M cenaly.com
☎️ SIP Phone Setup

☎️ Overview: connecting a phone to the PBX

What credentials the admin panel issues, what to enter into any SIP phone, network and ports, factory reset, list of supported brands

Documentation

SIP Phone Setup

The PBX in your admin panel can deliver calls not only to the browser and the mobile app but also to regular office IP phones: a desk phone at the front desk, a DECT handset in a waiter's pocket, a door station at the service entrance or an adapter for an old analog phone. All of them connect the same way: you create an extension for an employee in the admin panel, get five values and enter them into the phone.

This page covers what is the same for every brand: where to get the credentials, what they mean, what the venue network must allow and when a phone must be reset to factory defaults. Step-by-step guides with the screens of specific phones are in the Guides by brand table below.

Open: Admin panel → Telephony → “Operators” tab (admin.cenaly.com/telephony?tab=extensions).


Credentials#

Credentials are issued per extension, not per phone: every employee (or workplace — “Bar”, “Reception”) has their own internal number and their own account. One extension can be registered on several devices at once — for example, on a desk phone and in the app.

Where to get them:

  1. Telephony → Operators. When you create an operator, the “Extension credentials” window opens right away.
  2. If the window was closed, the password cannot be viewed — we store only its hash. Click “Reset password” next to the operator: a new password appears, the old one stops working.
  3. The same data is available in the employee card (Staff → employee → extension).

The “Copy all settings” button copies the whole window as one text — handy to send to the employee in a messenger. The “Show QR” button is only for the Zoiper and Linphone softphones; desk phones do not understand the QR and are configured with the fields.

Field in the window What it is Where to enter it in the phone
SIP server the address of our PBX: sip.<your domain> on the shared contour or the name of your dedicated machine. Take it from the window, not from memory Server / SIP Server / Registrar / Proxy
Extension number the short number of the employee that colleagues dial Display Name / Label — as the line label; not the login
Username sip-xxxxxxxx-<number> — the long string in full, with the prefix User Name / User ID and Auth Name / Register Name / Authentication ID, if it is a separate field
Password shown once Password / Auth Password
Port 5060 Server Port / Registrar Port
Transport UDP Transport / Protocol

The most common setup mistake is entering the extension number (“101”) into the login field instead of the long login sip-…-101. The phone answers “Register Failed” / “Forbidden”.


What to enter into any phone#

If your device has no page of its own in the table below, these values are enough — they are the same for every brand:

Parameter Value
Server / Registrar / Outbound proxy the address from the window; Outbound proxy — the same address or empty
Port 5060
Transport UDP (TCP is accepted too; TLS and SRTP are not offered by the platform at the moment)
Username / Auth name the login from the window, in both fields
Password from the window
Display name anything: the employee's name or the place (“Bar”)
Codecs G.711 A-law (PCMA), G.711 µ-law (PCMU), G.722 — in this order; the rest can be disabled; G.729 is not needed
DTMF RFC 2833 (sometimes called RFC 4733 or “Out-of-band”)
Registration expiry (Expires) factory value, usually 60–3600 s — no need to change
NAT enable keep-alive if there is such a checkbox; STUN is not needed
Time the venue's time zone, default NTP — otherwise the call history will show the wrong time

There is no “one-click” automatic configuration (auto-provisioning from our server): the phone is configured manually with the fields above or — for a fleet of phones — with your own provisioning server.


Venue network#

The phone only needs outgoing internet access to the PBX address — no port forwarding on the router is required:

  • UDP 5060 — signalling (registration, calls);
  • UDP 10000–20000 — voice (RTP). The shared contour uses 10000–10200, a dedicated machine uses the whole range;
  • UDP 123 — time (NTP), UDP 53 — DNS.

Three things that break telephony most often:

  1. SIP ALG on the router (“SIP Helper”, “SIP Passthrough”). The router “helps” SIP by rewriting packets — the phone registers, but the call drops after 30 seconds or only one side is heard. Disable SIP ALG in the router settings.
  2. Wi-Fi with client isolation. A venue's guest network usually forbids devices from seeing each other — the phone will not find the computer you are configuring it from. Connect the phone to the staff network, preferably by cable.
  3. Power. Most office phones are powered via PoE (802.3af) from the switch; if the switch has no PoE, a power adapter is needed, and it is often sold separately.

How to tell the phone is connected#

  • On the phone the “No Service” / “Unregistered” message disappears, the line shows a registration icon or a name.
  • In the admin panel (Telephony → Operators) the operator gets a green dot, next to it — the time of the last activity and the string the phone identifies itself with (for example Yealink SIP-T31G 124.86.0.130). The status comes from the PBX and refreshes no more than once a minute.
  • Test call: dial a colleague's extension from the phone — or call this extension from another one.
  • Audio check: dial *43 and the PBX plays your own voice back to you. Registration and audio break independently, and the green dot says nothing about audio: see “Checking call quality” below.

