# Troubleshooting Cisco IP phones stuck upgrading firmware

Canonical: https://warmtransfer.net/knowledge/cucm-phone-firmware-upgrade-troubleshooting

Last verified: 2026-10-02

# Troubleshooting Cisco IP phones stuck upgrading firmware

Before Cisco IP phones can upgrade, the files for the new load must be available at a location they can reach, most commonly the Unified CM node running the Cisco TFTP service[^12]. Cisco lists 2 causes for endpoints not upgrading after a firmware install: the device pack was not installed on the TFTP server, or the TFTP service was not restarted afterwards[^15].

## How firmware reaches the phone

A device pack COP file contains firmware files plus database updates, and installing it on the publisher updates the default firmware for the affected models[^4]. A firmware-only zip package contains individual device firmware files that the administrator must extract and upload manually to the appropriate directory on the TFTP servers, and it does not update the database defaults[^59]. After installing a device pack or firmware, restart the Cisco TFTP service on every node where it runs[^43]. After a device pack install, the Cisco Tomcat service must be restarted on all cluster nodes[^44].

In the 8800 startup sequence the phone loads the firmware image stored in flash, then requests the CTL file, then the ITL file, and only then requests its configuration file from TFTP[^2]. After a Unified CM upgrade, IP phones automatically download their new firmware[^1]. Phones cannot be used for calls while their firmware is being upgraded[^31]. Cisco offers applying new phone firmware in a controlled way before the Unified CM upgrade, as a pre-upgrade task, to reduce phone downtime after the upgrade[^39].

## How a phone's load is chosen

The default firmware load for each phone model is set in Device > Device Settings > Device Defaults[^9]. A value in the Phone Load Name field of an individual phone's configuration overrides the model's default firmware load[^28]. Device > Device Settings > Firmware Load Information lists the devices that are not using their model's default load[^11].

Cisco's procedure for upgrading a single phone starts by copying the model's current load name from Device Defaults before installing new firmware, so the default can be put back afterwards[^42]. After the COP install changes the default, the technote restores the old default in Device Defaults (using Swap Loads) so that other phones of that model stay on the old load[^50]. To move one phone to the new load, enter the new load in that phone's Phone Load Name field, Save, then click Apply Configuration and reset the phone[^34]. The running load can be checked on the phone's web page or on the phone under Settings > Model Information (Load File)[^56].

## Reading the phone's own status

On an 8800 phone, the Inactive load field appears only while a download is in progress and shows Upgrade in Progress or Upgrade Failed, with a check mark or an X per downloaded file[^13]. On an 8800 phone, Applications > Admin settings > Status > Status messages shows the 30 most recent status messages the phone has generated[^48].

| Status message | Meaning | Action |
| --- | --- | --- |
| Checksum Error | The downloaded software file is corrupted[^3] | Get a new copy of the firmware and place it in the TFTPPath directory[^3] |
| Load rejected HC | The downloaded application is not compatible with the phone hardware[^25] | Check the load ID assigned to the phone[^25] |
| TFTP access error | The TFTP server is pointing to a directory that does not exist[^51] | Check that DHCP (or the static setting) points to the correct TFTP server[^51] |

The 8800 status message TFTP timeout means the TFTP server did not respond, and the listed causes are a busy network, a connectivity problem or a TFTP server that is down[^53]. The 8800 status messages also include Trust List update failed (CTL and ITL update failed) and No Trust List installed (no CTL or ITL file on the phone)[^54].

## Diagnosing a stalled upgrade

### Device pack and file signing

The 8800 14.4(1) release notes require Unified CM to be running the latest device package before the firmware release is installed[^24]. Cisco warns that if Unified CM lacks the device package that supports an 8800 firmware release, the firmware may not work correctly[^10]. Beginning with Unified CM 14.0, all phone loads must use the SHA512 hashing algorithm and the file name must end in.cop.sha512[^46]. COP files with k3 in the name are signed with keys used by Unified CM 10.0.1 and later, and Cisco says to check the ciscocm.version3-keys.cop.sgn README before installing one on an older release, where a missing key produces 'The selected file is not valid'[^23].

### Interrupted or slow downloads

Cisco attributes firmware downloads that fail part way through mainly to network issues or congestion, and notes that Cisco Webex Wireless Phone 840 and 860 support RFC 7233 range requests so they can resume a download[^16]. For 8800 firmware 14.3(1), Cisco notes that an upgrade over the WLAN interface may take more than an hour[^58].

### Hardware version minimums and upgrade paths

Each supported hardware Version ID (VID) of Cisco IP Phone 8800 models has its own minimum firmware release[^57]. An 8800 phone that requires a newer minimum firmware cannot be loaded with an older firmware version[^32]. 8800 phones with VID V07 or earlier can run any firmware load[^55]. WarmTransfer's reading of the sources is that a newer-VID phone assigned a default or per-phone load below its hardware minimum is likely to reject that load and fail the upgrade, which matches the Load rejected HC symptom[^33].

A Cisco IP Phone 7800 may have trouble booting when upgraded directly from a release earlier than 11.5(1) to firmware 12.0(1)[^40]. For 7800 phones on firmware earlier than 11.5(1), Cisco's 2 workarounds are to upgrade to 11.5(1) first and then to 12.0(1) or later, or to upgrade directly to 12.0.1ES5 or later[^41]. Downgrading 8800 firmware from 14.3(1) or later to an earlier release can lose ringtone associations, typically on multi-line phones, and Cisco's fix is a factory reset[^45].

### Deleted loads

Unused firmware must be deleted separately on each server in the cluster[^8]. Deleted firmware loads cannot be restored except by a DRS restore, so deleting the wrong load can leave phones assigned to it unable to find their file[^7].

### Trust list failures

If neither the primary nor the backup TFTP server is listed in the CTL or ITL file on an 8800 phone, the file must be unlocked before changes to the TFTP server settings can be saved[^6]. A phone with no CTL or ITL file (or a blank ITL because of Prepare Cluster for Rollback to Pre 8.0) blindly trusts the next CTL or ITL it downloads and uses that signer from then on[^17]. Once a phone has downloaded the CTL and ITL files, it requests only signed configuration files[^22]. When phones report Trust List Verification Failed, new configuration changes do not take effect on them[^19]. We infer that a phone whose ITL no longer trusts the TFTP signer will probably not act on a new default or per-phone load assignment, because the assignment reaches it only through a configuration file it can no longer accept[^18].

Never regenerate the CallManager and TVS certificates at the same time, because if both change together, phones cannot download new files until their ITL is deleted manually[^30]. The Security By Default technote states that Cisco provides no method to delete all ITLs from phones remotely, and its documented options are the phone's settings menu and the Prepare Cluster for Rollback to pre 8.0 parameter[^20]. From Unified CM 10.0(1), an ITLRecovery key created at install or upgrade lets 'utils itl reset localkey' or 'utils itl reset remotekey' issue a reset ITL to all TFTP directories, with TFTP restarted cluster-wide, so phones regain trust in bulk[^21].

## Load servers and Peer Firmware Sharing

On Cisco IP Phone 8800 phones, Load Server names an alternate TFTP server used only for phone firmware upgrades, so images can be stored locally instead of crossing the WAN for every phone[^26]. The per-phone load server is set by entering an IP address or hostname in the Load Server field of the phone's configuration, then Save and Apply Config[^27]. A third-party load server must be able to serve every file the phone requests over HTTP on TCP port 6970 (preferred) or over UDP-based TFTP[^29]. When looking for a TFTP server, a Cisco IP Phone 8800 prefers manually assigned TFTP servers over DHCP-assigned ones, regardless of protocol[^52].

Cisco Peer-to-Peer Distribution Protocol (CPPDP) is a Cisco proprietary protocol that forms a peer-to-peer hierarchy of devices, and the Peer Firmware Sharing feature uses it[^5]. Peer Firmware Sharing is model-specific (different phone types form separate hierarchies) and works only between phones in the same subnet[^38]. PFS uses UDP broadcasts and phone-to-phone TCP child connections on port 4051[^36]. The Peer Firmware Sharing setting is taken first from the individual phone configuration, then the Common Phone Profile, then Enterprise Phone Configuration[^37]. WarmTransfer's reading of the sources is that, because current 8800 documentation still lists CPPDP as the Peer Firmware Sharing protocol, the same-model, same-subnet, port-4051 behaviour in the legacy PFS technote probably still applies to 7800/8800 phones, but that has not been confirmed in a current document[^35].

## See also

- [Cisco IP phone firmware management](https://warmtransfer.net/knowledge/cucm-phone-firmware)
- [Troubleshooting phone trust and ITL failures in Unified CM](https://warmtransfer.net/knowledge/cucm-itl-trust-troubleshooting)
- [Troubleshooting IP phones that do not get a voice VLAN or DHCP options](https://warmtransfer.net/knowledge/ip-phone-dhcp-vlan-troubleshooting)
- [Troubleshooting Cisco IP phone registration](https://warmtransfer.net/knowledge/cisco-phone-registration-troubleshooting)
- [Troubleshooting Unified CM upgrade failures](https://warmtransfer.net/knowledge/cucm-upgrade-failures)
- [Cisco IP phone end-of-sale and end-of-support dates by model](https://warmtransfer.net/knowledge/cisco-ip-phone-end-of-support)

## Applicability

Applies to: Cisco Unified Communications Manager, Cisco IP Phone 8800 Series, Cisco IP Phone 7800 Series, and Cisco Unified IP Phone. Deployments: on-premises. Sources checked 2026-10-02. The SHA512 load requirement applies beginning with Unified CM 14.0[^46]. ITL recovery with 'utils itl reset' is available from Unified CM 10.0(1)[^21]. 8800 firmware 14.4(1) lists Unified CM 8.5(1) and later as supported call control[^49]. The 7800 boot issue concerns direct upgrades from a release earlier than 11.5(1) to firmware 12.0(1)[^40].

## What remains uncertain

The upgrade path for newer PhoneOS-based Cisco desk phones on Unified CM is not covered by the sources below. Whether ITL trust state governs the firmware image download itself, rather than only configuration files, is not covered by the sources below. The specific minimum firmware values for 8800 hardware VIDs later than V07 are not covered by the sources below. The 7800 Series hardware version and minimum firmware compatibility information is not covered by the sources below. A mapping of which Unified CM device package supports which phone firmware release is not covered by the sources below. Current Load Server and Peer Firmware Sharing field syntax beyond an IP address or hostname, such as a port or base path, is not covered by the sources below. The step-by-step procedure for uploading a firmware-only zip to each TFTP node is not covered by the sources below.

## Sources

[^1]: After a Unified CM upgrade, IP phones automatically download their new firmware. Source: [Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Pre-Upgrade Tasks (Manual Process)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/upgrade/15/cucm_b_upgrade-and-migration-guide_15/cucm_m_pre-upgrade-tasks-15.html), Upgrade IP Phone Firmware. Checked 2026-10-02.
[^2]: In the 8800 startup sequence the phone loads the firmware image stored in flash, then requests the CTL file, then the ITL file, and only then requests its configuration file from TFTP. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01.html), Phone Startup Overview (steps: Load the stored phone image; Request the CTL file; Request the ITL file; Request the configuration file). Checked 2026-10-02.
[^3]: The 8800 status message Checksum Error means the downloaded software file is corrupted; the action is to get a new copy of the firmware and place it in the TFTPPath directory. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01101.html), Status Messages table, row 'Checksum Error'. Checked 2026-10-02.
[^4]: A device pack COP file contains firmware files plus database updates, and installing it on the publisher updates the default firmware for the affected models. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Install a Device Pack or Individual Firmware. Checked 2026-10-02.
[^5]: Cisco Peer-to-Peer Distribution Protocol (CPPDP) is a Cisco proprietary protocol that forms a peer-to-peer hierarchy of devices, and the Peer Firmware Sharing feature uses it. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01.html), Network Protocols (CPPDP row). Checked 2026-10-02.
[^6]: If neither the primary nor the backup TFTP server is listed in the CTL or ITL file on an 8800 phone, the file must be unlocked before changes to the TFTP server settings can be saved. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Installation](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_011.html), Configure Network Settings > IPv4 Fields. Checked 2026-10-02.
[^7]: Deleted firmware loads cannot be restored except by a DRS restore, so deleting the wrong load can leave phones assigned to it unable to find their file. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Remove Unused Firmware from the System (caution). Checked 2026-10-02.
[^8]: Unused firmware must be deleted separately on each server in the cluster. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Remove Unused Firmware from the System. Checked 2026-10-02.
[^9]: The default firmware load for each phone model is set in Device > Device Settings > Device Defaults. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Set up Default Firmware for a Phone Model. Checked 2026-10-02.
[^10]: Cisco warns that if Unified CM lacks the device package that supports an 8800 firmware release, the firmware may not work correctly. Source: [Cisco IP Phone 8800 Release Notes for Firmware Release 14.3(1)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/firmware/14-3-1/p881_b_8800-rn-1431.html), Install the Firmware Release on Cisco Unified Communications Manager. Checked 2026-10-02.
[^11]: Device > Device Settings > Firmware Load Information lists the devices that are not using their model's default load. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Find Devices with Non-default Firmware Loads. Checked 2026-10-02.
[^12]: Before endpoints can upgrade, the files for the new load must be available at a location the endpoints can reach, most commonly the Unified CM node running the Cisco TFTP service. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Device Firmware Updates Overview. Checked 2026-10-02.
[^13]: On an 8800 phone, the Inactive load field appears only while a download is in progress and shows Upgrade in Progress or Upgrade Failed, with a check mark or an X per downloaded file. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01101.html), Phone Information fields (Inactive load). Checked 2026-10-02.
[^14]: For new devices that will not register after a device pack install, the guide points to a device type mismatch in Phone Configuration and a restart of the CallManager service on the publisher. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Potential Issues with Firmware Installs (table). Checked 2026-10-02.
[^15]: Cisco lists two causes for endpoints not upgrading after a firmware install: the device pack was not installed on the TFTP server, or the TFTP service was not restarted afterwards. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Potential Issues with Firmware Installs (table). Checked 2026-10-02.
[^16]: Cisco attributes firmware downloads that fail part way through mainly to network issues or congestion, and notes that Cisco Webex Wireless Phone 840 and 860 support RFC 7233 range requests so they can resume a download. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Potential Issues with Firmware Installs (table), partial-download row. Checked 2026-10-02.
[^17]: A phone with no CTL or ITL file (or a blank ITL because of Prepare Cluster for Rollback to Pre 8.0) blindly trusts the next CTL or ITL it downloads and uses that signer from then on. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), ITL file and phone trust behaviour (no CTL/ITL present case). Checked 2026-10-02.
[^18]: A phone whose ITL no longer trusts the TFTP signer will probably not act on a new default or per-phone load assignment, because the assignment reaches it only through a configuration file it can no longer accept (inferred). Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Troubleshoot section (Trust List Verification Failed scenario). Checked 2026-10-02.
[^19]: When phones report Trust List Verification Failed, new configuration changes do not take effect on them. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Troubleshoot section (Trust List Verification Failed scenario). Checked 2026-10-02.
[^20]: The Security By Default technote states that Cisco provides no method to delete all ITLs from phones remotely; its documented options are the phone's settings menu and the Prepare Cluster for Rollback to pre 8.0 parameter. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Reset the ITL / ITL deletion options. Checked 2026-10-02.
[^21]: From Unified CM 10.0(1), an ITLRecovery key created at install or upgrade lets 'utils itl reset localkey' or 'utils itl reset remotekey' issue a reset ITL to all TFTP directories, with TFTP restarted cluster-wide, so phones regain trust in bulk. Source: [Unified Communications Manager ITL Enhancements in Version 10.0(1)](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/117598-technote-itl-00.html), ITL Recovery; utils itl reset. Checked 2026-10-02.
[^22]: Once a phone has downloaded the CTL and ITL files, it requests only signed configuration files. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Phone download sequence with SBD. Checked 2026-10-02.
[^23]: COP files with k3 in the name are signed with keys used by Unified CM 10.0.1 and later; to install one on an older release, Cisco says to check the ciscocm.version3-keys.cop.sgn README first, and a missing key produces 'The selected file is not valid'. Source: [Cisco IP Phone 8800 Series Release Notes for Firmware Release 12.0(1)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/firmware/12-0-1/release_notes/p881_b_8800-series-RN-for_12_0_1.html), Cisco Unified Communication Manager Public Keys. Checked 2026-10-02.
[^24]: The 8800 14.4(1) release notes require Unified CM to be running the latest device package before the firmware release is installed. Source: [Cisco IP Phone 8800 Release Notes for Firmware Release 14.4(1)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/firmware/14-4/p881_b_8800-rn-1441.html), Install the Firmware Release on Cisco Unified Communications Manager. Checked 2026-10-02.
[^25]: The 8800 status message Load rejected HC means the downloaded application is not compatible with the phone hardware; the action is to check the load ID assigned to the phone. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01101.html), Status Messages table, row 'Load rejected HC'. Checked 2026-10-02.
[^26]: On Cisco IP Phone 8800 phones, Load Server names an alternate TFTP server used only for phone firmware upgrades, so images can be stored locally instead of crossing the WAN for every phone. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Installation](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_011.html), Load Server. Checked 2026-10-02.
[^27]: The per-phone load server is set by entering an IP address or hostname in the Load Server field of the phone's configuration, then Save and Apply Config. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Using a Load Server (procedure). Checked 2026-10-02.
[^28]: A value in the Phone Load Name field of an individual phone's configuration overrides the model's default firmware load. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Set up Default Firmware for a Phone Model; Set the Firmware Load for a Phone. Checked 2026-10-02.
[^29]: A third-party load server must be able to serve every file the phone requests over HTTP on TCP port 6970 (preferred) or over UDP-based TFTP. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Using a Load Server. Checked 2026-10-02.
[^30]: Never regenerate the CallManager and TVS certificates at the same time; if both change together, phones cannot download new files until their ITL is deleted manually. Source: [Understand CUCM Security By Default and ITL Operation and Troubleshooting](https://www.cisco.com/c/en/us/support/docs/voice-unified-communications/unified-communications-manager-callmanager/116232-technote-sbd-00.html), Certificate regeneration guidance. Checked 2026-10-02.
[^31]: Phones cannot be used for calls while their firmware is being upgraded. Source: [Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Pre-Upgrade Tasks (Manual Process)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/upgrade/15/cucm_b_upgrade-and-migration-guide_15/cucm_m_pre-upgrade-tasks-15.html), Upgrade IP Phone Firmware. Checked 2026-10-02.
[^32]: An 8800 phone that requires a newer minimum firmware cannot be loaded with an older firmware version. Source: [Cisco IP Phone 8800 Series Compatibility](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/compatibility/p881_b_phone-8800-series-compatibility.html), Hardware versions and minimum firmware. Checked 2026-10-02.
[^33]: If a newer-VID phone is assigned a default or per-phone load below its hardware minimum, it is likely to reject that load and fail the upgrade, which matches the Load rejected HC symptom (inferred). Source: [Cisco IP Phone 8800 Series Compatibility](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/compatibility/p881_b_phone-8800-series-compatibility.html), Hardware versions and minimum firmware. Checked 2026-10-02.
[^34]: To move one phone to the new load, enter the new load in that phone's Phone Load Name field, Save, then click Apply Configuration and reset the phone. Source: [Upgrade IP Phone Firmware Individually](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/213288-upgrade-ip-phone-firmware-individually.html), Configure, Steps 7-8. Checked 2026-10-02.
[^35]: Because current 8800 documentation still lists CPPDP as the Peer Firmware Sharing protocol, the same-model, same-subnet, port-4051 behaviour in the legacy PFS technote probably still applies to 7800/8800 phones, but that has not been confirmed in a current document (inferred). Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Technical Details](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01.html), Network Protocols (CPPDP row). Checked 2026-10-02.
[^36]: PFS uses UDP broadcasts and phone-to-phone TCP child connections on port 4051. Source: [Cisco IP Phone Feature - Peer Firmware Sharing](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200615-Cisco-IP-Phone-Feature-Peer-Firmware-S.html), How PFS works. Checked 2026-10-02.
[^37]: The Peer Firmware Sharing setting is taken first from the individual phone configuration, then the Common Phone Profile, then Enterprise Phone Configuration. Source: [Cisco IP Phone Feature - Peer Firmware Sharing](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200615-Cisco-IP-Phone-Feature-Peer-Firmware-S.html), Enable PFS. Checked 2026-10-02.
[^38]: Peer Firmware Sharing is model-specific (different phone types form separate hierarchies) and works only between phones in the same subnet. Source: [Cisco IP Phone Feature - Peer Firmware Sharing](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/200615-Cisco-IP-Phone-Feature-Peer-Firmware-S.html), How PFS works. Checked 2026-10-02.
[^39]: Cisco offers applying new phone firmware in a controlled way before the Unified CM upgrade, as a pre-upgrade task, to reduce phone downtime after the upgrade. Source: [Upgrade and Migration Guide for Cisco Unified Communications Manager and the IM and Presence Service, Release 15 and SUs - Pre-Upgrade Tasks (Manual Process)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/upgrade/15/cucm_b_upgrade-and-migration-guide_15/cucm_m_pre-upgrade-tasks-15.html), Upgrade IP Phone Firmware. Checked 2026-10-02.
[^40]: A Cisco IP Phone 7800 may have trouble booting when upgraded directly from a release earlier than 11.5(1) to firmware 12.0(1). Source: [Cisco IP Phone 7800 Series Release Notes for Firmware Release 12.0(1)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/7800-series/firmware/12-0-1/release_notes/pa2d_b_7800-release-notes-for-1201.html), Upgrade from a pre-11.5(1) Firmware Release. Checked 2026-10-02.
[^41]: For 7800 phones on firmware earlier than 11.5(1), Cisco's two workarounds are to upgrade to 11.5(1) first and then to 12.0(1) or later, or to upgrade directly to 12.0.1ES5 or later. Source: [Cisco IP Phone 7800 Series Release Notes for Firmware Release 12.0(1)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/7800-series/firmware/12-0-1/release_notes/pa2d_b_7800-release-notes-for-1201.html), Upgrade from a pre-11.5(1) Firmware Release. Checked 2026-10-02.
[^42]: Cisco's procedure for upgrading a single phone starts by copying the model's current load name from Device Defaults before installing new firmware, so the default can be put back afterwards. Source: [Upgrade IP Phone Firmware Individually](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/213288-upgrade-ip-phone-firmware-individually.html), Configure, Step 2. Checked 2026-10-02.
[^43]: After installing a device pack or firmware, restart the Cisco TFTP service on every node where it runs. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Install a Device Pack or Individual Firmware. Checked 2026-10-02.
[^44]: After a device pack install, the Cisco Tomcat service must be restarted on all cluster nodes. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Install a Device Pack or Individual Firmware. Checked 2026-10-02.
[^45]: Downgrading 8800 firmware from 14.3(1) or later to an earlier release can lose ringtone associations, typically on multi-line phones, and Cisco's fix is a factory reset. Source: [Cisco IP Phone 8800 Release Notes for Firmware Release 14.4(1)SR2](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/firmware/14-4-1SR2/p881_b_8800-rn-1441sr2.html), Limitations and restrictions (firmware downgrade note). Checked 2026-10-02.
