CloudUCM – FAQ

This Frequently Asked Questions (FAQ) document provides concise answers and guidance for using the CloudUCM. It is intended to assist administrators and users in resolving common issues and understanding key features.


Product Overview & Specifications

CloudUCM is a cloud-based PBX that requires no hardware for deployment, significantly reducing maintenance costs. IP phones and Wave can connect to CloudUCM from anywhere as long as they are connected to the Internet and can be used for audio calls/video calls/meetings, allowing people around the world to easily collaborate with one another.

For more details, please refer to: https://myucm.cloud/

While both CloudUCM and UCM are stable and efficient phone systems with their own advantages, CloudUCM has the following benefits:

  • Cost-Savings: CloudUCM services are on cloud servers, significantly reducing on-premises deployment and maintenance costs.
  • Scalable: Easily expand your phone system capabilities as your business evolves without complex professional maintenance.
  • Flexible Remote Office: Empowers employees to work remotely and communicate effortlessly from anywhere with any device.
  • High Availability: 99% availability of services through AWS and immune to local disasters and outages.
  • One-stop Work Platform: With CloudUCM, you have a comprehensive add-in ecosystem, integrating rich CRM systems, Live Chat, WhatsApp, MS Teams, Hot desk and other collaborative add-ins, as well as support for custom internal add-ins for companies.

Please consider the following questions and essential features when you look for a good cloud PBX provider:

  • Do you need any advanced features in addition to the standard phone system features?
  • Do they support remote working and mobile working?
  • Do they allow you to integrate your system with 3rd party platforms and provide easy-to-use add-ins?
  • Do they offer cloud PBX services as part of a unified communications solution, enabling users to take their experiences to the next level with features such as comprehensive remote management of PBX and VoIP devices?
  • Do their cloud servers provide a stable and reliable service?
  • Do they place their servers in geographically dispersed data centers?
  • Do they have the ability to integrate with your existing trunk server?
  • Do they provide ongoing customer support and system updates?

CloudUCM has all of these features above.

CloudUCM converts capital expenditures into operating expenditures.

  • Minimum initial investment is required to get started. Aside from IP endpoints, you would only pay an ongoing subscription fee every year.
  • With SIP trunk features, you have the flexibility to choose service providers based on your own budget and needs.
  • No maintenance costs. For small businesses with limited resources, CloudUCM does not require dedicated IT staff to manage and maintain the system.

Currently not supported. HA redundancy between CloudUCM and UCM63xx/CloudUCM is in the future plan.


Initialization & Activation

No. RemoteConnect features are already included with your CloudUCM purchase. UCM RemoteConnect is a cloud service for physical UCM systems that enables administrators to securely manage their systems remotely, register IP phones from any location, and support calling from remote networks without the need for complex firewall configurations.

When the CloudUCM plan expires, your CloudUCM will stop running and can no longer be used. We will temporarily preserve the data in the cloud server for up to 30 days, during which you can renew your plan. Please be mindful of plan expiration dates and renew at your earliest convenience.

CloudUCM subscription plans are sold by authorized resellers. You can place orders for CloudUCM plans by contacting your Grandstream equipment reseller.

You can sign in to the GDMS to request a trial or contact your Grandstream equipment reseller.

For GDMS “Personal” and “Enterprise” users, one CloudUCM trial is allowed per GDMS account at any given time. Once the trial is converted to a paid plan, the GDMS user can apply for a new trial again.

For GDMS “Service Provider,” “Reseller,” and “System Integrator” users, up to five CloudUCM trials are allowed per GDMS account at any given time. Once a trial ends or is converted to a paid plan, the GDMS user can apply for a new trial again.

The plan will not take effect until the CloudUCM device has been activated. For example, if you purchase a 1-year Plus plan on April 2nd, 2024, and the device is not activated until May 5th, 2024, the plan will take effect from May 5th, 2024 up to May 5th, 2025.

Yes. Since CloudUCM plans take effect only when the CloudUCM devices are activated, there is no cost or fee for holding plans for unactivated devices. Additionally, this allows for quick responses to customer requirements.

No. Each CloudUCM device is a cloud PBX virtual machine with its own separate storage space for data and files. Sharing a CloudUCM with other customers may result in fatal security and privacy breaches.

A channel reseller can purchase a CloudUCM plan for each customer separately based on their deployment requirements such as the number of extensions and concurrent calls (see CloudUCM Plan Specifications).

