GSC356x – User Manual

  • Updated on June 15, 2026

WELCOME

Thank you for purchasing the Grandstream GSC3560/GSC3565.

The GSC3560/GSC3565 is a smart outdoor intercom that functions as an advanced access control system, delivering secure facility access and real-time monitoring for buildings of all sizes.

Key features include:

  • A durable metal casing with IP66 weatherproofing and IK10 vandal resistance for reliable operation in harsh environments
  • Built-in dual microphones and a high-power 10W speaker for clear two-way intercom communication
  • PoE support for streamlined installation with a single network cable
  • Multiple alarm interfaces (alarm-in, relay-out, RS485, line-out) for integration with existing security systems
  • Support for various door access methods, including mobile app, SIP call, HTTP API, and QR code (GSC3565 only)

The GSC3560/GSC3565 can be integrated with Grandstream multimedia phones, GSC3570/GSC3574/GSC3575 indoor control stations, and GS Wave soft phones and desk phones, which enables a complete, unified building security solution.

With advanced security design, including Solid State Relay (SSR) technology, the device provides strong protection against magnetic interference and unauthorized access attempts.

Additional capabilities include:

  • Support for multiple intelligent alarms such as intrusion detection, loitering detection (GSC3565 only), tamper alerts, and high-temperature warnings…
  • AI-based motion detection (GSC3565 only) for enhanced monitoring and automation
  • Built-in white LED lighting for improved visibility in low-light conditions (GSC3565 only)
  • Event-triggered snapshots sent to email, FTP servers, or mobile applications (GSC3565 only)
  • Support for cloud management and access control mobile applications

The GSC3565 model further enhances functionality with 4MP HDR imaging, H.264 video compression, and a wide 152° field of view, providing high-quality 1080p video for clear identification and monitoring.

With its robust design, flexible integration options, and intelligent security features, the GSC3560/GSC3565 is an ideal solution for smart offices, residential complexes, industrial parks, and small-to-medium enterprises seeking reliable and scalable access control.

PRODUCT OVERVIEW

Feature Highlights

The following table contains the major features of the GSC356X series.

  • Audio-only intercom with no camera or video-related features

  • Dual microphones with 5.5m pickup range and high-power 10W HD speaker

  • SIP-based communication with door control via integrated SSR relay

  • Supports Grandstream SecureAccess app and cloud connectivity

  • Multiple alarm input/output ports with built-in tamper protection

  • Rugged outdoor design with IP66 weatherproof and IK10 vandal resistance

  • Full HD video intercom with 4MP HDR camera supporting H.264 and 1080p streaming

  • AI-based motion detection with up to 120dB wide dynamic range for clear imaging

  • Multiple door access methods including mobile app, QR code, SIP call, and HTTP API

  • Advanced alarm system supporting intrusion, tamper, temperature, and security alerts

  • Dual microphones with 5.5m pickup range and high-power 10W HD speaker

  • ONVIF Profile S support with SIP, RTSP streaming, and cloud/app integration

GSC356X Features at a Glance

Technical Specifications

The following table summarizes all the technical specifications, including the protocols/standards supported, voice codecs, telephony features, and upgrade/provisioning settings for GSC356X.

GSC3560

GSC3565

Image Sensor Resolution

Not Supported

1/3”, 4MP, HDR

Lens Type

Not Supported

4M CMOS sensor, LENS: 127(H) x70(V)x 152°(D)

Day & Night

Not Supported

6x White LED

Max Resolution

Not Supported

Video: 1920*1080, Snapshots: 1920*1080

Minimum Illumination

Not Supported

30 frames per second

Wide Dynamic Range

Not Supported

Yes, up to 120db

Embedded Analytics

Not Supported

AI-based Motion detection

Microphone

Two mics, pickup distance up to 5.5m

Speaker

90dB hands-free call and 100dB broadcast. max 10W

APP

Support Cloud, Grandstream SecureAccess Mobile App

Snapshots

Triggered upon events, sent to Email, FTP Server, Grandstream SecureAccess App and/or Local

Network Protocol

TCP/IP/UDP , RTP/RTCP , HTTP/HTTPS local upload and mass provisioning using TR-069 , ARP/RARP, ICMP, DNS (A record, SRV, NAPTR) ,DHCP ,SSH ,SMTP, TFTP, NTP, STUN, SIMPLE, TLS, SRTP

Telephony Features

SIP Paging, Multicast Paging, call-waiting with priority override

Audio Codecs

G.711µ/a, G.722 (wide-band), G.726-32, G.729 in-band and out-ofband DTMF (In audio, RFC2833, SIP INFO), VAD, CNG, AEC, PLC, AJB, AGC, ANS

Video Codecs

Not Supported

H264 High Profile / Main Profile / Base Profile, Motion JPEG

QoS

Layer 2 (802.1Q, 802.1p), 802.11e and Layer 3 (ToS, DiffServ, MPLS) QoS

Security

User and administrator level passwords, Ed25519 and X25519 based authentication, 256-bit AES encrypted configuration file, TLS, SRTP, HTTPS, 802.1x media access control

Upgrade/ Provisioning

Firmware upgrade via TFTP/HTTP/HTTPS, mass provisioning using TR-069 or AES encrypted XML configuration file

Button

  • 1x anti-tamper button

  • 1x doorbell key

  • 1x reset button

Access Control

1xSSR

Auxiliary Ports

2x Alarm in ports, 2x Relay out ports, 1x differential line out port

Network Interface

1x RJ45, One 10/100 Mbps port with integrated PoE

Expansion Interface

RS485, SD card slot (up to 256GB)

Power & Green Energy Efficiency

DC power supply: 12-48V/2A 24W PoE: 802.3at class4

Dimensions (H x W x D) and Weight

Unit: 200mm x 120mm x 40mm Weight: 0.732KG
Package Weight: 1.551KG

Interoperability

ONVIF (Profile S)

Package

1* GSC3560/65 Device,

1* Quick Installation Guide,

1* Certification Regulatory Information,

1* Install Positioning Sticker,

5* (PA 3.5 x 33 mm )Screw,

1* ( PM 3 x 6 mm ) Ground Wire Screw, 5* (KM4*14mm)Screw,

5* Expansion bolt, 1* Screwdriver, 1* Ground Wire,

1* Waterproof silicone plug,

1* Wall Mounting Position Sticker, Pole bracket (optional),

Flush Mount Bracket(optional)

Installation type

Wall Mount, Pole Mount (optional), Flush Mount (optional)

Temperature and Humidity


Operating Temperature: -40 – 70°C
Operating Humidity: -10 – 90°C (non- condensing) Storage Temperature: -40 – 70°C
Storage Humidity: -10 – 90°C (non- condensing)

Protection Class

IP66 (EN60529)
IK10 (IEC62262) for metal surface/buttons

IP66 (EN60529)
IK10 (IEC62262) for both metal surface/buttons and lens area

Multilingual

English, German, Italian, French, Spanish, Portuguese, Russian, Chinese

Compliance

FCC/CE/RCM/IC

GETTING STARTED

This chapter provides basic installation instructions, including the list of the packaging contents and information for obtaining the best performance using the GSC356X series of smart outdoor intercoms.

Equipment Packaging

  • GSC3565 / GSC3560
Panel a: two vertical enclosure housings labeled GSC3560 (or GSC3565), indicating quantity 1
GSC3565GSC3560 Package Content
  • A : 1 x GSC3565/GSC3560.

  • B : 1 x Positioning Sticker.

  • C : 1 x Wall Bracket.

  • D : 5 x (ST 3.5 x 32mm) Screws and Screw Anchors.

  • E : 5 x (M 4 x 14mm) Screws.

  • F : 2 x Dual-Port Waterproof Silicone Plug.

  • G : 1 x Wrench.

  • H : 1 security bolt.

  • I : 1 x (M3 x 6mm) Screw.

  • J : 1 x Quick Installation Guide, and 1 x Regulatory Paper.

Note

Check the package before installation. If you find anything missing, contact your system administrator.

Description of the GSC356X

The figure below shows a description of the front views of the GSC356X series of smart outdoor intercom devices:

Back panel diagrams of GSC3560 and GSC3565 showing microphone holes, dial key, and speaker; GSC3565 also shows camera and flash light.
GSC356X Front View

GSC356X Wiring Connection

The GSC3565/GSC3560 provides a terminal block interface for power, relay control, alarm integration, and RS-485 communication. Below is a detailed explanation of each pin and its function:

Three-view diagram of a rugged enclosure device: side view with two small connectors, back view with a terminal block and reset area, and a zoomed inset highlighting the power/communication terminal strip (12-48 V, PoE).
GSC356X Wiring Connection

Connector

Function

Note

Network Port(PoE)

Ethernet and PoE Supply

Single 10/100Mbps network port, supports 802.3 at PoE power supply.

DC IN+

Power Supply (+)

Positive terminal for DC power input. Supports a wide voltage range DC 12V–48V.

DC IN-

Power Supply (-)

Negative terminal for DC power input.

LINE OUT +

Audio Line Output (+)

Positive audio output terminal for connecting external amplifiers, speakers, or audio systems.

LINE OUT –

Audio Line Output (-)

Negative audio output terminal for connecting external amplifiers, speakers, or audio systems.

RS485A

RS485 Communication (+)

Positive line for RS485 differential signal.

RS485B

RS485 Communication (-)

Negative line for RS485 differential signal.

ALARM1

Alarm Input 1

Input for external devices (e.g., door contacts, sensors, or exit buttons).

ALARM2

Alarm Input 2

GND

Alarm Ground

Common ground reference for alarm inputs.

NO2

Relay Output2

For “Fail Secure” (Locked when Power Lost) Strike, connect COM2 & NO2.  

For “Fail Safe” (Open when No Power) Magnetic Lock, connect COM2 & NC2.

Relay: Maximum current allowed is 30VDC/2A.

Note: Relay Output 2 uses a Solid State Relay (SSR), which provides electronic switching instead of mechanical contacts. Verify that the connected lock is compatible with the SSR output specifications and voltage requirements (30V/2A MAX)

COM2

NC2

NO1

Relay Output1

For “Fail Secure” (Locked when Power Lost) Strike, connect COM1 & NO1.  

For “Fail Safe” (Open when No Power) Magnetic Lock, connect COM1 & NC1.

Relay: Maximum current allowed is 30VDC/2A.

COM1

NC1

SD Card Slot

Data Storage

Maximum capacity 256GB.

Reset Button

System Reset

Press and hold to restore to factory defaults.

Tamper Button

Tamper Detection

It prevents violent demolition.

GSC356X Wall Mount Installation

This section provides step-by-step instructions for the IN-wall mounting of the the GSC356X IP intercom device, using the GSC3565 model as an example, on a wall using one of the available installation methods:

A positioning sticker is included in the package to ensure accurate and aligned mounting across all installation types.

Mounting template: outer rectangle with four corner holes, inner dashed boxes marking a 1‑gang and an 86 box, center Ø27 mm hole with crosshair, and side mounting pegs.

Please follow these steps carefully to ensure a weather-protected and tamper-resistant installation:

  1. Place the provided positioning sticker on the wall at the desired mounting height.
  2. Using the markings on the sticker as a guide, drill holes at the indicated positions.
Note

Drill patterns may vary depending on the selected installation method (1-gang box, 86 box, or direct wall mount).

  1. Insert the supplied screw anchors into the holes.
  2. Secure the wall-mounted bracket using the included ST 3.5 × 33mm self-tapping screws, along with their screws.
Step-by-step: drill Ø6.5 mm holes, mount the wall plate, then secure the enclosure with screws.
  1. Route the necessary cables (power, network, door strike, etc.) through the center opening or the bottom opening of the bracket, depending on the wires’ source.
  2. Insert the waterproof silicone port plug into the cable exit area at the bottom of the rear cover to protect and organize the cables.
  3. Place the rear cover onto the bracket, aligning it with the screw holes.
  4. Secure the rear cover by placing the securing clip on top of it.
  5. Optionally, connect the DC POWER outlet to power on the device, or use an Ethernet cable connected to a PoE switch.
Diagram of two wiring options for an electrical enclosure: left shows a front view with internal terminals labeled f, h, i; middle shows the back of the enclosure with cables prepared to connect; right shows the rear module connected with labeled point a and a magnified inset of the connector area.
  1. Place the device onto the wall-mounted bracket.
  2. Use a wrench to tighten the M 4 × 14mm screws, securing the door station to the bracket.
Exploded view of a wall‑mount electrical enclosure with the front panel removed, showing internal components and screw placements for assembly or disassembly (left). Right shows the fully assembled enclosure side view with ventilation grille and mounting holes.

Powering the GSC356X

The GSC356X IP Smart outdoor intercom can be powered using PoE or PSU:

Using PoE (Suggested)

  • Connect the other end of the RJ45 cable to the PoE switch.
  • A PoE injector can be used if a PoE switch is not available.
Diagram showing a wall-mounted device connected via Ethernet cable to a labeled PoE switch (ports 1–5). The setup illustrates Power over Ethernet wiring.
Powering the GSC356X Using PoE

Using Power Supply Unit (Not Provided)

  • Connect the other end of the RJ45 cable to a network switch or router, for data transmission only, not to power on the device.
  • Connect a DC 12-48V power source via the related cable to the correct pins of the GSC356X to power on the device.
Power supply module mounted in a frame with a terminal block and two cables; bottom schematic shows DC input 12–48 V, 2 A.
Using a Power Supply Unit

GSC356X ACCESS AND CONFIGURATION

The GSC356X includes an embedded web server that responds to HTTP/HTTPS GET and POST requests. This allows users to configure and manage the device through any standard web browser.

To begin configuration, please refer to the sections below.

Notes:

  • To access the GSC356x web interface, your computer must be connected to the same local network (subnet) as the GSC356x. (This is typically done by connecting your computer to the same router, hub, or network switch as the device.)
  • If no hub or switch is available (or if all ports are in use), you can also connect the GSC356x directly to your PC’s Ethernet port using a network cable and configure both devices with compatible static IP addresses.

Accessing the GSC356X via Dynamic IP (DHCP)

By default, the GSC356X is configured to automatically obtain an IP address from a DHCP server, such as your network router. This method is suitable for most typical office or home setups.

To connect the GSC356X to your network, please follow the instructions below:

  1. Use an Ethernet cable to connect the GSC356X to a router, network switch, or access point with DHCP enabled.
  2. Power the device using one of the following methods:
    • PoE (Power over Ethernet): The GSC356X supports IEEE 802.3at Class 4, allowing it to receive power and data over a single Ethernet cable.
    • Power Adapter: Connect a DC 12V power source via the related cable to the correct pins of the GSC356X.
  3. After the device powers on, it will receive an IP address from the DHCP server. You can locate this IP using the tools mentioned in the following sections.

Using GS Search to Retrieve the GSC356X IP Address

GS search is a program that is used to detect and capture the IP address of the Grandstream facility management solution devices. Below are instructions for using the “GS Search” utility tool:

  1. Download the GS Search utility tool from the Grandstream website using the following link: GS_Search
  2. Double-click on the downloaded file, and the search window will appear.
  3. Click on the “Search” button to start the discovery for Grandstream devices.
  4. The detected devices will appear in the output field as shown below.
Software search window listing a DOORCAM GSC3655 device with IP 192.168.6.51, HTTP 443, RTSP 554, and a partially hidden MAC; a centered Search button below; bottom strip shows 'IP Address Configuration' and 'Facility Device Password Recovery'.
GS Search Discovery

Accessing the GSC356X via Static IP

If there is no DHCP server in the network, or the GSC356X does not get an IP from the DHCP server, users can connect the GSC356X to a computer directly, using a static IP to configure the GSC356X.