Checking call quality#

A registered phone is not yet a phone you can be heard on. Registration and audio travel over different channels and break independently: registration is port 5060, while the voice is a separate RTP stream on ports 10000–20000. The green dot in the admin panel stays lit even when no audio gets through at all.

That is why the PBX has a service number — *43, the echo test. Dial it from the phone you have just set up:

  1. The PBX answers and, after a second, plays a short beep.
  2. Then it plays your own voice back to you: speak into the handset and you hear yourself.
  3. Speak for about ten seconds, not one — otherwise the test has no time to measure itself (why — below).
  4. When you are done, just hang up (or press # — you will hear a second beep).

The test costs nothing, calls nobody and disturbs nobody: it never leaves your PBX. Run it as often as you like, including on a live venue at peak hour.

On a phone with auto-dial, enter *43 and press Send / OK / 📞 — most devices do not start dialling on a star key by themselves.

What the result means#

The beep comes before the echo on purpose: it tests one direction on its own, before the microphone gets involved. Hence four different outcomes — and they are four different faults:

What you hear What it means What to do
A beep, then your own voice Audio flows both ways — the line works Nothing
A beep, but no voice Audio does not reach the PBX from the phone Turn off SIP ALG on the router, check the microphone/headset and speakerphone mode, take the phone out of the guest Wi-Fi
Not even a beep (silence) Audio does not reach the phone from the PBX Allow outbound UDP 10000–20000, turn off SIP ALG, check whether a firewall is dropping the traffic
You hear yourself, but choppy, echoing or late The path exists but is poor Use a cable instead of Wi-Fi, check how loaded the internet link is, disable rate limiting on the router
No beep and the phone does not connect at all The number was never dialled Press Send/OK after *43 — see the note above

Some delay in the echo is normal and equals the round trip to the PBX: under 300 ms it is barely noticeable. If your own voice comes back noticeably late (half a second or more), calls will be uncomfortable for guests — the link is to blame, not the phone.

Numbers instead of impressions#

Your ear honestly says “bad”, but it does not say “how bad” — and a conversation with the carrier or with whoever set up the router has to happen in numbers. So every *43 test lands in the call log (Telephony → Log) as an internal call, with the measurements attached:

  • packet loss (loss) — under 1 % is unnoticeable, above 3 % sounds like gurgling and dropped syllables;
  • jitter (jitter) — the spread in packet arrival times; up to 30 ms the phone smooths it out itself, past 50 ms the audio starts to break up;
  • latency (rtt) — round trip; under 150 ms the conversation feels natural, past 300 ms people start talking over each other. Phones that do not send RTCP report no latency — that is “not measured”, not “zero”;
  • packet counters (rx / tx) — how many arrived and left. A zero in rx is exactly “the PBX cannot hear you”.

Hold the call for at least ten seconds. The PBX takes those numbers not from the audio itself but from RTCP service reports, which the phone and the PBX exchange once every few seconds. A test dropped after a second still tells you the truth about the audio (you heard yourself), but the log will say “not measured” — that is not a fault and not a zero, it means there was nothing to measure yet.

The same log is a ready-made answer for the carrier: date, time, loss and jitter for a specific device.

When to run it#

  • Right after connecting a phone — before the device is handed to an employee. That is the only moment when an audio fault is caught for free rather than by a guest complaint.
  • After any network work — a new router or carrier, the phone moved to another socket or network, a firmware update.
  • When someone complains about quality — start with *43 from that same device: in a minute it separates “bad line on our side” from “bad line on the caller's side”.

Factory reset#

A reset is needed more often than it seems, and every brand page describes it separately (from the device and from the web UI). When there is no way around it:

  • The phone was bought second-hand or came from a previous provider. Someone else's accounts remain inside, and above all — the auto-provisioning server address of the previous provider: the phone will dutifully download the old configuration and overwrite yours at every reboot. The symptom is “I set it up, it worked, next morning it does not register again”.
  • The web UI administrator password is forgotten. It cannot be recovered, only reset.
  • The phone behaves strangely after a firmware update or experiments with settings — a reset is cheaper than an investigation.

What gets erased: accounts, network settings (static IP, VLAN), language, directories and call history. The firmware stays. After the reset: language → time zone → network (if not DHCP) → account.


Guides by brand#

One page — one family of phones with a common web UI. Each page covers: how to find the IP, the factory password, the account screen with a screenshot from the manufacturer's documentation, verification, factory reset and the typical errors of that brand.

Family Models Guide
☎️ Yealink T1x–T5x and CP9xx SIP-T19(P) E2, SIP-T21(P) E2, SIP-T23G, SIP-T27G, SIP-T30/T31/T33/T34W, SIP-T41S/T42S/T43U/T46U/T48U, SIP-T53/T53W/T54W/T57W/T58W, T7x/T8x, CP920/CP925/CP965 Open
📡 Yealink W5x/W6x/W7x (DECT) W52P, W53P, W56P, W60B, W70B, W73P, W76P, W79P, W80DM, W90DM, W53H, W56H, W73H, W78H Open
☎️ Grandstream GRP26xx / GXP / WP8xx GRP2601/2602/2603/2604, GRP2612/2613/2614/2615/2616, GRP2624/2634/2636, GRP2650/2670, GXP1610/1615/1620/1625/1628/1630, GXP1760/1780/1782, GXP2130/2135/2140/2160/2170, WP810/820/822/825 Open
📡 Grandstream DP7xx (DECT) DP750, DP752, DP755, DP720, DP722, DP730, DP715/DP710 (legacy) Open
🔌 Grandstream HT80x/HT81x (ATA) HT801, HT802, HT812, HT814, HT818, HT813 (FXS+FXO) Open
☎️ Fanvil X / V / H (desk and hotel phones) X1S/X1SP/X1SG, X3S/X3SP/X3U/X3SG, X4/X4U/X4G, X5S/X5U, X6/X6U, X7/X7C/X7A, X210/X210i, V62/V64/V65, H2U/H3/H5/H5W, W611W Open
☎️ Panasonic KX-HDV / KX-TGP / KX-UT KX-HDV100, KX-HDV130, KX-HDV230, KX-HDV330, KX-HDV430, KX-TGP500/550/600, KX-TPA60/65, KX-UT113/123/133/136/248 Open
☎️ Cisco SPA / MPP 6800–8800 / ATA 19x SPA301/303, SPA501G/502G/504G/508G/509G/512G/514G, SPA525G2, CP-6821/6841/6851/6861/6871, CP-7811/7821/7841/7861, CP-8811/8841/8845/8851/8861/8865, ATA 191/192 Open
☎️ Snom D-series and M-series DECT D120/D140/D150, D315/D335/D345/D375/D385, D712/D715/D717/D735/D765/D785, D812/D815/D862/D865, HD100/HD101/HD350W, M300/M400/M700/M900, M25/M65/M85/M90 Open
☎️ Poly (Polycom) VVX / Edge E / Trio / OBi VVX 101/150/201/250, VVX 301/311/350/401/411/450, VVX 501/601, Edge E100/E220/E300/E350/E400/E450/E500/E550, Trio 8300/8500/8800, OBi 200/300 Open
📡 Gigaset N670 / N870 IP PRO and DECT handsets N530 IP PRO, N610 IP PRO, N670 IP PRO, N770 IP PRO, N870/N870E IP PRO, R700H/S700H/SL800H/SL850H PRO, Maxwell C Open
☎️ D-Link DPH-150S / DPH-400S DPH-120S/120SE, DPH-150S/150SE, DPH-400S/400SE Open
☎️ Htek UC9xx / UC8xx UC902/UC902S/UC902G/UC903, UC912/UC921, UC923/UC924/UC926, UC842/UC862 Open
☎️ Escene ES / WS ES220/ES270/ES280/ES290/ES292, ES330/ES380, ES410/ES620, WS330 Open
☎️ Flyingvoice FIP1x, P series and FTA (ATA) FIP10/FIP10P/FIP11C/FIP11CP, FIP12WP/FIP13G/FIP14G/FIP15G Plus/FIP16 Plus, P10/P11 (P/G/W/S/U), P20/P21/P22/P23, FTA1101/FTA5102E2/FTA5111, G504/G508 Open
☎️ Eltex VP-12/15/17/20/30 and TAU (ATA) VP-12/VP-12P, VP-15/VP-15P, VP-17P, VP-20/VP-20P, VP-30P/VP-30P-WB, TAU-1M.IP/TAU-2M.IP/TAU-4M.IP/TAU-4.IP, TAU-8N.IP/TAU-16.IP/TAU-24.IP/TAU-32M.IP Open
☎️ QTECH QVP and QIPP QVP-80P/QVP-95P/QVP-95PR, QVP-100/QVP-100P/QVP-200/QVP-200P, QVP-300P/QVP-300PR/QVP-400PR, QVP-500PR/QVP-600P/QVP-600PR, QIPP-100/100P, QIPP-225PG/300PG/401PG/425PG/475PG, QIPP-800PG V2/QIPP-1000PG Open
🔌 Yeastar TA and Dinstar DAG gateways (ATA) Yeastar TA100/TA200, Yeastar TA400/TA800, Yeastar TA1600/TA2400/TA3200, Yeastar TA410/TA810 (FXO), Dinstar DAG1000-1S/2S/4S/8S, Dinstar DAG2000-16S/24S/32S Open
☎️ Alcatel-Lucent 80x8s CE, Myriad and Halo 8008/8008G CE, 8018 CE, 8058s/8068s/8078s CE, Myriad M3s/M5s/M7s/M7s Pro/M8, Halo H3G/H6 Open
☎️ Avaya J100 (Open SIP) J129, J139, J159, J169, J179, J189 Open
☎️ AudioCodes 400HD / C450HD 405HD, 420HD, 430HD, 440HD, 445HD, 450HD, C450HD/C455HD Open
☎️ Mitel 6800 / 6900 (SIP) 6863i/6865i/6867i/6869i/6873i, 6920/6930/6940/6970 Open
☎️ Unify OpenScape CP / OpenStage (SIP) CP100/CP200/CP205, CP400, CP600/CP600E/CP700/CP700X, OpenStage 15/20/40/60/80 SIP, OpenScape Desk Phone IP 35G/55G Open
🚪 Fanvil i-series, Akuvox and 2N door phones Fanvil i10/i10S/i10V, Fanvil i20S/i21/i23, Fanvil i30/i31/i32V/i33V, Fanvil i51W/i52W/i53W/i56A/i61/i62/i63/i64, Akuvox R20/R26/R27/R28/R29, Akuvox E11/E12/E16/E18, Akuvox A01/A02/A05, 2N IP Verso/Solo/Base/Force/Uni/Style Open
☎️ Karel IP1xx (Turkey) IP111/IP112/IP113/IP116, IP131/IP132G/IP136/IP138, IP1131/IP1141, IP202P/IP203G/IP212G, IP310/IP313G Open
☎️ Sangoma P-Series and D-Series P310/P315/P320/P325/P330/P370, D40/D45/D50/D60/D62/D65/D70/D80 Open

Softphones (Zoiper, Linphone, MicroSIP, the smartphone app) are configured with the QR code or the same fields — they do not need a separate page.


If it does not register#

In order, from the most common to the rarest — regardless of the brand:

  1. The login was not entered in full. It must be sip-…-<number>, not the number itself. Check both fields — User Name and Auth Name.
  2. The password is outdated. Someone clicked “Reset password” — the old one no longer works. Do not guess, issue a new one.
  3. Wrong server address. A venue with a dedicated machine has its own address, not the shared sip.<domain>. Copy it from the window.
  4. TCP transport with “silence”. If the phone does not even get a rejection — switch to UDP.
  5. Network. The router blocks UDP 5060, SIP ALG is on, the phone is on the guest Wi-Fi.
  6. Foreign provisioning. Settings “change by themselves” — see “Factory reset”.
  7. Wrong firmware. Devices with Microsoft Teams / Skype for Business / Zoom firmware (Yealink, Poly, AudioCodes and Cisco have such variants) do not register on a regular SIP PBX until the SIP firmware is loaded. The model looks the same from the outside — check the boot screen.

If this did not help — the brand page lists the messages of that specific device and what they mean.


FAQ#

How do I check the line without calling real people?#

Dial *43 from the phone and the PBX plays your own voice back to you (echo test). It tests the audio rather than the registration, costs nothing and disturbs nobody: the call never leaves your PBX. What each outcome means is covered in “Checking call quality”.

Which phone should I buy?#

For the front desk and the office — any desk SIP phone from the table; mass-market and inexpensive are Yealink T31/T33, Grandstream GRP2601/2602, Fanvil X3/X4. For waiters and the floor — a DECT base with handsets (Yealink W70B, Grandstream DP752, Gigaset N670): one base covers the floor, the handsets stay in pockets. For a hotel — hotel models without extra buttons (Fanvil H series, Snom HD1xx). For an old analog phone — an ATA adapter (Grandstream HT801). The main thing: the model must support open SIP; “Teams-only” and “Zoom-only” devices will not work.

Can one extension be put on two phones?#

Yes: one account registers on several devices at the same time (for example, a desk phone and the app), the call reaches all of them. If you need calls to ring in turn or simultaneously for different people — that is a ring group in “Telephony → Ring groups”, not a shared account.

An employee got a new extension number — does the phone need reconfiguring?#

Yes. The login contains the number, so a new number means a new account and a new password. Rewrite the login (in both fields) and the password in the phone.

Do I need a static IP or port forwarding?#

No. The phone establishes the connection to the PBX from inside your network; no incoming connections from outside are required. Port forwarding on the router is unnecessary and harmful.

Is there automatic configuration by MAC address (provisioning)?#

No. The platform does not run a provisioning server: the phone is configured with the fields from the “Extension credentials” window. For a fleet of dozens of devices use your own provisioning server — the brand pages have a collapsed “Fleet provisioning” block with parameter names.

Is encryption (TLS/SRTP) supported?#

Not at the moment: registration goes over UDP/TCP to port 5060, voice is plain RTP. Do not enable TLS/SRTP in the phone “just in case” — it will not register.


Was this article helpful?