface of the phone > Confirm > Auto Provision > Phone says Configuring then goes back to the Settings screen. No change to any settings.
 
does the phone ask for username and password after the reset?
 
Check you have unticked 'Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)' under options for the extension

Check your blacklist IP's to see if anything has been listed.

Unticked and the public IP of the remote network isn't listed, just two unrelated IPs.
 
does the phone ask for username and password after the reset?

As this is being done remotely I cannot see what the physical handset is doing, I will try and get the user to report back.
 
User has reported that the login after reboot did not show up at all.
 
In this case, I'm fairly certain the phone cannot reach your PBX or the Yealink RPS server.

Firstly, check if your PBX is reachable externally. You can do this by connecting to the management console via FQDN (not via direct IP).
 
In this case, I'm fairly certain the phone cannot reach your PBX or the Yealink RPS server.

Firstly, check if your PBX is reachable externally. You can do this by connecting to the management console via FQDN (not via direct IP).
Thanks for your reply - I can access the FQDN via a machine at the remote site. Also ran a nslookup and this resolved.
 
Have you checked you have the correct mac address of the phone ?
 
  • Like
Reactions: JohnS_3CX
That's great news. Log into the web UI of the phone, and see if it has been populated with a provisioning URL.

I'm guessing this has not happened, because it would have connected to the pbx and would ask for a user and pass.

Also ensure that it has the latest 3CX firmware which would be 44.84.0.95
https://www.3cx.com/support/phone-firmwares/

You can also read here about stun configuration to know exactly what to expect. There are some requirements that need to be met before you can successfully provision it:
https://www.3cx.com/3cxacademy/videos/intermediate/configuring-remote-extensions/
 
Also go to security -> Trusted Certificates on the phone UI and set:

Only Accept Trusted Certificates
to disabled. Have had phone provisioning yealinks remotely when that setting is enabled.
 
We've managed to resolve this. When we changed the IP address of the remote phone and entered the provisioning URL manually and hit autoprovision the provisioning worked straight away. It seems the firewall installed by third party at the the remote site was blocking this provisioning/registration. We suspect this may happen again down the line and will look to implement rules to prevent this from occurring again. Thanks again for all the suggestions and help everyone!
 
Ok if you found that the phone was not receiving the RPS url, then you might have to run a capture on the firewall and see the traffic it was blocking ( probably the IPs that resolve from https://rps.yealink.com )

Glad to hear it was resolved for now at least!
 
Also go to security -> Trusted Certificates on the phone UI and set:

Only Accept Trusted Certificates
to disabled. Have had phone provisioning yealinks remotely when that setting is enabled.
Probably due to end of life models not supporting LE certs, or using custom FQDN certs that Yealink does not include in their trusted CA
 
Status
Not open for further replies.

Forum statistics

Threads
111,938
Messages
589,836
Members
164,821
Latest member
M_R