If no DHCP server is available or the DHCP request times out (after 3 minutes), the GSC356x will use its default static IP address: 192.168.0.160

  1. Connect the Ethernet cable from GSC356X to the computer network port directly.
  2. Configure the computer using Static IP: 192.168.0.XXX (1<XXX<255, except for 160) and configure the “Subnet mask” to “255.255.255.0”. Leave the “Default Gateway” to “Blank” like below:
Static IP on Windows

4. Power on the GSC356X, using a PoE injector or external DC power.

5. Enter 192.168.0.160 in the address bar of the browser to access the GSC356X Web UI.

GSC356X Web UI Login

Once the GSC356X is accessed through its IP address (whether static or dynamically assigned), the embedded Web User Interface (Web UI) will load in the browser. This interface allows administrators to configure and manage the device.

Upon accessing the Web UI, a login screen will appear, prompting for credentials:

GSC356x Web UI Login

There are two default passwords for the login page:

User Level

User

Password

Web Pages Allowed

End User Level

user

123

  • Status

  • Real-time Preview

  • Calls

  • Phone Settings

  • Network Settings

  • System Settings

  • Maintenance

  • Diagnostic

Administrator Level

admin

Random password available on the sticker at the back of the unit.

All pages

Note:

  • Upon first logging into the Web UI, users will be prompted to change the default administrator/user password. This is a mandatory step for security purposes and must be completed before proceeding with any configuration.
  • User-level access requires the option “Enable User Web Access” to be enabled in the security settings of the device (disabled by default).

Enable User Web Access

Saving and Applying Configuration Changes

After logging into the GSC356X Web UI and making any configuration changes, users must take action to ensure those changes are saved and applied correctly.

  • Pressing the “Save”
    button will store the changes temporarily, but they will not take effect until the user clicks the “Apply”
    button at the top of the Web UI.
  • Alternatively, users can simply click “Save and Apply”
    to save the settings and apply them immediately.
Note:

While most settings take effect after applying changes, it is recommended to reboot or power cycle the device to ensure all configurations are fully loaded and operational. This step is essential to finalize configurations that require a reboot, such as network settings.

To reboot the device remotely:

  • Click the “Reboot”
    button located in the top-right corner of the Web UI.
  • The browser will display a reboot message. Wait approximately 1 minute before logging in again.

GSC356X APPLICATION SCENARIOS

The GSC356X IP Smart Door Intercom can be used in different scenarios.

Emergency Call

The Emergency Call scenario is designed to provide an immediate response mechanism in critical situations by automatically placing a call when the intercom button is pressed. This feature ensures that users can quickly reach a predefined contact such as security staff, reception, or emergency services. In addition to initiating the call, the device can also trigger a relay output simultaneously to perform actions like unlocking a door or activating an alarm system, enabling both communication and physical response at the same time.

Doorbell panel being pressed; diagram shows triggering an emergency call or door release via SIP relay or direct call to open the door with a green phone icon on the right and a red emergency icon above the center line.
Emergency call

To configure the device to trigger an emergency call, follow the steps below:

  • Navigate to Basic Settings → Call Button Settings.
  • Locate “Number Called When Call Button Pressed”.
  • Enter the target number (SIP extension, IP, or external number) for emergency handling. Set Call Button Mode to Call the specified number. if you would like just to trigger or a call with no alarm, or to Both, if you would like to launch a call and trigger a relay output simultaneously.
  • Choose Call Mode (e.g., Serial Hunting if multiple numbers are configured). Define Calling Timeout as needed (e.g., 60 seconds) (Optional).
  • Configure backup numbers to determine where calls are routed when the primary defined number (Number Called When Call Button Pressed) is unavailable. Navigate to Access Control Settings → Basic Settings → Open Door Settings to define the 2nd, 3rd and 4th numbers to be called.
  • Select the desired action (unlock door, trigger siren, or activate external alarm) on the alarm action profile.
  • Click Save and Apply to activate the settings.
  • Press the call button on the intercom to test the configuration.
Basic Settings: Call Button Settings page showing account, mode, and timeout options with a table of call routes and an enable toggle at the bottom.

Peering Mode without SIP Server

The GSC356X can operate in Peering Mode, enabling direct IP communication without relying on a SIP server. This setup is ideal for standalone deployments on local networks where centralized SIP infrastructure is not available or not needed.

This is the solution to upgrade the traditional analog Intercom and CCTV security system. All you need is a Power source, a Switch or a PoE Switch, and a compatible Grandstream device such as the GXV series video phones or WP8x6 Wi-Fi phones.

In this section, we will use the GSC3575 Control Station to demonstrate the peering process. However, the same principles apply when using other compatible Grandstream devices.

Isometric floor plan showing three smart devices connected: control station (IP 192.168.6.245), Wi‑Fi router (WLAN 192.168.6.0/24), and outdoor intercom (IP 192.168.6.244).
Peering Mode without SIP Server

Prerequisites

Before configuring peering mode, ensure the following:

  1. Power Supply Options
    • The GSC356X supports:
      • PoE (802.3at, Class 4) via Ethernet
      • 12V DC (1A) via rear pin connectors
    • For the door strike or magnetic lock:
      • Can be powered using the same PSU as the GSC356X (if power rating allows)
      • Or separately, if PoE is used for GSC356X, and a dedicated PSU is used for the lock
  2. Networking
    • GSC356X and the receiving device must be on the same local subnet
    • Static or dynamic IP addressing is supported
  3. Connected Hardware
    • For door unlock functionality, ensure the relay pins (NO, NC, COM) are wired to a functional lock device.

Configuration Steps

  • On GSC356X

To enable direct IP communication with the GSC3575, configure the GSC356X using the steps below.

  1. Enable the SIP account by navigating to Account → Basic Settings.
  2. Enable the account by setting “Account Active” to Yes, and leave all SIP credential fields empty. In peering mode, the device communicates directly via IP, so registration to a SIP server is unnecessary.
Accounts settings page with the Account Active checkbox highlighted in red, showing fields for Account Name, SIP Server, proxies, and Save options in a left-hand navigation layout.
GSC356X General Account Settings Page
  1. Navigate to Phone Settings → General Settings and set Use Random Port to No. Fixed RTP ports ensure reliable audio and video transmission between static IP devices in direct IP mode.
GSC356X General Phone Settings Page
  1. Go to Access Control Settings → Doorbell Settings and enter the IP address or SIP URI of the target device (e.g., 192.168.1.88 or sip:192.168.1.88) in Number Called When Doorbell Pressed. This defines where the GSC356X should send calls when the doorbell is pressed.
GSC356X Doorbell Settings
  1. Set the Remote Open Door PIN under Access Control Settings → Open Door Settings. This enables users to remotely unlock the door from the receiving device using either SIP signaling or DTMF input.
  2. Click Save and Apply to ensure all settings are committed and activated.
GSC356X Open Door Settings
  • On GSC3575 Control Station
  1. To enable two-way direct IP calling, repeat steps 1, 2, and 3 from the GSC356X configuration on the receiving device.
  2. For the SIP-based relay trigger, users need to add the GSC356X door station to the list of monitored devices on the GSC3575 control station, as shown in the screenshot below.
    • Choose a door system number or leave the field blank.
    • Select the active account for monitoring.
    • Enter the GSC356X IP address under device IP.
    • Configure the Remote Open Door PIN as the access password.
GSC3575 Door System Monitor Settings
  1. To enable door unlocking via DTMF, select the DTMF mode based on your GSC356X config in the codec settings configuration of the active account.
GSC3575 Account Codec Settings

Remotely Unlocking the Door

The diagram below shows the flow of the remote door unlocking using a direct IP call.