Yes. You would need to subscribe to the CloudUCM plan for this CloudUCM to continue using it.

You can set up regular storage cleanup through the CloudUCM’s Maintenance page or purchase an add-on plan to expand your storage space.

If the existing number of extensions exceeds the max limit of the new plan, the excess extensions will need to be deleted within 7 days. Otherwise, all extensions will be disabled and cannot be used.

If the storage space usage exceeds the max limit of the new plan, several CloudUCM services such as calling, and meetings will become inaccessible until the excess data is cleared.

Yes. Otherwise, you will not be able to use it. You can activate a CloudUCM on GDMS or click the activation link in the CloudUCM activation email. Once activated, the CloudUCM will be running and accessible for management.

Concurrent calls are calculated assuming a call between a caller and callee counts as a single call. In contrast to the way UCMRC remote calls counts the caller and callee lines as two separate calls if both parties are registered via UCMRC, the same call would be counted as only one call with CloudUCM.

Note:

In an N-way conference, each party would count towards the concurrent call limit (e.g., 3-way conference members would count as three concurrent calls).

Yes. Each extension that’s rung in a queue call or ring group call will count as 1 call towards the concurrent call limit. Please be mindful of this when purchasing a plan and setting up your queues and/or ring groups.

Yes. Please refer to the Plan Specifications page to see the concurrent registration limits of each plan. While any SIP endpoint/softphone client can register to a CloudUCM extension as long as it doesn’t exceed the concurrent registration limit, each extension can have only one Wave PC registration and one Wave Mobile registration.


Call Management & Advanced Features

No. The call duration and concurrent number of emergency calls are not restricted by any CloudUCM plan specifications. 

You can use the Forwarding Exemption List (or Whitelist) in your extension’s Call Policy. Calls from numbers on this list will ring your extension normally and will not be forwarded, even if call forwarding is active.

Call Privileges (Internal, Local, National, International) control which outbound routes a user can access. A user must have a privilege level equal to or higher than the level set on an outbound route to make calls using that route. For example, a user with “Local” privileges cannot use a route set to “National”.

Yes. In the extension’s Features settings, you can set a “Maximum Call Duration”. Once this time limit (in seconds) is reached, the call will be automatically terminated.

Yes. In the Extensions→Features→Call Settings section, you can set “The Maximum Number of Call Lines” for the extension. A value of 0 indicates no limit. This prevents a single extension from using all available call paths.

In the Extension→Media tab, you can reorder and prioritize codecs for each extension. This allows you to force specific codecs for certain users (e.g., G.722 for HD voice quality).


LDAP & Phonebook Management

In the extension’s settings under the Features→Other Settings tab, users can configure the “Enable LDAP” option to remove or include the extension in the CloudUCM LDAP phonebook.

Yes. When you configure a SIP Peer Trunk to another UCM, you can enable the “Sync LDAP Enable” option in the trunk’s advanced settings. This allows the two PBXs to automatically exchange and sync their local LDAP phonebooks, creating a unified directory.

You can directly export the LDAP phonebook in CSV, XLS, VCF, and XML format by navigating to System Settings→LDAP Server→LDAP Phonebook. On this page, you will find an “Export Selected Phonebook” button which allows you to download the directory entries.

Yes, any device or application that supports standard LDAP protocol can connect to the CloudUCM LDAP server. This includes phones from other manufacturers, email clients, CRM systems, and mobile applications that support LDAP directory integration.

No. The default PBX phonebook (ou=pbx,dc=pbx,dc=com) cannot be edited or deleted from the LDAP phonebook section. To edit the contacts, please update extension information under Extensions, and changes will sync automatically.

On the phone, configure:

  • LDAP Server Address: [CloudUCM IP]
  • Port: 389
  • Base DN: dc=pbx,dc=com
  • Username: cn=admin,dc=pbx,dc=com
  • Password: [CloudUCM LDAP Root Password]
  • LDAP Name Attributes: CallerIDName, Email, Department, FirstName, LastName, etc.
  • LDAP Number Attributes: AccountNumber, MobileNumber, HomeNumber, etc.

You need to enable the global setting that allows LDAP contacts to appear in Wave. Navigate to System Settings→LDAP Server→LDAP Phonebook→LDAP Settings and ensure “Display LDAP Contacts on Wave” is enabled.


Configuration, Provisioning, & Firmware

  • Method 1: For Grandstream endpoints only:
    • Add the Grandstream IP phone to GDMS. Look for the newly added phone on the VoIP Device page. In the Options column for that phone, click on the button to enter the Account Configuration page. Select the desired CloudUCM extension and save your settings.
  • Method 2: If the endpoint is not on GDMS, cannot be added to GDMS, or is from another manufacturer, you can register it to CloudUCM by configuring the settings in the following table.

For more details, please refer to the document How to Configure CloudUCM on IP Phones.

Settings

Parameters

Values

Account Settings→Basic Settings

(Required)

SIP Server

CloudUCM SIP Server Address.

This information can be found under Web GUI→CloudUCM Plan page.

Note: Must include port number. By default, UDP/TCP is 5060, and TLS is 5061.

(Example: xxx.a.myucm.cloud:5061)

Account

Enter the desired extension on the CloudUCM.

Password

Enter the extension’s SIP password.

NAT Traversal

STUN

DNS Mode (Optional)

SRV

DNS SRV Failover Mode (Optional)

Use current server until no response

Account Settings→SIP Settings

(Optional. While TLS is recommended, UDP and TCP are also supported)

SIP Transport

Supports TLS/UDP/TCP. It is recommended to use TLS or TLS/TCP for security reasons.

Account Settings→SIP Settings

(Optional. If your network environment is not stable, configuring these is recommended.)

REGISTER Expiration (m)

50 (TLS or TCP)

3 (UDP)

Enable Session Timer

Yes

Session Expiration (s)

600

Min-SE (s)

90

Caller Request Timer

Yes

Callee Request Timer

Yes

UAC Specify Refresher

UAC

UAS Specify Refresher

UAS

Security Settings→TLS Settings

(Required)

Minimum TLS Version

1.2 or 1.3

Maximum TLS Version

1.2 or 1.3

There are two ways:

  • Method 1: Customers can directly enter the CloudUCM’s address into their address bar (e.g. https://test-aaa.m.myucm.cloud:8443) to bring up the CloudUCM management portal.
  • Method 2: The channel reseller can create and assign a sub-account on GDMS to each customer, and the customer can log into GDMS with those accounts and access their CloudUCM.

Yes. You can add a CloudUCM device to GDMS using its MAC address and initial password. When adding the device, you must also assign it to a site, as site selection is a required field.

Once added, the CloudUCM can be remotely managed through GDMS, including operations such as synchronizing extensions, remotely accessing the CloudUCM management portal, upgrading firmware, rebooting, and resetting the device to factory settings.

Yes. CloudUCM supports register trunks, peer trunks, and WebRTC trunks.

  • On the PBX Settings→SIP Settings→Transmission Protocol page, you can enable all transport protocols needed for your trunks. Only TLS is enabled by default.
  • Peer Trunk:
    1. You need to configure Provider Name, Host Name, and Transport.
    2. If the other party is a CloudUCM, the host name would be the domain address of the CloudUCM, and you will need to enable the Domain Connection Mode.
    3. If the other party is a UCM63xx with UCMRC services, the host name is the UCMRC domain address of the UCM63xx device with the port number (5061), the transport protocol is TLS, and you will need to enable the Domain Connection Mode.
  • Register Trunk:
    1. You need to configure Provider Name, Host Name, Transport, Registration Number, and Password.
    2. If the other party is a CloudUCM, the host name is the domain address of the CloudUCM.
    3. If the other party is a UCM63xx with UCMRC services, the host name is the UCMRC domain address of the UCM63xx device with the port number (5061), and the transport protocol is TLS.
  • DID Access: This is a new option that was added in firmware 1.0.27.18. If the service provider does not include domain in the “To” SIP header value, users can specify a DID to use for verifying incoming calls. However, this may cause incoming calls to fail due to incompatibility with service providers or improper configuration.
  • Port Access: The default behavior before DID Access mode was added in firmware 1.0.27.18. This sends outbound SIP traffic out from port 5060 and receives SIP requests on port 6040. This is the recommended option unless the service provider requires otherwise.

CloudUCM supports integrating and deploying with PSTN Analog Trunks and SIP Trunk Providers under private and external networks and supports mutual Trunk registration with other UCMs/CloudUCMs. Please refer to the CloudUCM Deployment Scenario Instructions for more details.