[^46]: Beginning with Unified CM 14.0, all phone loads must use the SHA512 hashing algorithm and the file name must end in .cop.sha512. Source: [Cisco IP Phone 8800 Release Notes for Firmware Release 14.0(1)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/firmware/14_0_1/p881_b_release-notes-for-140.html), Install the Firmware Release on Cisco Unified Communications Manager. Checked 2026-10-02.
[^47]: In 8800 firmware 14.4(1)SR2, the size of each firmware file downloaded during an upgrade is checked against the size recorded in the loads file to confirm integrity. Source: [Cisco IP Phone 8800 Release Notes for Firmware Release 14.4(1)SR2](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/firmware/14-4-1SR2/p881_b_8800-rn-1441sr2.html), Release notes body (exact section not identified by fetch). Checked 2026-10-02.
[^48]: On an 8800 phone, Applications > Admin settings > Status > Status messages shows the 30 most recent status messages the phone has generated. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01101.html), Display the Status Messages Window. Checked 2026-10-02.
[^49]: 8800 firmware 14.4(1) lists Unified CM 8.5(1) and later as supported call control. Source: [Cisco IP Phone 8800 Release Notes for Firmware Release 14.4(1)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/firmware/14-4/p881_b_8800-rn-1441.html), Related Hardware and Software / Unified CM compatibility. Checked 2026-10-02.
[^50]: After the COP install changes the default, the technote restores the old default in Device Defaults (using Swap Loads) so that other phones of that model stay on the old load. Source: [Upgrade IP Phone Firmware Individually](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/213288-upgrade-ip-phone-firmware-individually.html), Configure, Steps 4-5. Checked 2026-10-02.
[^51]: The 8800 status message TFTP access error means the TFTP server is pointing to a directory that does not exist; the action is to check that DHCP (or the static setting) points to the correct TFTP server. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01101.html), Status Messages table, row 'TFTP access error'. Checked 2026-10-02.
[^52]: When looking for a TFTP server, a Cisco IP Phone 8800 prefers manually assigned TFTP servers over DHCP-assigned ones, regardless of protocol. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Cisco IP Phone Installation](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_011.html), Configure Network Settings > IPv4 Fields. Checked 2026-10-02.
[^53]: The 8800 status message TFTP timeout means the TFTP server did not respond; listed causes are a busy network, a connectivity problem or a TFTP server that is down. Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01101.html), Status Messages table, row 'TFTP timeout'. Checked 2026-10-02.
[^54]: The 8800 status messages include Trust List update failed (CTL and ITL update failed) and No Trust List installed (no CTL or ITL file on the phone). Source: [Cisco IP Phone 8800 Series Administration Guide for Cisco Unified Communications Manager - Monitoring Phone Systems](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/adminguide/P881_BK_C136782F_00_cisco-ip-phone-8800_series/P881_BK_C136782F_00_cisco-ip-phone-8811-8841_chapter_01101.html), Status Messages table, rows 'Trust List update failed' and 'No Trust List installed'. Checked 2026-10-02.
[^55]: 8800 phones with VID V07 or earlier can run any firmware load. Source: [Cisco IP Phone 8800 Series Compatibility](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/compatibility/p881_b_phone-8800-series-compatibility.html), Hardware versions and minimum firmware. Checked 2026-10-02.
[^56]: The running load can be checked on the phone's web page or on the phone under Settings > Model Information (Load File). Source: [Upgrade IP Phone Firmware Individually](https://www.cisco.com/c/en/us/support/docs/unified-communications/unified-communications-manager-callmanager/213288-upgrade-ip-phone-firmware-individually.html), Verify. Checked 2026-10-02.
[^57]: Each supported hardware Version ID (VID) of Cisco IP Phone 8800 models has its own minimum firmware release. Source: [Cisco IP Phone 8800 Series Compatibility](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/english/compatibility/p881_b_phone-8800-series-compatibility.html), Hardware versions and minimum firmware table. Checked 2026-10-02.
[^58]: For 8800 firmware 14.3(1), Cisco notes that an upgrade over the WLAN interface may take more than an hour. Source: [Cisco IP Phone 8800 Release Notes for Firmware Release 14.3(1)](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cuipph/8800-series/firmware/14-3-1/p881_b_8800-rn-1431.html), Install the Firmware Release (WLAN note). Checked 2026-10-02.
[^59]: A firmware-only zip package contains individual device firmware files that the administrator must extract and upload manually to the appropriate directory on the TFTP servers; it does not update the database defaults. Source: [Administration Guide for Cisco Unified Communications Manager, Release 15 and SUs - Manage Device Firmware](https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/15/adminGd/cucm_b_administration-guide-15/cucm_b_test-adminguide_chapter_0110.html), Install a Device Pack or Individual Firmware. Checked 2026-10-02.
