Graves on SOHO Technology

End User Perspective On SOHO Technology
  • rss
  • Home
  • About
    • Contact
    • Advertisers
    • Disclosure
  • Guides & How-To’s
  • Product Reviews
  • Best of…
  • Raves

Local Provisioning For IP Phones

mjgraves | November 2, 2008

9480i bl 270x270 96x96 Local Provisioning For IP PhonesA short while ago VUCs Randulo tweeted that he had recently updated the firmware on his Polycom phones. He said that he did this using a local provisioning server setup temporarily just for the task. If you’re using a hosted IP-PBX then you may not have a suitable server running 24/7/365.

If you don’t run a provisioning server all the time then booting the phones can take a lot longer. On boot-up the phones simply fail to contact the provisioning server and eventually boot using their existing internal settings. But this means waiting through a series of time-outs, which is the principle source of delay.

In the phones core network configuration you can specify how many times the phone will try to contact the provisioning server before giving up, also the retry interval. This can partially mitigate the delay.

Polycom Server Settings Menu

Polycom Server Settings Menu

If you really want to get around this issue the only real solution is to run a provisioning server. It can be local to your network or remotely accessed.

Within my office I sometimes use a local provisioning server to test new firmware. I usually run Solar Winds freeware TFTP server on my Windows desktop. Once I’m happy with the release I upload it to an FTP server at my employers head office in the UK. All my Polycom phones reference this remote server, also the small herd of phones that I manage at various locations across the US.

If you oversee phones at various sites then, like me you may be forced to use remote access to effect central provisioning. Many phones support various connect schemes for provisioning. The most common are TFTP, FTP and HTTP. Some, like our Polycom units, also support secure versions of these protocols.

Securing a remote provisioning server is a serious matter. If that server is hacked then your phones configs could be compromised. With access to your config files a hacker has all your SIP credentials and can easily start making fraudulent use of your hosted PBX account.

Imagine a wily hacker hosting globally accessed conference calls. Costly? To paraphrase one newly-minted American celebrity…You betcha!

So choose your connection scheme wisely. FTP while convenient is not secure. FTP logins are passed in the clear and easily snooped using WireShark. If possible use SFTP or HTTPS instead. Many IP phone manufacturers also provide software tools to encrypt config files themselves, further protecting against hacks.

The security issue adds another dimension to the logic behind maintaining a local provisioning server. If this service is inside your LAN then you can take further steps to lock down unwanted access. Perhaps by restricting access to only IP addresses on your local subnet for example.

Yes, there may be merit in using a local provisioning server, but running hardware just for this purpose seems wasteful. That is, unless we choose that hardware wisely.

More on that matter to follow….

Categories
VoIP
Tags
ftp, http, polycom, provisioning, security, sip, technology, tftp, VoIP, VUC
Comments rss
Comments rss
Trackback
Trackback

« A VoIP Milestone: Friday Oct 31, 2008 VoIP Users Conference Nov 7: HD Conference. Are You Ready? »

Leave a Reply

Click here to cancel reply.

Recent Comments

  • mjgraves on The iPhone In My Office
  • mjgraves on Blogging In Transition: A Host Of Issues – Act One
  • mjgraves on Gigaset SIP/DECT Handsets For 2010: Part 6 – SL78H
  • Larry C on Blogging In Transition: A Host Of Issues – Act One
  • Vince on Gigaset SIP/DECT Handsets For 2010: Part 6 – SL78H

Making Use Of HDVoice Right Now!

  • Series Introduction
  • HDVoice Using Skype
  • HDVoice Using Gizmo5
  • HDVoice Using SIPGate
  • HDVoice Using OnSIP
  • HDVoice Using IdeaSIP
  • HDVoice Using SIP Sorcery

Making A Difference


Change a life.

VoIP Users Conference

Tags

3G A580IP apple Asterisk Astlinux Audio blog Broadband CATiq cellular codec conference cordless DECT digium DSL FWD G.722 gateway Gigaset gsm HD hdvoice headset hp M3 music onsip phone polycom QoS siemens sip skype SNOM soft phone sprint Squeezebox technology USB Video VoIP VUC wideband wifi

RSS mgraves' shared items in Google Reader

  • Use FreeSWITCH To Make Free Calls With gmail Voice Interface!
  • Video far from Clear
  • Toshiba Folio 100 Android tablet breaks cover
  • First look at the HP Mini 5103 – Video
  • T-Mobile Shows the G2 Off Themselves
  • HP introduces Mini 5103 business class netbook with Atom N550 processor
  • Acrobits iPhone SIP app Groundwire on sale today
  • TweedleD Back From the Dead Using Twitter OAuth
  • Gigaset DX800A – the new all-round phone for professionals sets high standards
  • will gmail calling make headset calling more comonplace

Archives

  • ▼2010 (118)
    • ▼September (1)
      • Blogging In Transition: A Host Of Issues – Act Three
    • ▶August (15)
    • ▶July (16)
    • ▶June (17)
    • ▶May (15)
    • ▶April (17)
    • ▶March (16)
    • ▶February (8)
    • ▶January (13)
  • ▶2009 (229)
    • ▶December (16)
    • ▶November (15)
    • ▶October (13)
    • ▶September (24)
    • ▶August (23)
    • ▶July (18)
    • ▶June (16)
    • ▶May (17)
    • ▶April (22)
    • ▶March (18)
    • ▶February (21)
    • ▶January (26)
  • ▶2008 (297)
    • ▶December (26)
    • ▶November (23)
    • ▶October (24)
    • ▶September (26)
    • ▶August (21)
    • ▶July (32)
    • ▶June (24)
    • ▶May (16)
    • ▶April (14)
    • ▶March (29)
    • ▶February (22)
    • ▶January (40)
  • ▶2007 (14)
    • ▶December (8)
    • ▶November (5)
    • ▶October (1)

Meta

  • Register
  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org
rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox