Troubleshooting Cisco IP phone registration
Cisco IP phones
Verified 2026-09-24 · 67 sources · tier 2
For Unified CM, voice, and network administrators troubleshooting phone registration failures..
During startup, an 8800 Series phone executes a defined sequence across network configuration, TFTP requests, trust verification, and Unified CM connection 62. Registration depends on PoE, the voice VLAN, DHCP, DNS, and TFTP in addition to Unified CM 11.
Before you start
- Cluster Security Mode is displayed under System > Enterprise Parameters as 0 for non-secure mode and 1 for mixed mode 6.
- Non-secure mode is the default cluster security mode after installation 48.
- Phones download a configuration file from TFTP that lists Unified CM nodes and TCP ports in priority order 5.
What changes by situation
Pick your answers to see only your path. Nothing is sent anywhere until you make a plan.
Two questions. One permanent page you can send to your manager.
Step 1 Scope the failure and record identifiers
Do
Record the affected phone models, locations, total number of affected phones, firmware versions, several affected MAC addresses, and the timestamp when the issue began 59.
Verify
Confirm that the scope specifies whether the failure impacts a single device, a model, a site, or the cluster, and that MAC addresses and a start time are available for log filtering 59.
Rollback
Suggested rollback: retain the recorded details in the incident log without making configuration changes.
Step 2 Confirm Unified CM device records and capacity
Do
Navigate to Device > Phone and confirm the phone is added to the database, or confirm autoregistration is enabled 49. If an individual node stops registering devices at 5000 endpoints, increase the Maximum Number of Registered Devices service parameter on each node 25.
Verify
Check that the phone record appears in Unified CM Administration 49. If registration status displays incorrectly, verify that the Cisco RIS Data Collector service is running and that DNS resolution functions across nodes 57.
Rollback
Suggested rollback: delete any manually created device record or restore the Maximum Number of Registered Devices service parameter to its previous value.
Step 3 Check network path and edge connectivity
On the internal network
Do
Confirm physical link and PoE power on the switch port 11. On a Catalyst 9300 switch, configure the voice VLAN using switchport voice vlan vlan-id on the access port and verify CDP is enabled on the port to send VLAN configuration to the phone 65. Ensure the phone obtains its auxiliary VLAN via CDP or voice VLAN via LLDP-MED before making DHCP requests 367.
Verify
Run show interfaces interface-id switchport to verify the configured voice VLAN 65. Check that the switch port is enabled and has network access to the DHCP server 47.
Rollback
Suggested rollback: restore the previous switch port voice VLAN configuration using the command line interface.
Over Mobile and Remote Access through Expressway
Do
Confirm the endpoint is supported over Mobile and Remote Access (MRA), which includes the IP Phone 7800 and 8800 Series on firmware 11.0(1) or later and excludes the 8821, 8821-EX, and 8831 34. Verify that public external DNS contains _collab-edge._tls.<domain> SRV records 37. Confirm the external firewall permits inbound TCP 5061 and TCP 8443 to Expressway-E 35. If using activation code onboarding, verify "Allow Activation Code via MRA" is checked on the Phone Configuration window in Unified CM, and ensure the Cisco Manufacturing root certificates reside in the CallManager-trust store 2933. For Desk Phone 9800 and Video Phone 8875 endpoints using SIP OAuth over MRA, onboard using activation codes and ensure TFTP Encrypted Config remains disabled 1.
Verify
Use Maintenance > Tools > Network utilities > DNS lookup on Expressway-C to verify internal SRV records, and on Expressway-E to verify external DMZ resolution for _collab-edge._tls and _cisco-uds._tcp 32.
Rollback
Suggested rollback: uncheck Allow Activation Code via MRA or revert modified external DNS records and firewall rules.
Step 4 Verify IP addressing and TFTP resolution
On the internal network
Do
Open Applications > Admin settings > Status on the phone to check addressing errors 64. Evaluate reported messages: "DHCP timeout" indicates no DHCP response 40, "No default router" indicates a missing gateway 43, and "Duplicate IP" indicates an IP address conflict 41. If the phone fails to obtain an IP, check that the voice VLAN has access to the DHCP server 47. Configure DHCP custom option 150 on the DHCP server (configured as option 150 ip ip-address on Cisco IOS) to provide TFTP server addresses 5015. If using static addressing, configure the TFTP server locally on the phone 63. If the phone was moved between locations, set an alternate TFTP server under Applications > Admin settings > Network setup > Ethernet setup > IPv4 setup > TFTP Server 1 2. When using hostnames, confirm DNS contains forward and reverse records for the TFTP server and Unified CM 12.
Verify
Confirm that "DHCP timeout", "No default router", and "Duplicate IP" are absent 404143. Verify that the status screen does not report "TFTP timeout", which indicates an uncommunicative TFTP server 44. If "File not found " appears, verify the phone device record in the Unified CM database 42.
Rollback
Open Applications > Admin Settings > Reset Settings > Network Setup on the 8800 Series phone to reset network settings and cause DHCP to reconfigure the IP address 46.
Suggested rollback: revert DHCP scope parameters.
Over Mobile and Remote Access through Expressway
Do
Navigate to Status > Unified Communications on Expressway-C to verify synchronization with Unified CM, and rediscover Unified CM and IM and Presence nodes if system configurations were modified 39. If a SIP trunk connects Unified CM and Expressway-C, assign the SIP trunk a different listening port on Unified CM from the port used for SIP line registrations 38.
Verify
Confirm that Status > Unified Communications on Expressway-C reports clean synchronization with no configuration errors 39.
Rollback
Suggested rollback: restore the original SIP trunk listening port on the call control system if modified.
Step 5 Check trust lists and configuration file retrieval
Non-secure mode (Cluster Security Mode = 0)
Do
In non-secure mode, the TFTP server responds to the phone's CTL request with 404 Not Found 9. Verify the phone proceeds to request the ITL file and receives a 200 OK before requesting its configuration file 16.
Verify
Review phone console logs to verify trust validation messages such as "File sign verify SUCCESS" 8. Confirm the phone status screen does not display "Trust List update failed" 45.
Rollback
Suggested rollback: no configuration changes were applied in this step.
Mixed mode (Cluster Security Mode = 1)
Do
Verify the phone downloads the CTL file from TFTP 28. If the CTL file lists a TFTP server with a self-signed certificate, ensure the phone requests a signed configuration file 28. Update the CTL file across all cluster nodes using the CLI command utils ctl update CTLFile 10.
Verify
On the phone, navigate to Applications > Admin Settings > Security Setup > Trust List and confirm entries are present for both CTL File and ITL File 60. Confirm the phone does not display "No Trust List installed" or "Trust List update failed" 45.
Rollback
Execute the CLI command utils ctl set-cluster non-secure-mode to update the CTL file and return the cluster to non-secure mode 27.
Step 6 Resolve trust list (ITL/CTL) mismatches
Non-secure mode (Cluster Security Mode = 0)
Do
Investigate an ITL mismatch if the phone was migrated between clusters or following a CallManager certificate regeneration 2622. Following certificate regeneration, ensure phones can connect to the Trust Verification Service (TVS) on TCP port 2445 to authenticate the new certificate before accepting an updated ITL 466. WarmTransfer's reading of the sources is that bulk ITL reset from Unified CM should be attempted prior to touching phones individually 20. Execute utils itl reset localkey or utils itl reset remotekey, check status with show itl, select Reset on the Enterprise Parameters page, and restart the TFTP service and endpoints 17. Cisco TAC states the ITL file needs deleting from a phone only when all of these hold: the phone's ITL signature does not match the TFTP server's ITL, the TVS signature in the ITL does not match the certificate presented, the phone shows verification failures, and no backup of the old TFTP private key exists 19.
Verify
Confirm that the phone retrieves the current ITL, console logs record "File sign verify SUCCESS", and the status display clears "Trust List update failed" 845.
Rollback
Perform a factory reset on an 8800 Series phone from the keypad by removing power, holding # while restoring power until the Headset and Speaker buttons light, and entering 123456789*0# 14.
Mixed mode (Cluster Security Mode = 1)
Do
Assess trust mismatches resulting from inter-cluster migration or renewed certificates 2622. WarmTransfer's reading of the sources is that bulk ITL reset from Unified CM should be attempted prior to touching phones individually 20. Execute utils itl reset localkey or utils itl reset remotekey, check status with show itl, select Reset on the Enterprise Parameters page, and restart the TFTP service and endpoints 17. Cisco TAC states the ITL file needs deleting from a phone only when all four failure conditions hold 19.
Verify
Navigate to Applications > Admin Settings > Security Setup > Trust List to verify both CTL File and ITL File display entries, and verify that "Trust List update failed" is cleared 4560.
Rollback
Perform a factory reset on an 8800 Series phone from the keypad by removing power, holding # while restoring power until the Headset and Speaker buttons light, and entering 123456789*0# 14.
Step 7 Align phone security profiles with cluster mode and path
On the internal network + Non-secure mode (Cluster Security Mode = 0)
Do
Assign the phone a security profile with Device Security Mode set to Non Secure, which uses a standard TCP connection to Unified CM 51. Authenticated and Encrypted profiles require TLS transport and are not supported for secure signalling in a non-secure cluster 4851.
Verify
Check Applications > Admin Settings > Security Setup on the phone to confirm the configured security mode matches Non Secure 60.
Rollback
Suggested rollback: reassign the previous phone security profile in the call control administration interface.
On the internal network + Mixed mode (Cluster Security Mode = 1)
Do
If assigning an Authenticated or Encrypted profile, confirm the phone holds a Locally Significant Certificate (LSC) or Manufacture-Installed Certificate (MIC) 2451. If neither certificate exists, apply a non-secure profile and install a certificate through the CAPF settings on the Phone Configuration window 24.
Verify
Check Applications > Admin Settings > Security Setup on the phone to verify LSC status reports installed and the security mode reflects Authenticated or Encrypted 60.
Rollback
Suggested rollback: Reapply the phone's previous security profile.
Over Mobile and Remote Access through Expressway + Non-secure mode (Cluster Security Mode = 0)
Do
Verify the phone is assigned a Non Secure phone security profile 51. If evaluating a secure profile, the profile name must be formatted as an FQDN and included in the Expressway-C server certificate's Subject Alternative Names (SAN) 36.
Verify
Confirm that the Expressway-C server certificate SAN includes any secure profile FQDNs in use, and verify Security Setup on the phone shows the assigned security mode 3660.
Rollback
Suggested rollback: reassign the previous phone security profile in the call control administration interface.
Over Mobile and Remote Access through Expressway + Mixed mode (Cluster Security Mode = 1)
Do
Verify the secure phone security profile name is formatted as an FQDN and is present in the Expressway-C server certificate Subject Alternative Names 36. Ensure TFTP Encrypted Config is not enabled if onboarding Desk Phone 9800 or Video Phone 8875 endpoints using SIP OAuth over MRA 1.
Verify
Check Applications > Admin Settings > Security Setup on the phone to confirm the LSC is installed, and verify the Expressway-C SAN covers the profile name 3660.
Rollback
Suggested rollback: reassign the previous phone security profile in the call control administration interface.
Step 8 Inspect phone status messages and restart causes
Do
Open Applications > Admin settings > Status on the phone to inspect the status messages and the Restart Cause field 64. Identify reported restart causes including TCP-timeout, CM-closed-TCP, KeepaliveTO, Failback, Phone-Reg-Rej, Load Rejected HC, and CM-ICMP-Unreach 56. Note that phones power cycle or reset when experiencing TCP connection failures to Unified CM, missing keepalive acknowledgements, network outages, DHCP failures, invalid static IPs, heavy network traffic absent a voice VLAN, or administrative resets from Unified CM 5355.
Verify
Suggested check: correlate the reported restart cause to the corresponding subsystem, checking network or DHCP parameters for TCP or timeout values, and security configuration for registration rejections.
Rollback
Suggested rollback: no system configuration changes were applied in this step.
Step 9 Collect diagnostic traces
On the internal network
Do
Collect the phone's Problem Report Tool (PRT) logs or console logs, along with Unified CM CallManager traces, Event Viewer logs, and TFTP traces 23. PRT logs can be gathered centrally in Unified CM Administration by selecting endpoints in Device > Phone and clicking "Generate PRT for Selected" 52. For an 8800 Series phone that cannot reach the network, attach a console cable and navigate to Applications > Admin settings > Aux port > Collect console log 7. In the Unified CM Event Viewer, filter EndPointUnregistered alarms by MAC address, timestamp, and unregistration reason code 13.
Verify
Confirm that collected trace files span the timestamps and include the specific MAC addresses identified during initial scoping 59.
Rollback
Suggested rollback: revert trace settings and diagnostic logging levels in the system administration interface.
Over Mobile and Remote Access through Expressway
Do
Collect the phone PRT logs, Unified CM CallManager traces, Event Viewer logs, and TFTP traces 23. On Expressway, adjust logging levels under Maintenance > Diagnostics > Advanced > Support Log configuration, and initiate a trace collection under Maintenance > Diagnostics > Diagnostic logging 31.
Verify
Confirm that both Expressway diagnostic logs and Unified CM traces span the failure timeframe and capture the target MAC addresses 59.
Rollback
Suggested rollback: restore support logging levels and disable active diagnostic logging sessions.