Video doorbell system: front panel with camera calls an indoor monitor via IP; the monitor then triggers the door to unlock via SIP relay or DTMF keypad sequence.
Direct IP Call for Remote Unlock

Once the doorbell is pressed:

  1. The GSC3575 receives the call and shows a video stream from the GSC356X
  1. The user can:
    • Tap the unlock icon during the incoming call or active call screen to trigger the door relay via SIP.
    • Enter the Remote Open Door PIN followed by the pound key (#) during the active call to unlock the door using DTMF.
Door Opened Prompt

Peering Mode with SIP Server

For medium to large-scale deployments, especially when multiple GSC356X units are deployed across a facility, Direct IP peering is not recommended due to limitations in maintaining simultaneous peer connections.

In such cases, using a central SIP server, like Grandstream’s UCM6300, SoftwareUCM, or GCC IPPBX, or a compatible SIP proxy, is strongly advised to manage call routing, access control, and video intercom functionality efficiently. The SIP server acts as the core system to register all devices, allowing centralized management.

For a typical deployment, the following might be needed:

  • Multiple GSC356X door systems (e.g., GSC3565)
  • A UCM6300 IPPBX or other compatible SIP Server
  • GXV33xx/GXV34xx video phones, GSC357x intercom stations, WP8x6 Wi-Fi phones, or any compatible devices.
  • PoE switch with proper Cat5e/Cat6 cabling
  • Power supply unit (PSU) if not using PoE.

If remote access is needed—for viewing live video feeds or unlocking doors remotely—a router with internet connectivity is essential. Additional requirements:

  • Router with WAN access
  • Internet connection (Fiber, DSL, 4G/5G, etc.)
  • Mobile device (Android/iPhone) with SIP client or IP camera app (e.g., GS Wave)
SIP server (UCM63xx) connected to a PoE switch; gateway and desk phones (GSC3565, GSC3560, GXV3350, GXV3480) and WP836 wireless handset shown in the network diagram.
Peering GSC356X with SIP Server

Peering Mode using NVR

The GSC356X series supports seamless integration with third-party Network Video Recorders (NVRs) using the ONVIF Profile S standard, only for the GSC3565 model with an HD Camera. This enables centralized live monitoring, video recording, and event management for facility access and surveillance applications.

The key protocols used in this scenario are:

  • ONVIF Profile S: Enables device discovery, stream configuration, and event handling.
  • RTSP (Real-Time Streaming Protocol): Used to stream live video to the NVR once authenticated and configured via ONVIF.

The recommended equipment list is:

  • One or more GSC3565 devices.
  • ONVIF-compliant NVR.
  • PoE switch or DC power supply.
  • Router (for Internet access if remote viewing is needed)
  • Optional: Android/iOS phone with compatible viewing app (e.g., IP Cam Viewer)
Surveillance system diagram: IP cameras connected to GSC3565 units via a switch, then to a Network Video Recorder (NVR) and router with internet access; smartphone and monitor shown for access.
Peering GSC356X with an Onvif Profile S NVR

The GSC356X Web UI provides options to configure ONVIF access credentials, which are essential for secure integration with NVRs or third-party ONVIF-compatible software. Under Monitoring → ONVIF, you will find:

  • ONVIF Username: This is the account the NVR or ONVIF client will use to authenticate with the GSC356X.
  • ONVIF Password: The corresponding password for that username.

These credentials are used during the ONVIF device discovery, stream setup, and event service access phases.

GSC356X ONVIF Settings

If the NVR or viewing client supports direct RTSP connections, the GSC356X acts as an RTSP server, streaming live video to the NVR. The NVR acts as an RTSP client, pulling the live video feed using the RTSP URL (which includes the username/password).

To configure RTSP settings, go to Monitoring → RTSP:

  • RTSP Port (default: 554)
  • RTSP Authentication: define how credentials (username/password) are sent
  • RTSP Username
  • RTSP Password
GSC356X RTSP Settings
Note:

It is recommended that the ONVIF account and the RTSP account use the same username and password to avoid access issues when previewing video from third-party NVRs or VMS (Video Management Systems). Some systems will attempt RTSP authentication using the ONVIF credentials.

GSC356X PERIPHERAL CONNECTIONS

Below is the illustration of GSC356X peripheral connections for related applications. We will take the GSC3565 as our testing unit.

Security system diagram: sensors (door strike, siren, infrared sensor, etc.) feed a central intercom panel, which connects to PoE gear and a manager; bottom shows endpoints like phones and recorder.
Peripheral Connections for GSC356x

Alarm IN/ Relay OUT

Alarm_In can be connected to 3rd-party sensors (such as an IR Motion Sensor, door contact switch, or panic button).

Relay_Out can be connected to devices such as a 3rd-party siren, strobe light, or an electric door striker.

The figure below shows an illustration of the Circuit for Alarm_In and Relay_Out.

Schematic showing an optocoupler between input (IN/GND) and relay output (OUT+/OUT-); labels Alarm in and Relay out.
Alarm In Relay Out Circuit for GSC356X

The Alarm_In and Alarm_Out circuit for the GSC356X should meet the following requirements:

Alarm Input

Dry contact (switch) input only.

Relay Output

125VAC/0.5A, 30VDC/2A, Normal Open, PINs

Note:

Higher voltage and wrong polarity connections are prohibited because this will damage the devices.

Protection Diode

When connecting the GSC356X to a door strike, it is recommended to set an EMF protection diode in reverse polarity for secure use. Below are examples of deploying the GSC356X for the protection diode.

Wiring diagram for an electric lock: control unit connects via COM/NC/NO to a lock coil, powered from V+ and V- on a power supply.
Protection Diode Example 1

The reverse EMF protection diode must always be installed in reverse polarity across the door strike.

Diagram of an electric strike door lock wiring: control unit on left, power supply on right, COM/NC/NO terminals, and red/black wires with diode and locking coil.
Protection Diode Example 2
Note

Power polarity connection: Diode: SS24 or If>=2A, Vr>=40V.

Connection Examples

This section illustrates different connection scenarios for the GSC356X IP Video Door Station, with explanations and practical use cases for each wiring setup.

While the wiring principles apply across both models in the series, the GSC3565 is used in this section as the representative example in the diagrams for visual consistency.

Power Supply Note:

  • PoE (802.3at Class 4) can be used to power the GSC356x directly through the network cable, simplifying installation and cabling.
  • Shared Power Supply (e.g., a 12V DC PSU) can be used to power both the GSC356X and connected devices like electric strikes or relays, provided the total current draw does not exceed the PSU’s capacity.
  • For fail-safe/fail-secure locks requiring higher current, it’s often recommended to use a dedicated power supply for the lock, while using PoE or a separate PSU for the GSC356X to prevent voltage drops or instability.

Important:

  • Do not reverse 12V and GND pins when powering the GSC356x using an external power supply. This can permanently damage the GSC356X or any attached devices. Always verify polarity before powering the unit.
  • If door strike/siren shares a PSU that doesn’t provide enough amperage, voltage drops or reboots may occur, especially during activation events. This can lead to failed unlocking, corrupted config, or device damage over time.
  • Exceeding the relay output limit (above 30V or 2A) can push the internal relay beyond its safe operating range, potentially leading to welded or burned contacts, complete relay failure, and, in extreme cases, a fire hazard.
  • Failing to isolate high- and low-voltage circuits can lead to unprotected mixing of power and control signals, increasing the risk of electrical noise, system malfunctions, or even shock hazards.

GSC356X with Fail-Secure Electric Strike

  • Pins used: NO (Normally Open) and COM (Common)
  • Fail-secure strikes require power to unlock.
  • When the GSC356X sends an unlock signal, it closes the circuit between NO and COM, energizing the strike to unlock the door.

This setup is ideal for high-security environments, such as server rooms or storage areas, where doors stay locked in case of power failure to prevent unauthorized entry.

Note:

Avoid using NC (Normally Closed) for this setup. As a fail-secure lock needs power to unlock, using NC will supply power continuously, keeping the lock in an open (unsecured) state when idle.

Technical wiring diagram for a GSC356X door control system showing connections from the DC power supply to the lock strike and controller, with color-coded wires (red, black, blue) and annotations for 12V DC input and minimum 2A current.
GSC3565 with Fail Secure Door Strike

GSC356X with Fail-Safe Magnetic Lock and Dry Contact Switch

  • Pins used: For the magnetic lock → NC (Normally Closed) and COM (Common), for the dry contact switch → ALARM1 (Alarm input 1) and GND (Ground).
  • Fail-safe locks stay locked when powered, and unlock when power is cut.
  • When the GSC356X triggers the relay (e.g., from button press or remote access), it opens the circuit, cutting power and unlocking the door.

This setup is especially effective in environments such as Emergency exits, where doors must remain locked by default and only unlock temporarily when access is granted.

Note:

Avoid wiring Fail-Safe Locks to NO (Normally Open) Without a Timed Cutoff. If the relay stays closed (power applied continuously), the lock may overheat or wear out, especially electromagnetic locks designed for short bursts of power.

Wiring diagram for GSC356X showing dry contact switch, power supplies, magnetic lock, and fail-safe lock connections with color-coded cables.
GSC356X with Fail Safe Magnetic Lock and Dry Contact Switch

GSC356X with Siren and Motion Sensor

  • Pins used: For the siren → NO (Normally Open) and COM (Common), for the motion sensor → ALARM1 (Alarm input 1) and GND (Ground).
  • Most electronic sirens are active when powered.
  • When the GSC356X triggers the relay (e.g., due to motion detection or alarm input), the NO contact closes with COM, powering the siren.
Note:

If you accidentally wire a siren to NC (Normally Closed), it will sound continuously, unless the relay is activated to break the circuit. This is typically not desired for siren applications.

Diagram of a motion-sensor alarm system: motion sensor, GSC356x controller, siren, and two power supplies with labeled wiring and connections.
GSC356X with Siren and Motion Sensor

Secure Open Door Peering with GSC357x

In this enhanced access control setup, the GSC357x Series functions as the secure internal relay controller for unlocking doors, with the GSC356X door system installed outside. This configuration is ideal for increasing physical security by relocating the unlocking relay circuit indoors, where it is less vulnerable to tampering.

In this section, we will be using the GSC3575 control station with the GSC3565 door intercom for secure open door peering (SIP-Based Connection).

  • GSC356X is installed outside the entry point (e.g., main gate or door).
  • GSC3575 is installed indoors, beyond the secured entry.
  • The electric lock or strike is connected to the GSC3575’s Alarm_Out (relay) interface, not the GSC356X device.
  • Communication between devices is established using SIP accounts registered to a SIP server.

This configuration ensures secure access control by moving the unlocking relay indoors while utilizing centralized SIP server management.

Network diagram of an access control system: outdoor GSC356x unit connects via PoE switch to indoor GSC357x controller, SIP server, router, and door strike power supply.
GSC357x Secure Open Door with GSC356X

GSC356X Configuration Steps

  1. Log in to GSC356X Web UI
  2. Under Account 1 Settings, register to the SIP server using the SIP credentials.
GSC356X Account Registration
  1. Navigate to Access Control Settings → Basic Settings:
    • Set Door Relay Options to “GSC357X Relay”
    • Set Account to Account 1.
    • Set the GSC357X SIP number to its SIP extension.
    • Set a GSC357X Door Password (shared with GSC3575)
Basic Settings page with Access Control Settings tab selected; shows GSC357X Relay options, a warning about DO settings, and Door 1–Door 2 configuration fields (Account, SIP number, and password).
GSC356X GSC Relay Configuration

GSC357x Configuration Steps

  1. Log in to GSC357x Web UI.
  2. Register the GSC357x account on the same SIP server as the GSC356X.
  3. Navigate to Settings → Digital Output:
    • Set Output Mode to “To Door”.
    • Set Door Control SIP Account to Account 1.
    • Set Door System SIP User ID to GSC356X SIP extension.
    • Set the Door System IP Address to the GSC356X IP.
    • Set Door System Password (same as on GSC356X).
GSC357x Digital Output Settings

GSC356X BUILT-IN ALARM FUNCTIONS

The GSC356X Series includes a range of built-in alarms that can detect security events such as tampering, unauthorized access, or environmental conditions. These alarms trigger user-defined response actions through configurable Alarm Profiles.

Each alarm event can be linked to one profile set under the Alarm Action Profile section in the GSC356X web UI. A profile defines which combination of responses should occur when an alarm is triggered.

Intrusion/Loitering Alarm (GSC3565)

This alarm monitors designated zones in the camera’s field of view for unauthorized presence.

Person standing near a wall with dashed glare lines from a light above, and an X marking the glare angle, a schematic diagram shows visibility rules in the left panel,
IntrusionLoitering Alarm GSC3565

Users can configure the following:

  • Zone Configuration: Up to 8 zones can be configured for intrusion or loitering detection.
  • Duration of Loitering (s): Specifies the time a person must stay within a zone to trigger a loitering alarm. If set to 0, the system will act as an intrusion alarm, triggering as soon as a humanoid is detected.
  • Alarm Schedule: Defines the active monitoring period for the intrusion/loitering detection. (e.g., Office hours)
  • Custom Alarm Tone: Enables customization of the audio alarm tone. (An audio alarm action profile must be assigned for the intrusion/loitering alarm to hear this prompt)
  • Alarm Prompt Tone: Configures the alarm prompt tone that will play when an alarm is triggered. (Supported audio file formats: mp3, wav, ogg, wma, mid, m4a)
  • Play Rules: Specifies how the alarm will play when triggered by choosing one of the following methods:
    • Maximum Duration: Sets the maximum time the alarm can play.
    • Number of Loops: Sets how many times the alarm will repeat (up to 10 times).
IntrusionLoitering Alarm Settings

Tamper Alarm

The GSC356X is equipped with a mechanical tamper detection button on the back panel that triggers an alarm if the device is forcefully detached or tampered with.

Line drawing of a screwdriver near a device, pointing to the anti-tamper sensor on the enclosure with a bell alert above.
Tamper Alarm

For tamper alarm settings, users have the option to either customize their own alarm tone or select from a predefined system list by using the following parameters:

  • Custom Alarm Tone: Enables customization of the audio alarm tone. (An audio alarm action profile must be assigned for the tamper alarm to hear this prompt).
  • Alarm Prompt Tone: Configures the alarm prompt tone that will play when an alarm is triggered. (Supported audio file formats: mp3, wav, ogg, wma, mid, m4a)
Tamper Alarm Settings

Remote Unlock Wrong Password Alarm

The Remote Unlock Wrong Password Alarm improves security for remote access methods such as SIP calls, HTTP API, or mobile app unlock. This feature prevents brute-force attempts or repeated incorrect password entries when unlocking doors remotely through the SecureAccess app.

When a user enters an incorrect password five consecutive times during a remote unlock attempt, the system will automatically trigger the configured alarm action. Additionally, the device will temporarily disable remote door opening for a specified lock time to prevent further unauthorized attempts.

Hand holding a smartphone showing multiple warning icons and 'Wrong Password' message as an alarm triggers, leading to doorlock security scene in the center and a locked door on the right.
Remote Unlock Wrong Password Alarm

To enable this alarm, navigate to Alarm Event Settings → Remote Unlock Wrong Password Alarm and configure the following parameters:

  • Lock Time (m): Defines the period (in minutes) that the remote door opening is locked after the alarm is triggered. Once this time expires, the counter resets, and remote unlock attempts are re-enabled.
  • Alarm Action Profile: Assigns the set of actions (e.g., trigger relay, SIP Alarm, Email Alarm) that the alarm will perform when activated.
  • Custom Alarm Tone: Enables uploading and selecting a personalized alarm sound.
  • Alarm Prompt Tone: Plays a predefined or uploaded prompt tone when the alarm is triggered (Supports MP3, WAV, OGG, WMA, MID, M4A).
  • Play Rules: Defines how the alarm behaves when triggered:
    • Maximum Duration (s): The maximum number of seconds the alarm will sound.
    • Number of Loops: Specifies how many times the alarm will repeat (up to 10 times).
Remote Unlock Wrong Password Alarm Settings

High Temperature Alarm

The GSC356X utilizes an internal sensor that detects excessive heat and triggers an alarm to protect the device from overheating.

