Onyx VoiceDocumentation
All chapters

Docs / Reference

Server settings reference

Server settings apply to the whole server and every tenant on it: the ports and network addresses of the phone engine, outgoing mail, desk phone provisioning, intrusion prevention, two-factor sign-in and Let's Encrypt. This chapter lists every setting with what it does, its default and the values it accepts, and where to change it.

Where to change them

Most settings are on the Server settings page of the console (system administrators only). The page has three groups: Calls and network (the engine.* keys), Voicemail e-mail (smtp.*) and Desk phone provisioning (provisioning.*). To change one:

  1. Open Server settings.
  2. Type the new value in the setting's field. An empty field shows the default in grey.
  3. Press Save next to it (or Enter). A wrong value is refused with a message saying what it must be.

The other settings have their own place in the console:

  • security.* (except the alert address): the Security page, cards When to block and Two-factor sign-in.
  • security.alert_email: the Call limits page, card Alerts.
  • tls.*: the Security page, card Certificate.

From a shell, every setting works the same way with onyx:

sudo onyx setting list
sudo onyx setting set engine.external_address 203.0.113.10
sudo onyx setting unset engine.external_address

setting list shows each key with its value, or (default) and the default. setting set checks the value and saves it. setting unset removes the setting so the default applies again; the console has no button for that. Values are trimmed of spaces at both ends. See Command line (onyx).

Changes reach the engine within a second. A few need the engine to restart: the SIP TLS port, the certificate files, and turning a STUN server on or off. The engine restarts by itself once no calls are up, so calls in progress are not cut. Every change is recorded in Change history.

The first-boot setup (onyx-setup) writes two of these settings for you: engine.hostname (the server's name) and engine.external_address (the public address, when you said the server sits behind NAT).

Calls and network

KeyConsole labelWhat it doesDefaultAllowed values
engine.hostnameServer nameThe name phones, softphones and browsers use to reach the server. Desk phone provisioning, the certificate and Let's Encrypt use it.this machine's host namea host name, e.g. pbx.example.com
engine.external_addressPublic addressThe router's public address, announced in calls when the server is behind NAT and phones or carriers reach it from the internet. Without it, outside calls through NAT have one-way or no audio.empty (no NAT)an IP address or host name, or empty
engine.local_netsLocal networksNetworks the server reaches without NAT. Calls to addresses in these networks use the server's own address; everything else gets the public address. Also the default for who may fetch phone settings.10.0.0.0/8,172.16.0.0/12,192.168.0.0/16networks in CIDR form, comma separated
engine.sip_portSIP portPort for SIP over UDP and TCP.50601-65535
engine.sip_tls_portSIP TLS portPort for SIP over TLS (encrypted calls).50611-65535
engine.rtp_startAudio ports fromFirst UDP port for call audio (RTP).100001-65535
engine.rtp_endAudio ports toLast UDP port for call audio.200001-65535
engine.codecsPhone codecsCodecs offered to phones and softphones, in order of preference.g722,ulaw,alawcomma separated from g722, ulaw, alaw, gsm, g726, speex, opus, h264, vp8
engine.tone_zoneCountry tonesThe dial, ringing and busy tones callers hear. us and ca also make 10-digit numbers count as North American (a leading 1 is added to DIDs and caller lookups).usus, ca, uk, au, de, fr, nl
engine.stun_serverSTUN serverA STUN server the engine asks for its public address. Only for servers behind NAT whose public address changes; a fixed engine.external_address is better.empty (none)host or host:port
engine.tls_cert_fileCertificate fileYour own certificate (PEM), used for SIP TLS and the console and portal. Leave empty to use Let's Encrypt or the server's self-signed certificate.emptyan absolute path
engine.tls_key_fileCertificate key fileThe private key (PEM) for engine.tls_cert_file.emptyan absolute path
engine.device_qualifyPhone keepalive (seconds)How often the engine checks that each registered phone is still there. The check also keeps NAT routers from forgetting remote phones.600 (never) or 10-3600

Notes:

  • If you change engine.sip_port, engine.sip_tls_port or the audio port range, change the firewall and any port forwards on the router to match. See Network, NAT and firewall.
  • The certificate files are used only when both files exist. See Names and certificates.
  • Codecs that a trunk uses are set on the trunk, not here. See Trunks (carriers).

Voicemail e-mail

Onyx Voice sends voicemail to e-mail, call limit alerts and test messages through an SMTP server you choose.