Step 10 Validate stable registration
Do
During startup an 8800 Series phone contacts Unified CM after requesting its configuration file 62.
Verify
Verify that the phone transmits a SIP REGISTER message and receives a SIP/2.0 200 OK containing contact information and an expiration interval 61. Confirm that Unified CM Administration lists the endpoint as Registered, and verify that no subsequent EndPointUnregistered alarms appear in the Event Viewer for the target MAC address 13.
Rollback
Suggested rollback: if registration fails, preserve gathered trace captures for escalation.
Applicability
Applies to: Cisco Desk Phone 9800 Series, Cisco IP Phone 8800 Series, Cisco Unified Communications Manager, Cisco IP phones on Unified Communications Manager, Cisco IOS DHCP server, Cisco Expressway, and Cisco Catalyst 9300 (IOS XE). Deployments: on-premises. Sources checked 2026-09-24. The configuration file contains a prioritized list of Unified CM nodes and the TCP ports used to connect to them 5. An individual Unified CM node stops registering devices at 5000 endpoints when the Maximum Number of Registered Devices service parameter is at default 25. The cluster security mode is displayed under System > Enterprise Parameters as 0 for non-secure mode and 1 for mixed mode 6. The command utils ctl update CTLFile updates the CTL file across all cluster nodes 10. Bulk ITL reset is performed using utils itl reset localkey or utils itl reset remotekey 17. Expressway MRA onboarding with an activation code is supported from X14.0 29. Expressway-C Subject Alternative Names must match secure phone security profile names from X12.6 36. Catalyst 9300 switch voice VLAN commands are documented for Cisco IOS XE 17.15.x 65. Documented endpoint models include the IP Phone 7800 and 8800 Series, Desk Phone 9800, and Video Phone 8875 1234.
What remains uncertain
The precedence order followed by an IP phone when simultaneously receiving TFTP addresses from local settings, DHCP option 150, DHCP option 66, and siaddr is not covered by the sources below. Specific unregistration numeric reason codes within EndPointUnregistered event alarms are not covered by the sources below. Menu paths for 7800, 9800, and 8875 series phones are not covered by the sources below. Whether recent Expressway releases permit CAPF operations over MRA is not covered by the sources below.
See also
Related to
- Unified CM and Webex Calling coexistence during a migration — Phones moved between Unified CM clusters or platforms hit the ITL signer mismatch covered in step 6.
- Voice VLAN and LLDP-MED and CDP and PoE for IP phones — Step 3 of the guide (voice VLAN; CDP and LLDP-MED; PoE) overlaps that topic; this guide cites only its own claims because no registry claims were supplied for it.
Sources
- 1Desk Phone 9800 and Video Phone 8875 on Unified CM using SIP OAuth over MRA must be onboarded with an activation code, and TFTP Encrypted Config cannot be enabled for their MRA use.Use Mobile and Remote Access (MRA) on 9800/8875 (Unified CM) · Use Mobile and Remote Access (MRA) on 9800/8875 > requirements and onboarding · Checked 2026-09-24
- 2An 8800 Series phone can be set to use an alternate TFTP server, useful when the phone has moved location, under Applications > Admin settings > Network setup > Ethernet setup > IPv4 setup > TFTP Server 1.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting · Troubleshooting > Check TFTP Settings · Checked 2026-09-24
- 3The 8800 Series phone uses CDP to exchange the auxiliary VLAN ID, power details and QoS information with a Cisco Catalyst switch, and supports LLDP-MED for voice VLAN configuration, device discovery, power and inventory management.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details · Technical Details > Network Protocols table, CDP and LLDP-MED rows · Checked 2026-09-24
- 4When the CallManager certificate is regenerated, phones cannot verify the newly signed files directly and contact TVS to authenticate the new certificate before accepting the updated ITL.Understand CUCM Security By Default and ITL Operation and Troubleshooting · Understand CUCM Security By Default and ITL Operation and Troubleshooting > certificate regeneration · Checked 2026-09-24
- 5The configuration file a phone downloads from TFTP contains a prioritized list of Unified CM nodes and the TCP ports used to connect to them.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU1 - Configure TFTP Servers · Configure TFTP Servers > TFTP server overview · Checked 2026-09-24
- 6The cluster security mode is shown under System > Enterprise Parameters as Cluster Security Mode, 1 for mixed mode and 0 for non-secure, and cannot be set on that page.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > verify cluster security mode · Checked 2026-09-24
- 7On an 8800 Series phone, console logs can be collected through the auxiliary port by selecting Applications > Admin settings > Aux port > Collect console log, with a console cable attached.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting · Troubleshooting > Capture console logs · Checked 2026-09-24