Wall-mounted alarm panel with a temperature-threshold indicator and a nearby thermometer icon shows alarm settings and alert status.
High Temperature Alarm

Users can enable and configure the High Temperature Alarm under Alarm Event Settings → High Temperature Alarm, where they can set a Custom Alarm Tone and the Alarm Interval (seconds) to control how frequently the alarm is triggered.

High Temperature Alarm Settings

Silent Alarm

Users can specify which alarms should operate in silent mode, triggering the assigned actions without producing an audible sound. This is useful in scenarios where discreet alerts are required without disturbing the environment.

To set silent alarms, users can select the events that will trigger the silent alarm under Alarm Event Settings by checking the corresponding check boxes (multiple selections are allowed).

Note:

The Hostage Code Alarm is inherently a silent alarm by design. Therefore, it cannot be selected under the Silent Alarm Event settings.

Alarm Event Settings: tabbed interface with a Reset All Alarms button and a two-column checklist of silent alarm options (All, Digital Input, Intrusion/Loitering, Tamper, Wrong password, Exceeded Access Time, Unauthorized Access, High Temperature, SD Card, Insufficient Power).
Silent Alarm Event

Reset All Alarms

This feature allows users to restore all alarm statuses on the GSC356X device and clear any active alarms with a single click, returning the system to a neutral state and ensuring accurate monitoring.

To reset all alarms, navigate to the Alarm Event Settings page and click the “Reset All Alarms” button.

Alarm Event Settings page showing a blue 'Reset All Alarms' button highlighted; a list of silent alarm options with checkboxes is visible below.
Reset All Alarms Button

Alarm Profile Association

Each alarm is mapped to a profile number (e.g., Profile 1, Profile 2, etc.) in the GSC356X settings. Each profile defines a set of response actions, such as:

  • Audio Alarm – Triggers built-in audio alarm.
  • SIP Alarm – Calls a designated SIP endpoint (e.g., a video intercom).
  • Linked Alarm Output – Activates relay/digital output (e.g., a siren).
  • Email Alarm – Sends email notification.
  • Snapshot Actions – Captures images and performs one or more of the following:
    • Upload to FTP server
    • Save locally
  • Sync Alarm Info to App – Sends the alarm information to the mobile app.
  • Sync Alarm Info to Home Assistant – Sends alarm event information to the Home Assistant platform for automation and monitoring.
  • Cloud Call Alarm – Initiates a cloud-based call notification to designated users or devices through the cloud service platform when an alarm event occurs.
Note:

Users can select one or more actions for an alarm by checking the corresponding boxes. To quickly select all available actions, users can check the “All” box.

Modal dialog titled Profile1 for editing an alarm action profile; includes Name field and multiple notification options with Cloud Call Alarm checked.
GSC356X Alarm Action Profile Settings

GSC356X WEB UI SETTINGS

This section describes the options in the GSC356X Web GUI, summarized below:

  • Status: Display the Account status, Network status, and System Info of the GSC356X.
  • Real-time Preview: View the live video streams of the GSC356X using your browser.
  • Access Control Settings: Configure door-related access and output settings, including door unlock methods, doorbell behavior, door opening schedules, and access logs that record all door entry activities.
  • Alarm Settings: Configure digital alarm input settings, built-in GSC356X alarm functions, action profiles, notification settings, alarm scheduling, and view logs of all triggered alarms.
  • Audio & Video Settings: Configure audio settings and video-related functions such as OSD (On-Screen Display), CMOS parameters, and privacy masking.
  • Monitoring: Configure ONVIF and RTSP settings for video streaming and integration with third-party systems.
  • Account Settings: Configure the SIP account settings for the GSC356X.
  • Calls: Place outgoing calls directly from the Web UI, review call history logs, and manage the call allowlist for enhanced control over incoming and outgoing call permissions.
  • Phone Settings: Configure various call-related features such as ringtones, auto answer, DND options, multicast paging, and other preferences.
  • Network Settings: Configure network-related parameters, including IPv4 address mode (DHCP, Static, PPPoE), Wi-Fi settings, and advanced options such as OpenVPN® for secure remote access.
  • System Settings: Manage system-level configurations such as time, Web/SSH access permissions, LED behavior, audio control, TR-069, backup and restore, email notifications, and FTP settings.
  • Maintenance: Perform system maintenance tasks, including firmware upgrades, configuration provisioning, factory reset, event notification setup, and system diagnostics.
  • Application: Configure account sharing on the GSC356X to synchronize SIP credentials with other supported Grandstream devices.
  • Diagnostic: Provides built-in tools to test and verify device functionality, such as microphone test, relay out test, tamper test, etc.

Status Page Definitions

System Info

System Info→Information

Product Model

Product model of the GSC356x.

Part Number

Product part number.

Software Version

Software Version

  • Boot: boot version number.

  • Core: core version number.

  • Prog: program version number. This is the main firmware release number, which is always used for identifying the software system of the GS356x.

  • Locale: locale version number.

  • Res: Resolution version number.

IP Geographic Information

Recommend Time Zone

Represent the time zone detected based on the IP address.

System Time

System Up Time

System up time since the last reboot.

System Time

Current system time on the GSC356x system.

System Time-Zone

Displays the time zone that is configured by user.

SD Card Storage Status

Total Space

Displays the total space of the connected SD card.

Used Space

Displays the used space of the connected SD card.

Available Storage

Displays the available space of the connected SD card.

PoE Detection

PoE Status

Indicates that the device is powered using Power over Ethernet (PoE).

System Information

Download System Information

Click to download system information.

Security Version

Displays the GSC356x security version.

System Info→Status

User Space

Shows the percentage of the user space used and the status of the Database.

Core Dump

Shows the status of the core dump and the core dump files generated if any. It also gives the ability to generate GUI/AVS/CPE/Phone core dump files manually.

Special Feature

OpenVPN® Support: displaying if the GSC356x supports OpenVPN®.

System Info→Cloud Service 

Cloud Service

The Cloud Service page under System Info displays information about the device’s cloud service registration and associated subscription packages. It allows administrators to view the organization to which the device belongs, check the status of assigned cloud service packages, and monitor package expiration dates. This information helps verify that the device is properly enrolled in cloud-based services and that the required licenses remain active.

Clicking A description of the package opens the SecureAccess License Fees page, which provides detailed information about the selected subscription package, including its features, supported services, license scope, and subscription details. This allows administrators to understand the capabilities and benefits included in their current SecureAccess plan.

Network Status

Network Status→Ethernet

LAN Port

Indicates the current status and speed (e.g., 100Mbps/Full) of the device’s LAN connection.

MAC Address

Displays the unique hardware address assigned to the device’s Ethernet interface.

PPPoE Link Up

Shows whether the PPPoE connection is established.

IPv4

IPv4 Address Type

Indicates how the IPv4 address is obtained (e.g., DHCP, Static, PPPoE).

IPv4 Address

Displays the current IPv4 address assigned to the device.

Gateway

Shows the IPv4 default gateway used for routing external traffic.

IPv4 NAT Type

Displays the Network Address Translation type.

IPv6

IPv6 Address Type

Indicates how the IPv6 address is assigned (e.g., Auto Config, Static).

Global Unicast Address

The device’s public IPv6 address used for external communication.

Link-Local Address

An automatically assigned local IPv6 address valid only within the local network segment.

IPv6 Gateway

Shows the default IPv6 gateway address.

IPv6 DUID

DHCP Unique Identifier used for IPv6 DHCP communication.

IPv6 NAT Type

Indicates the IPv6 NAT behavior.