Yes. You can create multiple organizations or sites on the GDMS platform to manage CloudUCM for your customers. For different customers, it is recommended to create multiple organizations and add CloudUCMs for different customers to different organizations for management. Each organization has its own CloudUCM devices, VOIP devices, extensions, tasks, and other data.

If a customer needs different CloudUCMs under one organization to be managed by separate departments, you can create multiple sites under the organization and add CloudUCMs to those different sites for management.

For more details, please refer to the CloudUCM Multi-tenant Management User Guide.

While creating the SIP trunk, the user needs to uncheck the option “Keep Trunk CID”, fills in the “From User” field with the trunk username, and configures the DOD number correctly. Then, the FROM header will be filled with the trunk username, and the Remote-Party-ID header will carry the DOD number simultaneously in the SIP messages.

If the user wants to display the configured DOD number on the callee side, the user needs to uncheck option “Keep Trunk CID” for the SIP trunk.

  1. If you need to set your CloudUCM to register to the peer device, you need to set it to a Register SIP Trunk.
  2. If the peer device does not have a fixed address, you can select to configure the Account SIP Trunk, and set the peer device to register to the account trunk number in the CloudUCM. After the CloudUCM successfully registers the peer device, the CloudUCM obtains the address of the peer device.
  3. For other usage scenarios, it is recommended to configure as Peer SIP Trunk.
  1. Please check the Inbound Routes→Pattern settings and see if the pattern settings have been correctly configured.
  2. Please check the Blacklist settings in the Inbound Routes module and see if the inbound call number is on the blacklist.
  3. Please check the option “Verify Inbound Requests” in your VoIP Trunks settings. If this option is enabled, the entry request is authenticated. If the peer party does not support the authentication initiated by the registration terminal, please do not check this option.  

Troubleshooting & Maintenance

All system activities are logged in the Operation Log, which can be found under Maintenance→Operation Log and includes configuration changes, login events, and administrative actions.

Note:

The super admin can view logs from all users.

CloudUCM follows a Login Timeout value defined under Maintenance→Login Settings→Login Security. The default timeout is 10 minutes, and you can set it to 0 if you do not want automatic logout.

The super admin can lift bans manually by selecting the banned user/IP and clicking Lift Ban in Maintenance→Login Settings→Login Security.

CloudUCM provides an integrated Ethernet Capture tool that can be used for troubleshooting, and can be found in Maintenance→Network Troubleshooting→Ethernet Capture.

SSL/TLS packets can be decrypted in Wireshark as long as the capture includes the full TLS handshake. Users can choose to enable or disable the “TLS Key” option when starting the capture.

Yes. CloudUCM supports Concurrent Multi-user Login. However, if two users try to modify the same configuration, CloudUCM will show a prompt.

Your admin account may not have the necessary Custom Privileges assigned. To verify this, navigate to Maintenance→User Management→Custom Privilege.


Network & Security

CloudUCM provides a Geo-IP Access Control feature that allows administrators to block all access from specific countries or regions. This restriction applies to Web GUI login, API requests, and extension registration.

Please follow the steps below to configure:

  1. Go to System Settings → Security Settings → Geo-IP Access Control
  2. Choose the countries you want to block
  3. (Recommended) Ensure your own IP address is not within any blocked region before enabling this feature

Yes. CloudUCM supports allowing only approved IPs to access the Web UI or API. To set this up, please follow the steps below:

  1. Go to System Settings → HTTP Server → CloudUCM Web Settings
  2. Enable “IP Address Whitelist” and add permitted IPs in CIDR or IPv6 format
  3. Click on Save and apply the changes

Once enabled, all non-whitelisted IPs will be denied access.

Yes. All CloudUCM data and files are encrypted by default, including recordings, logs, and system data.

Only the super admin can update the encryption key, which can be exported and used to decrypt the data using a Grandstream decryption tool. This can be configured under System Settings→Security Settings→Data/File Encryption.

CloudUCM supports:

  • Authentication App (Google/Microsoft Authenticator)
  • TOTP Hardware Token
  • FIDO Security Key

MFA can be enabled per CloudUCM user under Maintenance→User Management→System User Information.

Yes. CloudUCM can send alerts to users via Email and SMS notifications. The alert events can be configured under Maintenance → System Events.


Was this article helpful?

Need Support?
Can’t find the answer you’re looking for? Don’t worry we’re here to help!
Contact Support