Graves On SOHO VoIP

End User Perspective On IP Telephony In The Home Office
  • rss
  • Home
  • About
  • Guides & Reviews
  • Raves
  • Personal Blog

Local Provisioning For IP Phones

mjgraves | November 2, 2008

9480i bl 270x270 96x96 Local Provisioning For IP PhonesA short while ago VUCs Randulo tweeted that he had recently updated the firmware on his Polycom phones. He said that he did this using a local provisioning server setup temporarily just for the task. If you’re using a hosted IP-PBX then you may not have a suitable server running 24/7/365.

If you don’t run a provisioning server all the time then booting the phones can take a lot longer. On boot-up the phones simply fail to contact the provisioning server and eventually boot using their existing internal settings. But this means waiting through a series of time-outs, which is the principle source of delay.

In the phones core network configuration you can specify how many times the phone will try to contact the provisioning server before giving up, also the retry interval. This can partially mitigate the delay.

Polycom Server Settings Menu

Polycom Server Settings Menu

If you really want to get around this issue the only real solution is to run a provisioning server. It can be local to your network or remotely accessed.

Within my office I sometimes use a local provisioning server to test new firmware. I usually run Solar Winds freeware TFTP server on my Windows desktop. Once I’m happy with the release I upload it to an FTP server at my employers head office in the UK. All my Polycom phones reference this remote server, also the small herd of phones that I manage at various locations across the US.

If you oversee phones at various sites then, like me you may be forced to use remote access to effect central provisioning. Many phones support various connect schemes for provisioning. The most common are TFTP, FTP and HTTP. Some, like our Polycom units, also support secure versions of these protocols.

Securing a remote provisioning server is a serious matter. If that server is hacked then your phones configs could be compromised. With access to your config files a hacker has all your SIP credentials and can easily start making fraudulent use of your hosted PBX account.

Imagine a wily hacker hosting globally accessed conference calls. Costly? To paraphrase one newly-minted American celebrity…You betcha!

So choose your connection scheme wisely. FTP while convenient is not secure. FTP logins are passed in the clear and easily snooped using WireShark. If possible use SFTP or HTTPS instead. Many IP phone manufacturers also provide software tools to encrypt config files themselves, further protecting against hacks.

The security issue adds another dimension to the logic behind maintaining a local provisioning server. If this service is inside your LAN then you can take further steps to lock down unwanted access. Perhaps by restricting access to only IP addresses on your local subnet for example.

Yes, there may be merit in using a local provisioning server, but running hardware just for this purpose seems wasteful. That is, unless we choose that hardware wisely.

More on that matter to follow….

Categories
VoIP
Tags
ftp, http, polycom, provisioning, security, sip, technology, tftp, VoIP, VUC
Comments rss
Comments rss
Trackback
Trackback

« A VoIP Milestone: Friday Oct 31, 2008 VoIP Users Conference Nov 7: HD Conference. Are You Ready? »

Leave a comment

You can use these tags : <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

My Tweets

  • It's 100+ degrees yet again. There's only one answer. Mas margarita's por favor! Frozen with salt!
  • This weeks VUC call was interesting. Might drive me to roll up my sleeves and get into some code, first time in a long while. http://vuc.me
  • @e4VoIP The Konfetel device arrived. Many thanks. Hoping that it makes my UK guys happy. At very least I get to give it a try in depth.
  • Stella made blueberry muffins this morning. Going down nicely with fresh coffee. Yum!
  • @maximCH what does the reverse hold script do? Does it monitor a call for a change in media the ring back to me? That'd be cool.

Recent Comments

  • mjgraves on Gigaset Gear Starting To Hit US Retailers
  • Jason on Gigaset Gear Starting To Hit US Retailers
  • mjgraves on Making Use of Wideband Voice Right Now!: SIPGate
  • Florian on Making Use of Wideband Voice Right Now!: SIPGate
  • Chris Melville on DECT Wars: snom m3 vs Siemens S685IP

Recent Posts

  • New Jabra Headsets
  • HD Connect Gets Rolling
  • David Rowe On Royalty Free Codecs
  • Gigaset Gear Starting To Hit US Retailers
  • Making Use of Wideband Voice Right Now!: SIPGate

Gallery

Open Peak Phone Design Variations

Make a difference.


Change a life.

VoIP Users Conference

RSS From My Personal Blog

  • Pixel Power On The Cover Of Broadcast Engineering Magazine…sorta
  • Three Geeks In Pictures
  • Office Renovation Underway
  • A Great Overview Of Social Media For Geeks
  • Kites At TED: Saul Griffith

Say What?

grep..grep..grep… (Frog with UNIX stuck in its’ throat)

Tags

Asterisk Astlinux Audio blog Broadband cell cellular conference cordless DECT DSL firmware FWD G.722 gateway gsm HD hdvoice home Houston hp ip m0n0wall M3 music onsip phone polycom QoS review router siemens sip skype SNOM soft phone Squeezebox T5700 technology Traffic Shaping Video VoIP VUC wideband wifi

Archives

  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007

Meta

  • Register
  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org
rss Comments rss valid xhtml 1.1 design by jide powered by Wordpress get firefox

All content © copyright 2009 Michael Graves