Network Status→DNS & NAT

DNS Server

Displays the Primary and secondary DNS servers used

DNS Mode

Displays the DNS mode used by each account

NAT Traversal

Displays the NAT traversal mode used

Account Status

Account

Account index, shows the list of supported accounts. 4 acounts are supported, the 4th account is dedicated for cloud account management.

SIP User ID

Displays the configured SIP User ID for the account.

SIP Server

Displays the configured SIP Server address, URL or IP address, and port of the SIP server.

Operation

Displays the different types of operations that can be performed on each SIP account, including editing the account, accessing the voicemail….

Real-time Preview Page Definitions

Note

This configuration is exclusive for the GSC3565 model.

Stream 1

Displays the first video stream from the GSC356x real-time preview. The default set resolution is 1920*1080.

Stream 2

Displays the second video stream from the GSC356x real-time preview. The default set resolution is 1280*720.

Redirects to the RTSP stream page to configure the prefrences for stream 1 and stream 2.

Allows to refresh the video stream.

Allows speed dialing by selecting both the calling account and the destination phone number or IP address.

Adjusts the brightness for both streams.

Adjusts the contrast for both streams.

Adjusts the saturation for both streams.

Opens the stream in full-screen mode.

Access Control Settings Page Definitions

Basic Settings

Access Control Settings
Basic Settings UI for door control with two relay outs: Relay Out 1 uses Local Relay to Open Door (Delay 0s, Hold 5s) and Relay Out 2 is set to Open Door (Hold 5s); fields for door name and feature selections shown.
Access Control Settings Basic Settings Access Control Settings

Door Relay Options

Configure the door relay option:

  • Local Relay: Local Relay refers to the GSC356X controlling the relay. The strike is connected to either the COM1 or COM2 port, depending on whether one or two doors need to be controlled.

  • Web Relay: Triggers URLs for controlling the door relay. The configured web relay will get the communication from GSC356X, and will operate the strike to open door for the authenticated open door request

  • GSC357X Relay: Allows connecting a GSC357X control station to ensure consistency with the DO digital output on the GSC357X. This requires entering the phone number and door password for proper integration and relay control.

The default setting for the door relay option is “Local Relay”.

WebRelay On URL

Enter the URL that is triggered to activate (turn on) the door relay through WebRelay.

WebRelay Off URL

Enter the URL that is triggered to deactivate (turn off) the door relay through WebRelay.

WebRelay Username

Enter the username required for authentication when accessing the WebRelay URLs for controlling the door relay.

WebRelay Password

Enter the password associated with the WebRelay Username, used for authentication to control the door relay via the WebRelay URLs.

GSC357X Relay

Configures the following GSC357x relay information:

  • Open Door Account: The account from the GSC356X side used to control the door relay.

  • GSC357X SIP number: The SIP number associated with the GSC357X control station

  • GSC357X Door Password: A password set on both the GSC356X and the GSC357X control station that is required to open the door.

Relay Out 1 / Relay Out 2

Choose Feature

Selects the function of this relay output for the GSC356X. The Options include:

  • Alarm Output: Configures the relay to trigger an external alarm device.

  • Open Door: Configures the relay to control a door strike or lock for access control.

The default feature is “Open Door”.
Note: Only Relay Out 2 supports SSR (Solid-State Relay) functionality. For enhanced security, it is recommended to use Relay Out 2, which includes anti-magnetic protection, for door lock control and door opening operations.

Door Name

Enter the door name to be used with the Open Door feature.

Delay Response Time (seconds)

The time delay between receiving a door open command and activating this relay to unlock the door. The valid range is 0 to 20 seconds and default value is 0 which means instant.

Open Door Hold Time (s)

The duration in which this relay remains active (i.e., how long the door stays unlocked) before automatically locking again. The valid range is 1 to 1800 seconds and default value is 5.

State

Sets the default state of this alarm relay output. The options are:

  • Always On: The relay is normally open and closes when triggered.

  • Always Off: The relay is normally closed and opens when triggered.

‌Alarm Duration (seconds)

The duration that this alarm output remains active when triggered. The valid range is 1 to 1800 seconds and default value is 5.

Snapshot

Snapshot Type

Specifies when the device captures an image. Options include:

  • Open Door Snapshot: Takes a snapshot when the door is opened.

  • Doorbell Snapshot: Takes a snapshot when the doorbell button is pressed.

Both options are enabled by default.

Number of Snapshotd Photos

Specifies how many photos will be taken per snapshot event. The default number is 4.

Snapshot Storage Method

Determines where the snapshots are stored (FTP, Local).

Snapshot when Door Opened

Select the notification method of door opening snapshot.

  • APP notification: Requires device management by the APP.

  • Email Notification: Requires configuring email settings.

Both options are enabled by default.

Snapshot Delay when Door Opened(s)

Sets a delay (in seconds) before taking a snapshot after the door has been opened. The valid range is 0 to 10 seconds and default value is 0.

Snapshot when Doorbell Pressed

Select the notification method of doorbell snapshot.

  • APP notification: Requires device management by the APP.

  • Email Notification: Requires configuring email settings.

Both options are enabled by default.

Snapshot Delay when Doorbell Pressed(s)

Sets a delay (in seconds) before taking a snapshot after the doorbell is pressed. The valid range is 0 to 10 seconds and default value is 0.

Home Assistant

Home Assistant

Once enabled, devices can be discovered, monitored, and managed through the Home Assistant platform.
Enabled by default

Call Button Settings
Access Control Settings Basic Settings Call Button Settings

Call Out Account

Specifies the SIP account used to place the call when the doorbell is pressed. The default setting is “Auto”.

Call Button Mode

Defines the action triggered when the doorbell is pressed. Options include:

  • Call the Specified Number: Initiates a call to the configured number, IP address, or SIP extension.

  • Relay Out: Triggers the configured relay output.

  • Both: Calls the specified number and triggers the relay output.

The default option is “Call the Specified Number”.

Call Mode

Determines how calls are placed to multiple numbers when the doorbell is pressed. Options include:

  • Serial Hunting: Calls the listed numbers one by one in sequence until one answers.

  • Parallel Hunting: Calls all listed numbers simultaneously; the call is connected to the first one that answers.

The default option is “Serial Hunting”.

Calling Timeout(s)

Specifies the timeout for calling a single number. If the remote party does not answer within this time, the call will automatically disconnect. The valid range is 10 to 90, and the default value is 60 seconds.


Note: This setting takes precedence over the call timeout configured in the account settings.

Number Called When Doorbell Pressed

Defines the phone number, IP address, or SIP extension that the device will call when the doorbell is pressed, based on the table below:

  • Index ID: A unique identifier for each call number configuration (up to 4 different index IDs can be set).

  • Schedule: Specifies the schedule for when the call number is active (e.g., daily, schedule1, schedule2, etc).

  • Call Number: The phone number, IP address, or SIP extension to be called when the doorbell is pressed (up to 15 numbers can be configured).

  • Cloud Call Number (up to 5): Specifies cloud-based call numbers that can be used for remote access or communication (up to 5 numbers can be configured).

  • Operation (Edit/Delete): Allows the user to modify (edit) or remove (delete) the call number entries from the configuration.

Enable Call Button to End Call

When enabled, which is the default setting, pressing the call button again will end the current active call.

Open Door Settings
Open Door Settings page showing controls for Open Door & Call, SIP Open Door, HTTP API Open Door, and APP Open Door with toggles, password fields, and action buttons.
Access Control Settings Basic Settings Open Door Settings

Hang Up After Open Door

If enabled, the call (excluding ringing) will automatically end when the door is opened.

Enabled by default.

Call Hang Up Delay After Door Open (s)

Sets the time to automatically end the call after the door is opened.. The valid range is 3 to 1800 and the default value is 3.

Door 1 Remote Open Door Password

Specifies the password required to remotely unlock Door 1.

Door 2 Remote Open Door Password

Specifies the password required to remotely unlock Door 2.

SIP Open Door

Enable SIP Open Door

Enables the use of a PIN code (sent via SIP Message or DTMF tones) to remotely open the door. The default option is “SIP Message” only.

