Graves on SOHO Technology

End User Perspective On SOHO Technology
  • rss
  • Home
  • About
    • Contact
    • Advertisers
    • Disclosure
  • Guides & How-To’s
  • Product Reviews
  • Best of…
  • Raves

Local Provisioning For IP Phones

mjgraves | November 2, 2008

9480i bl 270x270 96x96 Local Provisioning For IP PhonesA short while ago VUCs Randulo tweeted that he had recently updated the firmware on his Polycom phones. He said that he did this using a local provisioning server setup temporarily just for the task. If you’re using a hosted IP-PBX then you may not have a suitable server running 24/7/365.

If you don’t run a provisioning server all the time then booting the phones can take a lot longer. On boot-up the phones simply fail to contact the provisioning server and eventually boot using their existing internal settings. But this means waiting through a series of time-outs, which is the principle source of delay.

In the phones core network configuration you can specify how many times the phone will try to contact the provisioning server before giving up, also the retry interval. This can partially mitigate the delay.

Polycom Server Settings Menu

Polycom Server Settings Menu

If you really want to get around this issue the only real solution is to run a provisioning server. It can be local to your network or remotely accessed.

Within my office I sometimes use a local provisioning server to test new firmware. I usually run Solar Winds freeware TFTP server on my Windows desktop. Once I’m happy with the release I upload it to an FTP server at my employers head office in the UK. All my Polycom phones reference this remote server, also the small herd of phones that I manage at various locations across the US.

If you oversee phones at various sites then, like me you may be forced to use remote access to effect central provisioning. Many phones support various connect schemes for provisioning. The most common are TFTP, FTP and HTTP. Some, like our Polycom units, also support secure versions of these protocols.

Securing a remote provisioning server is a serious matter. If that server is hacked then your phones configs could be compromised. With access to your config files a hacker has all your SIP credentials and can easily start making fraudulent use of your hosted PBX account.

Imagine a wily hacker hosting globally accessed conference calls. Costly? To paraphrase one newly-minted American celebrity…You betcha!

So choose your connection scheme wisely. FTP while convenient is not secure. FTP logins are passed in the clear and easily snooped using WireShark. If possible use SFTP or HTTPS instead. Many IP phone manufacturers also provide software tools to encrypt config files themselves, further protecting against hacks.

The security issue adds another dimension to the logic behind maintaining a local provisioning server. If this service is inside your LAN then you can take further steps to lock down unwanted access. Perhaps by restricting access to only IP addresses on your local subnet for example.

Yes, there may be merit in using a local provisioning server, but running hardware just for this purpose seems wasteful. That is, unless we choose that hardware wisely.

More on that matter to follow….

Categories
VoIP
Tags
ftp, http, polycom, provisioning, security, sip, technology, tftp, VoIP, VUC
Comments rss
Comments rss
Trackback
Trackback

« A VoIP Milestone: Friday Oct 31, 2008 VoIP Users Conference Nov 7: HD Conference. Are You Ready? »

Leave a Reply

Click here to cancel reply.

Recent Comments

  • CC on Gigaset SIP/DECT Handsets For 2010: Part 3 – C59H
  • mjgraves on Review: Plantronics Savi Go Bluetooth Headset
  • Heather on Review: Plantronics Savi Go Bluetooth Headset
  • mjgraves on Gigaset SIP/DECT Handsets For 2010: Part 3 – C59H
  • CC on Gigaset SIP/DECT Handsets For 2010: Part 3 – C59H

Making Use Of HDVoice Right Now!

  • Series Introduction
  • HDVoice Using Skype
  • HDVoice Using Gizmo5
  • HDVoice Using SIPGate
  • HDVoice Using OnSIP
  • HDVoice Using IdeaSIP
  • HDVoice Using SIP Sorcery

Making A Difference


Change a life.

VoIP Users Conference

Tags

3G apple Asterisk Astlinux Audio Broadband CATiq cell cellular codec conference cordless DECT digium DSL FWD G.722 gateway Gigaset gsm HD hdvoice headset hp M3 music onsip phone polycom QoS router siemens sip skype SNOM soft phone sprint Squeezebox technology USB Video VoIP VUC wideband wifi

RSS mgraves' shared items in Google Reader

  • World's Fastest Hybrid OK'd For Production
  • AT&T Churn Rate Insanely Low
  • Prepaid, 4G returns Sprint to customer growth
  • 2010 Travel
  • By The Numbers: Chevy Volt vs Nissan Leaf
  • Requiem for the G1
  • It's Here! The FreeSWITCH Book Has Been Published!
  • Asterisk v1.8
  • MIPS Technologies Delivers Reference Implementation for Skype on MIPS-Based™ Devices
  • Jailbreaking and Ripping DVDs Now Legal in One Fell Swoop!

Archives

  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007

Meta

  • Register
  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org
rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox