M cenaly.com
☎️ Telephony: Your Own PBX

☎️ Telephony: your own PBX

Your venue's own PBX in the panel: lines and numbers, extensions and ring groups, routing and schedules, call recording and analytics, the AI receptionist and agent assist, phones and gateways — an overview and where to start

Documentation

Telephony: your own PBX

In most venues the phone lives apart from everything else: the number is at the carrier, the handset is on the counter, and who called is remembered only by whoever picked up. The Telephony section turns that into a working tool: the location gets its own PBX — a phone exchange that answers calls to your number, distributes them to the team by your rules, records conversations and hands them over for analysis.

Open: Admin panel → Telephony (admin.cenaly.com/telephony). The section is switched on by the Telephony card in the app store — it is hidden by default.


What "your own PBX" means#

The PBX is dedicated to your location. It is a separate cloud machine with its own static IP address and its own connection address: nobody else's voice passes through it, the carrier accounts are yours, and we neither issue nor resell numbering. A single shared server for everyone is no longer offered to new locations at all.

Item How it works
Ordering the server a button on the "Server" tab. The service is paid and billed monthly — the confirmation before creation says so plainly
Capacity a ladder of presets labelled with the number of simultaneous conversations; a capacity change happens with no downtime, and you can wait until no calls are active
Load CPU and network charts for 1 hour / 24 hours / 7 days right in the server card
Settings save themselves; there is no "Save" button in the section. Every block has a "clock" icon — the history of its settings, with rollback
Where it physically runs the cloud is chosen by the country of the location; Russian locations are served only in Yandex Cloud (cenaly.ru)

At the top of the section there is the "Before the first call" checklist: five steps from zero to an answered and recorded test call (create the location's SIP account → connect an inbound line → set up routing → issue at least one extension → switch recording on). Every unfinished step is a link to the right tab; once everything is done, the checklist collapses into a single green line.


Where to start#

The order below is also the path of a call — from the outside in:

# Step Where In detail
1 Get a number: a provider's SIP trunk or a gateway with a SIM card Trunks and connections → Lines provider's number, GSM gateway
2 Issue extensions to the team Operators below
3 Connect phones and softphones credentials from the extension window setting up SIP phones
4 Set up inbound routing Routing, Ring groups below
5 Switch on outbound calls if the team calls out Outbound below
6 Switch on recording Recording below

Step 1. The number: provider or gateway#

The inbound number is yours, under your own contract with a carrier. There are three sources, and they add up:

Source How it connects What matters
A provider's SIP trunk the "Trunks and connections" tab: name, SIP host, port, transport, mode (REGISTER — the PBX registers with the carrier, or IP auth — the carrier sends calls to our IP), username and password. The "Check connection" button runs a live probe the number itself is added as a line on the "Lines" tab, and the line has a working "Accepts calls" switch. Full guide — connecting a provider's number
A gateway with a SIM card, a landline or ISDN the gateway registers on our PBX as an extension and dials an internal number itself when a call arrives the gateway does pass the caller's number on — it shows on the handset, in the log and in the "Calls" recording. Such a call has no line, so routing rules do not apply to it. Full guide — GSM gateway and landline
The built-in web-call line nothing to connect: the guest speaks from the browser one line, no number needed — calls from your website

The number of trunks and lines is not capped — it is your machine and your carrier accounts; the overall limit of the PBX settings list is 500 entries.


Step 2. Extensions for the team#

The Operators tab holds internal numbers. There are two kinds: our extension (an account on our PBX that a phone or softphone connects to; you choose the number yourself — 2–6 digits, your own venue numbering, with no cap on how many you create) and an inherited carrier number — behind it there is a number the person already has: an extension on someone else's PBX, a mobile or a landline. No password is issued for it, and the call reaches the person through the chosen channel.

Feature What it does
Assign to an employee the number shows up in the employee card, and dismissal revokes the extension automatically across all locations
"Hand out to the team…" issues numbers in bulk filtered by job title; whoever already has one is skipped
Credentials the password is shown once: copyable fields, "copy all settings" as text and a QR code for Zoiper and Linphone. Lost it — "Reset password"
Full number duplication a number that lives at the carrier is set up so that the person's phone registers with us, while the call still reaches their old handset at the provider
Equipment and logs the row shows what the employee connects with ("Yealink T31G", "Zoiper"), greyed out if the device is off. A click opens the device card: uptime over 24 hours / 7 / 30 days, connection history, calls and the line check

Step 3. Phones and softphones#

The same five values (server, username, password, port 5060, UDP transport) go into any device: a desk phone, a waiter's DECT handset, a door intercom, an adapter for an old analogue phone, or a softphone on a computer or a smartphone. One extension can be registered on several devices at once.

The full guide is setting up SIP phones: where to get the credentials, what the venue network must allow (outbound UDP 5060 and 10000–20000, SIP ALG switched off on the router), when a phone has to be factory reset, and step-by-step instructions for 26 device families. It also covers the *43 echo test: you dial it, you hear your own voice, and the call log gets packet loss, jitter and latency for that exact handset.

Employees add their own personal accounts themselves: Settings → "My SIP accounts" (admin.cenaly.com/settings?tab=sip-accounts) — these are their registrations on other systems (at a carrier, on an office PBX); they are private, they sync into the Cenaly apps on that person's devices, and they are not part of the location's PBX settings (see settings).


Step 4. Inbound routing#

The Routing tab holds the rules of "who to ring when a call arrives". Rules are checked top to bottom and the first match wins; their order is the priority, and you reorder them with arrows.

Rule axis Options
Which number was called chips grouped into "Lines (numbers)" and "Providers (trunks)"; several targets can be selected — any one of them matches
When days of the week and a time window in the location's time zone
Who is calling caller number prefix
Who answers everyone who has an extension · selected employees as name chips · a ring group · an AI assistant by name (phone consultant, receptionist, any voice bot) · an external number
If nobody answered a no-answer message, voicemail, an AI assistant, another group

The ring plan grid is a table where a row is a participant and a column is 5 seconds: "for the first 10 seconds the host rings, from the 10th the manager joins, from the 20th the host goes quiet". Cells are painted by dragging the mouse. The last row is the AI: it does not ring, it answers, so it starts where the last human stopped ringing.

Below the list of rules is the default answer: what happens when no rule matched (a greeting, voicemail, a bot). The same block holds the "this call is being processed" notice with a language choice and your own text — in a number of countries such a warning is mandatory, so it is on by default.

Ring groups (their own tab) are internal numbers (issued from 700) with their own distribution: a ring plan grid, a plain "all at once / one after another" hunt, or a queue with hold music, position announcements and a waiting cap. A member has a "Rings" toggle, personal working hours, a pause (the employee sets it from the handset: *71 — away, *72 — back) and their own hold music; the "Ring the person the guest already spoke to first" toggle tries the familiar employee for a few seconds. Three doors lead into a group: dialling its number from a phone, a routing rule, and a transfer by the AI receptionist. Next to them are conference rooms (the "Conferences" tab): extensions 600–649 with a PIN and video — dial the number from any registered device and you are in the shared conversation.


Step 5. Outbound calls#

Outbound calls are off by default, and switching them on is confirmed with plain wording about money: the call goes out over your trunk and the bill comes from your carrier. The "Outbound" tab decides which line a call dialled by an employee leaves from — three levels, in the order they are resolved:

  1. Smart rules "dialled-number pattern → line": digits plus X (any digit), N (2–9), Z (1–9) and a trailing dot for "any number of digits". A rule can be narrowed to specific employees, strip or prepend digits before sending them to the carrier, and override the number shown to the callee;
  2. the employee's personal line — "one each";
  3. the shared default line.

Anti-fraud is always on: a cap on simultaneous outbound calls per location and per employee, limits on dialled length, an unconditional block on premium and satellite destinations (no setting removes it) and a daily cap on talk minutes (no cap by default). At 80 % of the cap, at its exhaustion and on suspicious night traffic the PBX posts an alert with a push into the work chat — a hijacked account is recognised by minutes burnt overnight, not by the carrier's invoice at the end of the month.


Step 6. Call recording and "Calls"#

The Recording tab: switch it on, choose the scope (all calls / inbound only / operator calls only) and decide whether recordings older than N days are deleted. By default recordings are kept with no limit — you set the period yourself, and there is no upper bound.

A recorded conversation lands not only in the telephony player but also in the Calls section (admin.cenaly.com/calls) — the hub for recordings: uploading and receiving files, a table with filters and saved views, speech recognition, AI analysis of the conversation, tags, metrics, rules and automations, search and linking to an order. Retention for the recording store and for the "Calls" section is configured separately. A detailed article about "Calls" is being prepared.


The AI receptionist, agent assist and phone consultant#

Telephony is the infrastructure three AI surfaces run on. They are configured in their own sections, while the PBX only decides "who answers the call". Detailed articles on the receptionist and the agent assist are being prepared.

Surface What it does Where
AI receptionist a robot answers inbound calls on behalf of the venue: persona and tone, schedule, questionnaires (reservation, message, request), rules for transferring to the team, permitted actions, anti-spam and a text simulator. It answers from the knowledge base, and the "you are speaking to an AI" disclosure cannot be switched off where it is mandatory admin.cenaly.com/secretary
Agent assist during a conversation the employee gets answer cards from the knowledge base on top of a live transcript; no language model is called during the call — a pre-compiled pack does the work admin.cenaly.com/call-assist
Phone consultant an AI assistant as an ordinary row in the extension list: you can give it an internal number, put it into the "if nobody answered" rule or into the last row of the ring plan grid admin.cenaly.com/telephony?tab=extensions

Calls from your website#

Two free widgets run on the same PBX and arrive through the same inbound rules: calls from your website — a handset button, the guest speaks straight from the browser with no number to dial and no app to install; callback — the guest leaves a number, the PBX dials it and connects them to the venue, with retries on no-answer and a night queue with a morning round. You only pay for your own telephony — the widgets themselves are free.


Tabs of the Telephony section#

Tab What is there
Overview the "Before the first call" checklist, the location's SIP account summary, the "Check connection" button, the outage e-mail toggle, the PBX connection history
Lines inbound numbers, the "Accepts calls" switch, the default hold music and the built-in web-call line
Trunks and connections provider trunks as one row each (state, registration, check), editing credentials in place, the "Full number duplication" subsection and the catalogue of pairings with carriers, external PBXs and gateways
Routing inbound rules, the ring plan grid and the default answer underneath them
Outbound "number → line" rules, personal and shared lines, the master switch and the limits
Operators employee extensions, inherited numbers, equipment tags, device logs, AI assistants as rows
Ring groups group numbers (from 700): distribution, queue, members with personal hours, conditional variants
Conferences rooms 600–649: name, PIN, video, participant cap
Recording switch, recording scope, retention period
Server the PBX machine and the bridge on a PC, capacity and load, advanced SIP settings, trunk diagnostics (a capture of the SIP exchange)

The same settings are available as a single scroll from "Calls" (admin.cenaly.com/calls?tab=settings&set=pbx) — so that the PBX can be managed from where the recordings are listened to.


Wire diagnostics (SIP trace)#

When "the call does not go through" while every setting looks right, arguing is pointless — you need to see what our PBX and the carrier actually said to each other. That is what the "Wire diagnostics (SIP trace)" block on the "Server" tab is for.

SIP is the signalling that sets a call up: REGISTER (a phone or a trunk announcing itself), INVITE (someone is calling), response codes (200 OK, 401, 403, 488…) and the SDP block inside, which names the codecs and the addresses for audio. The trace is a transcript of that exchange as the server sees it.

How to capture one:

  1. Telephony → "Server" → the "Wire diagnostics" block. "Record for 15 minutes" opens a recording window (an "open until …" badge appears next to it; the cap is 2 hours).
  2. While the window is open, place that very call — the trace only shows what happened while the window was open.
  3. "Refresh" pulls in the latest tail of the exchange; the lines appear in the dark box below the buttons. "The PBX has not published the exchange yet" means "give it a minute" — the machine publishes the tail on its own cycle, it is not an error.
  4. "Stop now" closes the window early; it closes by itself in any case — the exchange contains caller numbers, that is personal data, so "switch it on and forget" is deliberately impossible here.

Worth knowing about the contents: the values of the authorization headers (Authorization, WWW-Authenticate) are stripped from the lines — there is no password in the trace; what you see is the tail of the exchange, and if the beginning did not fit, it says so right above the text. On a dedicated PBX the exchange is, in addition, recorded continuously and kept on the machine for 24 hours, so a complaint like "an hour ago the call had no audio" can still be looked into after the fact — there is no interval picker in the panel yet, so support retrieves the slice for the hour in question.

How to read the typical pictures:

What the exchange shows What it means
REGISTER401/407, then a repeated REGISTER200 OK a normal two-step registration (digest challenge) — this is how it should look
REGISTER403 Forbidden (or 404) the carrier refused: wrong username, password or domain — and with IP authorization, the call came from the wrong address
no response at all, 408 Request Timeout packets are not arriving: wrong port or transport, a filter on your network or the carrier's side, or with IP auth our address is not whitelisted
INVITE488 Not Acceptable Here (or 606) the codecs did not match: our PBX speaks G.711 A-law, µ-law and G.722, and does not support G.729, Opus or AMR
INVITE200 OK, but there is no audio or only one side is heard signalling went through, the problem is the audio stream (RTP): SIP ALG on the router, UDP 10000–20000 closed, or NAT — the SDP block (c=, m=audio) shows which address each side announced
INVITE480/486/603 the far end is unavailable, busy or declined — an answer from the other side, not a fault
INVITE503 Service Unavailable the carrier refused: channels, balance or the destination on their side
BYE right after the answer one of the sides is tearing the session down — usually session timers or keep-alive on an intermediate node
a pause between INVITE and the first response you can see at which step the PBX is waiting for the carrier — the very "silence before an outbound call"

What to send to support. There is no file export in the panel: select the text in the trace box and attach it to your message (or a screenshot), naming the time of the call and the number — that is enough for a diagnosis. If you prefer, switch on "Support access" in settings and an agent will look at the exchange themselves; how to write to support — here.

⚠️ Diagnostics are available on a dedicated PBX only: the Asterisk logger command is global, so on a shared server it would capture other tenants' exchanges. On the shared tier switching it on is refused.


Limitations#

  • Outbound calls through a gateway are not there yet. A gateway with a SIM card or a landline brings calls INTO the PBX; you cannot dial out through it from the panel — an outbound rule can only point to a line or a provider trunk. And routing rules do not apply to calls from a gateway: such a call has no line, so the gateway's own settings must point straight at a group or an employee number.
  • There is no encryption for provider trunks: a trunk works over UDP or TCP, and TLS and SRTP are not available for it. For phones, encryption is enabled by an advanced setting of the dedicated machine (which issues the certificate itself) — that part has not yet been verified on a live fleet of handsets.
  • Some features only exist on the dedicated machine: ring groups and the queue, conference rooms, call recording, two-sided ringing for a duplicated number, and the SIP exchange capture. A PBX raised on your own PC through the bridge, and the remnants of the shared server, do not execute them; outbound calls and routing rules are likewise assembled by whoever holds the trunks.
  • Codecs — G.711 A-law, µ-law and G.722; G.729, Opus and AMR are not supported. There is no phone auto-provisioning by MAC address — devices are configured with the fields from the extension window, or by your own provisioning server.
  • Countries where the PBX is unavailable (a local licence is required or sanctions apply): Türkiye, Belarus, China, Egypt, the UAE, Qatar, Oman, Kuwait, Iran, North Korea, Cuba, Syria. In Russia a dedicated PBX is allowed and runs only in Yandex Cloud — on cenaly.ru, where the shared server is closed.
  • The synthesiser voice depends on the cloud: on cenaly.ru the notice language list only offers what the local synthesiser can speak (six languages). Queue positions are announced in Russian and English — in other languages the queue works but does not read out the position.
  • Conferences v1: a room is entered from the inside only (an external call cannot be transferred into it), video shows the active speaker and requires the VP8 codec; there is no roster, no moderation and no conference recording.
  • We do not sell numbers. You buy the trunk and the number from a carrier yourself — a number cannot be moved "inside" the platform, it stays with the provider.

Troubleshooting#

Symptom Check
The phone does not register the username is entered in full (sip-…-<number>, not the number alone), the password has not been reset, the server address is taken from the window, transport is UDP. Full list — setting up SIP phones
The call connects but there is no audio, or only one side is heard dial *43 from that handset: a beep without your own voice means SIP ALG on the router, complete silence means UDP 10000–20000 is closed
Inbound calls do not arrive "Overview" → "Check connection": it walks the chain server → line → route → extensions and names the first broken link. Check the "Accepts calls" switch on the number and the trunk registration
An outbound call is rejected as "forbidden" whether the outbound master switch is on, whether the daily minute cap is exhausted, whether the destination is a premium one
A call is rejected for no clear reason, the trunk keeps flapping, there is a long silence before it connects open wire diagnostics on the "Server" tab and place the call again: the exchange shows which side answers and with which code
Calls stopped coming through and nobody noticed the "E-mail me when calls stop coming through" toggle on "Overview" is on by default: the letter arrives if the fault lasted 10 minutes

The general symptom-by-symptom guide is troubleshooting; if none of it helped, write to us — how to get help.


FAQ#

Do I need an external number to start?#

No. Without a number the PBX already takes calls from your website and from the app, and the team calls each other by internal numbers. A number is needed when guests have to reach you from an ordinary phone.

Can calls be taken on an employee's mobile?#

Yes, in two ways. An inherited number — the internal number lives with us while the call goes out to their mobile through the chosen channel (they get no account of ours). Full number duplication — the employee's phone registers with us, and then it takes part in groups, the ring plan grid and the rules on equal terms with everyone else.

How much does telephony cost?#

The PBX itself is a paid service: the dedicated server is billed monthly, and the confirmation before creation says so. Conversations are paid to your carrier at their tariff — we are not an intermediary in that chain. The "Calls from your website" and "Callback" widgets are free.


Was this article helpful?