VoIP phone wont configure

I have some new VoIP phones and for some reason they will not configure on my clients network, when i took them home they work perfectly. I tried Wiresharking on a hub to capture the traffic, however i am at a loss as to what it means of what is causing the issue. The DNS is our Win2012R2 server and this then forwards on to the public Google servers.
wireshark-capture.png
pereigroupAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Dirk KotteSECommented:
this capture show you
first:
172.16.1.36 try to establish a FTP connection (TCP21) to 172.16.0.9
second:
172.16.0.9 send a TCP-RESET immediately as answer back to 172.16.1.36

what can be seen from this?
- routing is OK, because the hosts communicate
- 172.16.0.9 don't accept the connection ... possible the pones come from an not allowed subnet or located within the false VLAN, or the local Firewall or FTP Serice is configured incorrectly
pereigroupAuthor Commented:
Thanks Dirk for the response.

The subnet on the DNS is 255.255.254.0 so allows IP ranges 172.16.0.0 to 172.16.1.255, the phone IP is 172.16.1.36 and the server IP is 172.16.0.9 so both are within range of the same subnet

We dont use VLAN on our network

I temporarily disabled the firewall on this server during the testing because it was blocking the communication (i will fix this later), so the firewall is not the issue.

The FTP service is not on our lan, it should be forwarded externally to the phone provider.
voip-packet-content.png
dns-response-to-voip.png
Dirk KotteSECommented:
can't recognize any forwarding.
there is traffic between microsoft (hyper-V i think) and polycom only.
and the (virtual) device with microsoft-MAC address send the session-reset.

if this is a virtual router/firewall/VPN/gateway, you should check the logfiles here.
Price Your IT Services for Profit

Managed service contracts are great - when they're making you money. Yes, you’re getting paid monthly, but is it actually profitable? Learn to calculate your hourly overhead burden so you can master your IT services pricing strategy.

pereigroupAuthor Commented:
This is a virtualised server running DNS and DHCP, the gateway/firewall/WAN is a physical device which is 172.16.0.5, i would need to run Wireshark on the server to see if any traffic was being forwarded to on from the DNS to elsewhere.

It seems that from what you are saying that the Polycom phone is trying to establish a FTP connection with the DNS server which it has no facility to facilitate. I dont know where to go from here. I spoke to the providor and they said the phone should be communicating on port 5060 which there is no traffic on.
Dirk KotteSECommented:
Port 5060 is SIP. The Phone use this Ports to establish calls. The phone must be connected to the call-server and ready booted before.
I think the phone try to get the Firmware/Configuration via FTP while booting.
Possible you have to configure the phone-server as DHCP-option.
Check: https://community.polycom.com/t5/VoIP-SIP-Phones/FAQ-How-can-I-setup-my-Phone-Provisioning-Download-Upgrade/td-p/4203
pereigroupAuthor Commented:
Thanks for the reply, it is a cloud based phone system, so i dont have access to the phone-server, when plugged the phones in at home it just worked (granted different IP range).
masnrockCommented:
Could you please show the settings for your DHCP server? More specifically, what options your DHCP server is sending. Sounds as if your phones are receiving a DHCP option that is causing them to try looking at the wrong place for FTP connections.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.