- 8Phone console logs show successful trust-file validation with strings such as 'File sign verify SUCCESS' for the ITL and 'SECD: verifyFile: verify SUCCESS' for configuration files checked against the ITL.Understand CUCM Security By Default and ITL Operation and Troubleshooting · Understand CUCM Security By Default and ITL Operation and Troubleshooting > phone console log examples · Checked 2026-09-24
- 9When the Unified CM cluster is in non-secure mode, the TFTP server answers the phone's CTL file request with 404 Not Found.Troubleshoot IP Phone Unregistration Issues in CUCM · Troubleshoot IP Phone Unregistration Issues in CUCM > configuration file download sequence · Checked 2026-09-24
- 10The CLI command utils ctl update CTLFile updates the CTL file on each node in the cluster.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > CLI commands · Checked 2026-09-24
- 11Phone registration depends on DHCP, DNS, TFTP, the voice VLAN and PoE in addition to Unified CM itself.Troubleshoot IP Phone Unregistration Issues in CUCM · Troubleshoot IP Phone Unregistration Issues in CUCM > components involved in registration · Checked 2026-09-24
- 12When the phone is configured with host names, DNS must hold entries for the TFTP server and Unified CM, and DNS should be configured for reverse lookups.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting · Troubleshooting > Verify DNS Settings · Checked 2026-09-24
- 13Unified CM event viewer logs record EndPointUnregistered alarms carrying device name, IP address, protocol, device type and a reason code, and TAC advises focusing on the reason number, MAC address and timestamp.Troubleshoot IP Phone Unregistration Issues in CUCM · Troubleshoot IP Phone Unregistration Issues in CUCM > EndPointUnregistered analysis · Checked 2026-09-24
- 14An 8800 Series phone is factory reset from the keypad by removing power, holding # while restoring power until the Headset and Speaker buttons light, then entering 123456789*0#; the reset clears all phone parameters.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Maintenance · Maintenance > Factory Reset > Perform Factory Reset from Phone Keypad · Checked 2026-09-24
- 15On a Cisco IOS DHCP server the TFTP server for IP phones is set in the DHCP pool with option 150 ip ip-address.Cisco Unified Communications Manager Express System Administrator Guide - Network Parameters · Network Parameters > Configure Single DHCP IP Address Pool · Checked 2026-09-24
- 16After the CTL request the phone requests the ITL file, which the TFTP server returns with 200 OK, and then requests its configuration file.Troubleshoot IP Phone Unregistration Issues in CUCM · Troubleshoot IP Phone Unregistration Issues in CUCM > configuration file download sequence · Checked 2026-09-24
- 17A bulk ITL reset is run with utils itl reset localkey or utils itl reset remotekey, checked with show itl, followed by Reset on the Enterprise Parameters page so devices restart and download the new ITL, and a restart of the TFTP service and devices.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Perform Bulk Reset of ITL File · Checked 2026-09-24
- 18The ITL file is used for initial trust between endpoints and Unified CM and contains the TFTP, TVS and CAPF certificates plus the ITLRecovery certificate used to sign it.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Initial Trust List · Checked 2026-09-24
- 19Cisco TAC states the ITL file needs deleting from a phone only when all of these hold: the phone's ITL signature does not match the TFTP server's ITL, the TVS signature in the ITL does not match the certificate presented, the phone shows verification failures, and no backup of the old TFTP private key exists.Understand CUCM Security By Default and ITL Operation and Troubleshooting · Understand CUCM Security By Default and ITL Operation and Troubleshooting > when the ITL file must be deleted · Checked 2026-09-24
- 20Deleting trust files from phones is a last resort: the bulk ITL reset from Unified CM should be tried before touching phones individually, because a manual deletion must be done at each phone.inferredSecurity Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Perform Bulk Reset of ITL File (read with 116232 ITL deletion section) · Checked 2026-09-24
- 21Where the ITL must be removed from a phone that no longer trusts the cluster, the phone's buttons must be pressed manually on the phone to delete it.Understand CUCM Security By Default and ITL Operation and Troubleshooting · Understand CUCM Security By Default and ITL Operation and Troubleshooting > ITL deletion · Checked 2026-09-24
- 22Some phones do not pick up the latest ITL file and keep the old one when ITL files are updated, for example on renewal of the CallManager certificate.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Certificate Management Changes for ITLRecovery Certificate · Checked 2026-09-24
- 23For unregistration issues Cisco TAC lists the phone's Problem Report Tool (PRT) or console logs from the phone, and CallManager traces, event viewer logs and TFTP logs from Unified CM, as the data to collect.Troubleshoot IP Phone Unregistration Issues in CUCM · Troubleshoot IP Phone Unregistration Issues in CUCM > Logs to collect · Checked 2026-09-24
- 24Before applying a security profile that uses certificates, the phone must hold a Locally Significant Certificate (LSC) or Manufacture-Installed Certificate (MIC); if it has none, apply a non-secure profile and install a certificate through the CAPF settings on the Phone Configuration window.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security > phone security setup prerequisites · Checked 2026-09-24
- 25If a node will not register more than 5000 phones, the Maximum Number of Registered Devices service parameter is at its default and must be raised on each node.Troubleshooting Guide for Cisco Unified Communications Manager Release 12.5(1) — Device Issues · Device Issues > Phone Issues > Phones Not Registering · Checked 2026-09-24
- 26A phone moved from one Unified CM cluster to another can fail because the new cluster's ITL file is not signed by the signer in the ITL the phone already holds.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Migrate IP Phones Between Clusters with Cisco Unified Communications Manager and ITL Files · Checked 2026-09-24
- 27The CLI command utils ctl set-cluster mixed-mode updates the CTL file and sets the cluster to mixed mode, and utils ctl set-cluster non-secure-mode updates the CTL file and returns it to non-secure mode.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > CLI commands · Checked 2026-09-24
- 28In mixed mode phones download the CTL file from TFTP, and if the CTL contains a TFTP server entry with a self-signed certificate the phone requests a signed configuration file.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > endpoint behaviour in mixed mode · Checked 2026-09-24
- 29From Expressway X14.0, a phone onboarding with an activation code switches to MRA mode only if Allow Activation Code via MRA is checked on its Phone Configuration window in Unified CM.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - Onboarding MRA Devices · Onboarding MRA Devices > Activation code onboarding over MRA · Checked 2026-09-24
- 30CAPF certificate operations are not supported over MRA; MRA supports encrypted TFTP configuration files only when CAPF enrollment was completed on premises.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites > Unsupported features / encrypted TFTP · Checked 2026-09-24
- 31Expressway diagnostic logs are captured through Maintenance > Diagnostics > Diagnostic logging, with log levels set under Maintenance > Diagnostics > Advanced > Support Log configuration.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · MRA Troubleshooting > Diagnostic logging · Checked 2026-09-24
- 32Expressway's Maintenance > Tools > Network utilities > DNS lookup checks _collab-edge._tls and _cisco-uds._tcp SRV records; run from Expressway-C it shows the internal view and from Expressway-E the DMZ view.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · MRA Troubleshooting > Checking DNS records · Checked 2026-09-24
- 33Activation code onboarding over MRA requires the Cisco Manufacturing root certificates in the Unified CM CallManager-trust store and outbound TCP 443 from the publisher to the Cisco cloud onboarding hosts.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - Onboarding MRA Devices · Onboarding MRA Devices > Activation code onboarding requirements · Checked 2026-09-24
- 34The X15.2 MRA guide lists the IP Phone 7800 and 8800 Series (minimum 11.0(1)) as supported over MRA and excludes the 8821, 8821-EX and 8831.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites > Supported endpoints · Checked 2026-09-24
- 35The external firewall must allow inbound TCP 5061 for SIP and TCP 8443 for HTTPS to the Expressway-E for MRA.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites > Firewall / port requirements · Checked 2026-09-24
- 36Secure MRA registrations fail if the Expressway-C server certificate's Subject Alternative Names do not include the phone security profile names in use, and from X12.6 those profile names must be FQDNs in both Unified CM and the certificate.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · MRA Troubleshooting > Registration failures > secure registration and phone security profile names · Checked 2026-09-24
- 37For MRA, public external DNS must hold _collab-edge._tls.<domain> SRV records so endpoints can discover the Expressway-E.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites · MRA Requirements and Prerequisites > DNS records · Checked 2026-09-24
- 38MRA endpoints can fail to register if a SIP trunk exists between Unified CM and Expressway-C using the same listening port as SIP line registrations; the trunk needs a different listening port on Unified CM.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · MRA Troubleshooting > Registration failures > SIP trunk between Unified CM and Expressway-C · Checked 2026-09-24
- 39Expressway-C's Status > Unified Communications page shows synchronization with Unified CM, and Unified CM and IM and Presence nodes should be rediscovered after configuration changes on them.Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting · MRA Troubleshooting > Checking Unified CM discovery / status · Checked 2026-09-24
- 40The phone status message 'DHCP timeout' means the DHCP server did not respond.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems · Monitoring Phone Systems > Status Messages table, row DHCP timeout · Checked 2026-09-24