KeyConsole labelWhat it doesDefaultAllowed values
smtp.hostMail serverThe SMTP server that sends the mail. Nothing is sent while it is empty.emptya host name or IP address
smtp.portMail portThe server's port.587, or 465 when smtp.security is tls1-65535
smtp.securityMail encryptionstarttls connects in plain and upgrades to TLS; tls uses TLS from the start; none sends unencrypted.starttlsnone, starttls, tls
smtp.usernameMail usernameThe sign-in name, when the server wants one.empty (no sign-in)any text
smtp.passwordMail passwordThe password. It is never shown: the console says "Set (type to replace)" and onyx setting list shows (set).emptyany text
smtp.fromMail senderThe From address of every message. The display name stays (for example the caller's name on a voicemail). Use an address your mail server is allowed to send as, or SPF and DMARC checks may reject the mail.empty (the message's own sender)an e-mail address

To check the settings, run sudo onyx mail test [email protected]. It prints sent, or the mail server's error.

Desk phone provisioning

KeyConsole labelWhat it doesDefaultAllowed values
provisioning.allowed_netsPhones may fetch settings fromThe networks desk phones may download their settings from. Requests from other addresses are refused. any allows the internet, for remote phones.empty = the networks in engine.local_netsnetworks in CIDR form, comma separated; any; or empty
provisioning.ntp_serverTime server for phonesThe time server written into the phones' settings.pool.ntp.orga host name, or empty for the default
provisioning.pnpPlug-and-playWhether the server answers new phones that announce themselves on the local network (Yealink, Grandstream, Fanvil, Snom, Htek).onon, off
provisioning.pnp_tenantTenant for new plug-and-play phonesThe tenant whose phone list a new phone joins when its MAC address is not assigned anywhere yet. Empty means the only tenant, when there is just one; with several tenants and no value, unknown phones are not answered.emptya tenant code, or empty

Plug-and-play answers only phones in the networks of provisioning.allowed_nets. See Desk phones.

Intrusion prevention and two-factor sign-in

These are on the Security page. The labels below are that page's.

KeyConsole labelWhat it doesDefaultAllowed values
security.ban_afterFailed sign-insHow many failed sign-ins (phones, softphones or the console) from one address block it.100 (never block) or 3-1000
security.ban_windowWithin (minutes)The time the failures must fall within.101-1440
security.ban_minutesBlock for (minutes)How long a block lasts.600 (until an administrator lifts it) up to 525600
security.never_banNever blockAddresses and networks that are never blocked: your offices, admin addresses and the server's own addresses (only 127.0.0.1 is exempt by itself).emptyaddresses or CIDR networks, comma separated
security.require_2faRequire it for administratorsWith admins, every administrator must sign in with an authenticator code as well as the password; those who have not set it up are asked to at their next sign-in.offoff, admins

The intrusion prevention settings are read again every 30 seconds. The two-factor requirement takes effect within half a minute. See Security.

Call limit alerts

KeyConsole labelWhat it doesDefaultAllowed values
security.alert_emailSend alerts to (Call limits page)Who gets an e-mail when a call limit stops a tenant's outside calls. Sent through the smtp.* settings.empty (no alerts)e-mail addresses, comma separated

See Call limits (toll fraud).

Let's Encrypt

These are set together in the Certificate card of the Security page, not one by one.

KeyConsole fieldWhat it doesDefaultAllowed values
tls.acmeGet a certificate for <server name> from Let's Encrypt and renew it automaticallyTurns Let's Encrypt on. The server's name (engine.hostname) must be a public DNS name pointing at the server, with port 80 open to the internet.offon, off
tls.acme_emailContact e-mailThe address the certificate authority writes to about expiry problems. The console will not turn Let's Encrypt on without it.emptyan e-mail address
tls.acme_extra_namesAlso valid forMore names on the same certificate, for example an old name kept while phones move to the new one. Each needs a DNS record pointing at the server.emptyhost names, comma separated
tls.acme_serverACME directory (under Test server (staging, Pebble))Another ACME server instead of Let's Encrypt, such as Let's Encrypt's staging server for tests.empty = Let's Encryptan https:// directory URL
tls.acme_ca_fileTest server's CA file (same place)The certificate authority file of a test ACME server, trusted only for talking to that server.emptyan absolute path

When you turn Let's Encrypt on in the console you must also tick I accept the Let's Encrypt subscriber agreement. Setting tls.acme to on with onyx setting set skips that check box, so read the agreement first. See Names and certificates.

Settings you cannot change

The server also keeps the passwords the control plane uses to talk to the engine. They are made on the first start, are not listed by onyx setting list, and onyx setting set refuses them.