A phone does not register
"Registering" is a phone checking in with the system so it can make and receive calls. When it never checks in — or keeps dropping off — here is where to see that, and what to check, in order.
Where to see the registration state
Every device has its own live Registration status card. Open Customers > Devices, find the phone, and open it — the card sits at the top of the General tab.
| Field | Meaning |
|---|---|
Badge (Online / Offline) | Whether the phone currently has a live registration. The text after it (e.g. Unregistered, Rejected) is the underlying technical status. |
Registration expires | When the current registration runs out. A phone re-registers well before this on its own — if it stops, this stays empty and the badge flips to Offline. |
Source IP:port | The address the system last saw this phone register from. If the phone is behind a router (NAT), this is the router's public address, not the phone's own. |
User agent | What the phone or app identifies itself as. Useful to confirm which physical phone (or which app) you're actually looking at. |
Qualify (RTT) | Round-trip time of the system's periodic "are you still there" ping — a rough health/latency indicator while registered. |
The devices list also shows a small dot per row (green = online) so you can scan several phones at once without opening each one.
What to check, in order
1. Wrong password (or username)
The single most common cause. The phone's SIP username and password must match the device's own Secret exactly — a typo, a copy-paste with a trailing space, or a phone still holding last month's password after it was regenerated. The secret itself is never shown again once set; if it's in doubt, set a new one on both the device and the phone.
2. NAT and Transport
Both live under Authentication & network on the device's General tab, next to Host and Port.
NAT tells the system whether this phone sits behind a router doing network address translation (almost every phone on an office or home internet connection does). Left wrong, calls may register but audio or reconnection can fail in ways that look unrelated to registration. Transport must match what the phone itself is configured to send (udp, tcp or a TLS variant) — a phone sending TCP to a device expecting UDP will simply never be seen.
For the full field-by-field explanation of every option here, see Device settings in depth.
3. The phone's own network path
A phone with the right password can still fail to register if it cannot reach the server at all — a firewall on the customer's side, a blocked port, or a Wi-Fi network that filters SIP traffic. This lives outside the product and cannot be seen from these pages; if the first two checks pass, it points here.
4. This system has blocked the phone's IP
Repeated failed registration attempts (a wrong password tried many times, or a scanner hitting the same port) get the source IP blocked automatically by fail2ban, the brute-force protection seen on System status. A phone that used to register fine and now can't — right after several bad attempts — is often this, not a new fault.
Open Monitoring > Blocked IPs, find the phone's address (the same one shown on its Registration status card, or the customer's public IP if they're behind a router), and click Unblock. If it reappears shortly after, the underlying cause — usually still a wrong password being retried — needs fixing first, or it will simply get blocked again.
Don't confuse this with the Admin IP whitelist (Settings > Admin IP access). That one is a separate, optional feature that restricts which IPs staff logins to this product's own web pages are accepted from — it has nothing to do with a customer's phone registering. If it happens to be switched on and your own office IP isn't approved, you won't be able to open these pages at all, which can look like "everything is broken" when only your own admin access is affected.
Check
After a fix, ask the phone to re-register (most phones do this within a minute on their own, or it can be forced by restarting the phone). Reload the device's page — the badge should turn Online, Registration expires should show a future time, and Source IP:port should match where the phone actually is.