- 41The phone status message 'Duplicate IP' means another device is using the IP address assigned to the phone.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems · Monitoring Phone Systems > Status Messages table, row Duplicate IP · Checked 2026-09-24
- 42The phone status message 'File not found <Cfg File>' means the phone's configuration file was not found on the TFTP server, which the guide ties to the phone not being in the Unified CM database.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems · Monitoring Phone Systems > Status Messages table, row File not found <Cfg File> · Checked 2026-09-24
- 43The phone status message 'No default router' means DHCP or static configuration did not specify a default router.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems · Monitoring Phone Systems > Status Messages table, row No default router · Checked 2026-09-24
- 44The phone status message 'TFTP timeout' means the TFTP server did not respond; the guide suggests checking connectivity and that the TFTP server is active.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems · Monitoring Phone Systems > Status Messages table, row TFTP timeout · Checked 2026-09-24
- 45The phone status message 'No Trust List installed' means no CTL or ITL file is installed, and 'Trust List update failed' means an update of the CTL and ITL files failed.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems · Monitoring Phone Systems > Status Messages table, rows No Trust List installed and Trust List update failed · Checked 2026-09-24
- 46On an 8800 Series phone, Admin Settings > Reset Settings > Network Setup resets network settings and causes DHCP to reconfigure the phone's IP address.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Maintenance · Maintenance > Basic Reset > Reset Network Setup · Checked 2026-09-24
- 47If a phone cannot obtain an IP address, check that the network or VLAN it connects to has access to the DHCP server and that the switch port is enabled.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting · Troubleshooting > Startup Problems > Cisco IP Phone Cannot Obtain IP Address · Checked 2026-09-24
- 48Non-secure mode is the default Unified CM cluster security mode after installation and provides no secure signalling or media; mixed mode supports both secure and non-secure endpoints.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes · Security Modes > Non-Secure Mode; Mixed Mode · Checked 2026-09-24
- 49A phone can register with Unified CM only if it has been added to the Unified CM database or autoregistration is enabled.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting · Troubleshooting > Startup Problems > Phone Does Not Register with Cisco Unified Communications Manager · Checked 2026-09-24
- 50Cisco recommends DHCP custom option 150 for IPv4 devices to learn the TFTP server address, lists DHCP option 066 and CiscoCM1 as alternatives it does not recommend, and uses Cisco vendor-specific DHCPv6 information for IPv6.System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU1 - Configure TFTP Servers · Configure TFTP Servers > TFTP server overview / finding the TFTP server · Checked 2026-09-24
- 51A phone security profile's Device Security Mode is Non Secure (a TCP connection to Unified CM), Authenticated (TLS with NULL/SHA for signalling) or Encrypted (adds signalling encryption), and secure modes use TLS as the transport.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security · Phone Security > phone security profile settings > Device Security Mode; Transport Type · Checked 2026-09-24
- 52PRT logs can be collected centrally in Unified CM Administration by selecting Device > Phone, finding and selecting phones, and clicking Generate PRT for Selected.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting · Troubleshooting > Generate a Problem Report from Unified CM · Checked 2026-09-24
- 53The 8800 guide lists intermittent network outages, DHCP errors, incorrect static IP addressing, heavy network use without a voice VLAN and intentional resets from Unified CM as causes of phones resetting.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting · Troubleshooting > Phone Resets Unexpectedly · Checked 2026-09-24
- 54On an 8800 Series phone, Admin Settings > Reset Settings > Security Settings deletes only the CTL file from the phone.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Maintenance · Maintenance > Basic Reset > Remove CTL File · Checked 2026-09-24
- 55Phones power cycle or reset because of a TCP failure while connecting to Unified CM or a failure to receive acknowledgements to their KeepAlive messages.Troubleshooting Guide for Cisco Unified Communications Manager Release 12.5(1) — Device Issues · Device Issues > Phone Issues > Phone Resets · Checked 2026-09-24
- 56The phone's Restart Cause field reports values including TCP-timeout, CM-closed-TCP, KeepaliveTO, Failback, Phone-Reg-Rej, Load Rejected HC and CM-ICMP-Unreach.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems · Monitoring Phone Systems > Network Statistics > Restart Cause field · Checked 2026-09-24
- 57Unified CM Administration can show an incorrect device registration status if the Cisco RIS Data Collector service is not running or if network or DNS resolution problems prevent communication.Troubleshooting Guide for Cisco Unified Communications Manager Release 12.5(1) — Device Issues · Device Issues > Incorrect Device Registration Status Displays · Checked 2026-09-24
- 58Setting the enterprise parameter Prepare Cluster for Rollback to pre-8.0 to True makes the cluster publish an ITL with blank entries, and phone services that use HTTPS do not work while it is enabled.Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security · Default Security > Roll Back Cluster to a Pre-8.0 Release · Checked 2026-09-24
- 59Cisco TAC advises establishing the affected phone models, locations, number of phones and firmware versions, and noting several affected MAC addresses and the time the issue started, before troubleshooting unregistration.Troubleshoot IP Phone Unregistration Issues in CUCM · Troubleshoot IP Phone Unregistration Issues in CUCM > Background / clarifications before troubleshooting · Checked 2026-09-24
- 61A successful SIP phone registration appears as the phone's REGISTER answered by SIP/2.0 200 OK carrying the contact and an expiry; the tech note's example shows 120 seconds.Troubleshoot IP Phone Unregistration Issues in CUCM · Troubleshoot IP Phone Unregistration Issues in CUCM > SIP registration process · Checked 2026-09-24
- 62During startup an 8800 Series phone configures its VLAN, obtains an IP address, accesses a TFTP server, requests the CTL file, requests the ITL file, requests its configuration file, and then contacts Unified CM.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details · Technical Details > Phone Startup Process, steps 5 to 11 · Checked 2026-09-24
- 63A phone with a statically defined IP address must have its TFTP server configured locally on the phone; otherwise the DHCP server directs it to the TFTP server.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details · Technical Details > Phone Startup Process, step 7 Access TFTP Server · Checked 2026-09-24
- 64On an 8800 Series phone, status messages, network statistics and call statistics are under Applications > Admin settings > Status.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems · Monitoring Phone Systems > Cisco IP Phone Status > Display the Status Messages Window · Checked 2026-09-24
- 65On a Catalyst 9300 the voice VLAN is set per access port with switchport voice vlan vlan-id, CDP must be enabled on the port to send that configuration to the phone, and show interfaces interface-id switchport displays it.VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs · Configuring Voice VLANs > Configuring a Voice VLAN / Monitoring Voice VLAN · Checked 2026-09-24
- 66The Trust Verification Service (TVS) runs on Unified CM on TCP port 2445 and authenticates certificates the phone does not already trust, so the phone need not hold a full trust store.Understand CUCM Security By Default and ITL Operation and Troubleshooting · Understand CUCM Security By Default and ITL Operation and Troubleshooting > TVS · Checked 2026-09-24
- 67When connected to a Cisco Catalyst switch, the switch tells the phone the voice VLAN, and the phone needs its VLAN membership before it makes its DHCP request.Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details · Technical Details > Phone Startup Process, step 5 Configure VLAN · Checked 2026-09-24
Documents
Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Security
Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Maintenance
Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems
Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details
Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Troubleshooting
Cisco Unified Communications Manager Express System Administrator Guide - Network Parameters
Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.0) - Onboarding MRA Devices
Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Requirements and Prerequisites
Mobile and Remote Access Through Cisco Expressway Deployment Guide (X15.2) - MRA Troubleshooting
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Default Security
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Phone Security
Security Guide for Cisco Unified Communications Manager, Release 15 and SUs - Security Modes
System Configuration Guide for Cisco Unified Communications Manager, Release 12.5(1)SU1 - Configure TFTP Servers
Troubleshoot IP Phone Unregistration Issues in CUCM
Troubleshooting Guide for Cisco Unified Communications Manager Release 12.5(1) — Device Issues
Understand CUCM Security By Default and ITL Operation and Troubleshooting
Use Mobile and Remote Access (MRA) on 9800/8875 (Unified CM)
VLAN Configuration Guide, Cisco IOS XE 17.15.x (Catalyst 9300 Switches) - Configuring Voice VLANs
Cite this page
APA
WarmTransfer. (2026, September 24). Troubleshooting Cisco IP phone registration. WarmTransfer. https://warmtransfer.net/guides/cisco-phone-registration-troubleshooting
BibTeX
@misc{warmtransfer-cisco-phone-registration-troubleshooting,
title = {Troubleshooting Cisco IP phone registration},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/guides/cisco-phone-registration-troubleshooting},
note = {Verified 2026-09-24}
}