HTTP API Open Door

Enable HTTP API Remote Open Door

Configures the method for remotely opening the door via the HTTP API. Options include:

  • Disable (default): Disables the HTTP API for remote door opening.

  • Challenge+Response Authentication: Requires a challenge-response process for authentication before the door is opened.

  • Basic Authentication: Requires a username and password for authentication before the door is opened.

! Disclaimer: Grandstream Networks,Inc. is not responsible or liable for any security issues resulting from enabling the HTTP APl remote open door function.

HTTP API Open Door Compatibility Mode

Enables compatibility with HTTPS for HTTP API calls. When enabled, the system supports secure HTTPS mode for opening the door remotely via the API. Disabled by default.

APP Open Door

APP Open Door Button

Enables or disables the use of the button within the mobile app to open the door.

QR Code Open Door

If enabled, the QR code generated by the app will be used to open the door.

Static QR Code Open Door

If enabled, the door can be opened using a static QR code generated by the app.

Keep Door Open
Basic Settings: Keep Door Open with Schedule Open Door, date/time pickers, and a weekly custom time grid.
Access Control Settings Basic Settings Keep Door Open

Door 1 / Door 2

Keep Door Open

Configures the door to remain open. Options:

  • Disable (default): Disable keeping the door open.

  • Immediate Door Open: The door will open immediately without a schedule.

  • Schedule Open Door: The door will open based on a pre-configured schedule.

Duration to Keep Door Open (m)

Specifies the time duration (in minutes) to keep the door open.

Keep Door Open Time

Logs the time for which the door will remain open after being triggered.

Begin of Valid Time

The start time of the scheduled period during which the door can remain open.

End of Valid Time

The end time of the scheduled period during which the door can remain open.

Open Door Schedule

Defines the schedule type for opening the door, with options like specific schedule slots (e.g., schedule1, schedule2).

Include Holiday

When enabled, the configured open door schedule also applies on the selected holiday.

Custom Time

A table that allows setting custom time rules when Open Door Schedule is set to “Custom Time”, enabling the user to define specific intervals during which the door will remain open.

User Management

The User Management section is designed to simplify and centralize the management of users authorized to interact with the device through Grandstream’s cloud platform. Instead of configuring users locally, administrators are encouraged to use GDMS SecureAccess or the SecureAccess mobile app to add the device and define access groups, users, and permissions. Once configured in the cloud, all user data—including credentials and access rights—is automatically synchronized and pushed to the device, ensuring consistent, scalable, and remotely manageable access control across deployments.

User Management page guiding to manage user info via GDMS SecureAccess, with steps to add this device and configure access groups, plus app/website download info and a QR code.
User Management

Open Door Record

Export

Export open door record as .csv file.

Clear

Clear open door record.

No.

The record number or identifier for each door opening event in the system.

Open Door Type

Specifies the method used to open the door such as Keep Door Open, and SIP Open Door.

Door information

Door being accessed (door1/door2).

Open DoorTrigger

Indicates the source that initiated the door opening event

Keep Door Open Time

The date when the door remained open after being triggered.

End of Valid Time

The time when the scheduled door access or open period ends.

 Operation

Provides actions that can be performed on the record, such as delete, or view details.

Alarm Settings Page Definitions

Alarm Event Settings

Alarm Event Settings→Alarm Event

Alarm Status

Click to restore all alarm statuses on this GSC356x device and clear active alarms.

Silent Alarm Event

Specifies which types of alarm events will trigger a silent alarm (multiple choices are supported):

  • None (No alarm will be silent)

  • All (All Alarms will be silent)

  • Digital Input

  • Tamper Alarm

  • Exceeded Access Time Limit Alarm

  • High Temperature Alarm

  • Insufficient Power Alarm

  • Intrusion/Loitering Alarm

  • Wrong password alarm of remote open door

  • Unauthorized Access Alarm

  • SD Card Alarm

The default setting is “None”.

Intrusion/Loitering Alarm

Intrusion/Loitering Alarm

Enables or disables the intrusion or loitering detection alarm.

Disabled by default.

Detection Zone

Allows configuration of up to 8 zones in the camera view where intrusion or loitering is monitored.

Duration of Loitering (s)

Sets the time (in seconds) a person must stay in a zone to trigger the alarm. The valid range is 3-300 or 0, and the default vaue is 10 seconds.


Note: If set to 0, an alarm is triggered as soon as as a humanoid is detected in the designated area.

Alarm Schedule

Defines when the alarm is active (e.g., daily, schedule1, schedule2, etc.).

Alarm Action Profile

Assigns a pre-configured action profile (up to 10 available) that determines how the system responds to the alarm.

Custom Alarm Tone

Enables customization of the local audio alarm tone. This setting is disabled by default.


Note: An audio alarm action profile must be assigned for this alarm event to hear this prompt.

Alarm Prompt Tone

Configures the alarm prompt tone that will play when this alarm is triggered. (Supported audio file formats: mp3, wav, ogg, wma, mid, m4a)

Play Rules

Specifies how the alarm will play when triggered by choosing one of the following methods:

  • Maximum Duration

  • Number of Loops

The default method is “Maximum Duration”.

Maximum Duration (s)

Defines the maximum duration (in seconds) for this alarm event. The valid range is 1 to 3600 and the default value is 60 seconds.

Number of Loops

Sets how many times the alarm will repeat. The valid range is 1 to 10 and the default value is 1.

Tamper Alarm

Tamper Alarm

Enables or disables the tamper alarm that detects physical tampering with the device.

Disabled by default.

Alarm Action Profile

Selects a response profile when a tamper alarm is triggered.

Custom Alarm Tone

Enables customization of the local audio alarm tone. This setting is disabled by default.


Note: An audio alarm action profile must be assigned for this alarm event to hear this prompt.

Alarm Prompt Tone

Configures the alarm prompt tone that will play when this alarm is triggered. (Supported audio file formats: mp3, wav, ogg, wma, mid, m4a)

Wrong password alarm of remote open door

Wrong password alarm of remote open door

Enables/Disables an alarm if the remote door opening password is entered incorrectly multiple times.

When enabled, the device will trigger an alarm if the password is entered incorrectly five times in a row for remote open door operations, including:

  • SIP unlock

  • HTTP API unlock

  • App unlock

This feature is disabled by default.

Lock Time (m)

Specifies the duration, in minutes, that remote door opening is disabled after multiple incorrect password attempts trigger an alarm.


When the lock time expires, the incorrect password count is reset and remote door opening is re-enabled.


Valid range is 1 to 1440, and the default value is 5 minutes.

Alarm Action Profile

Specifies the action profile that will be executed when the remote unlock wrong password alarm is triggered.

Custom Alarm Tone

Enables customization of the local audio alarm tone. This setting is disabled by default.


Note: An audio alarm action profile must be assigned for this alarm event to hear this prompt.

Alarm Prompt Tone

Configures the alarm prompt tone that will play when this alarm is triggered. (Supported audio file formats: mp3, wav, ogg, wma, mid, m4a)

Play Rules

Specifies how the alarm will play when triggered by choosing one of the following methods:

  • Maximum Duration

  • Number of Loops

The default method is “Maximum Duration”.

Maximum Duration (s)

Defines the maximum duration (in seconds) for this alarm event. The valid range is 1 to 3600 and the default value is 60 seconds.

Number of Loops

Sets how many times the alarm will repeat. The valid range is 1 to 10 and the default value is 1.

Exceeded Access Time Limit Alarm

Exceeded Access Time Limit Alarm

Triggers an alarm if someone attempts to open the door outside of the allowed time.

Disabled by default.

Alarm Action Profile

Specifies the action profile that will be executed when the exceeded access time limit alarm is triggered.

Custom Alarm Tone

Enables customization of the local audio alarm tone. This setting is disabled by default.


Note: An audio alarm action profile must be assigned for this alarm event to hear this prompt.

Alarm Prompt Tone

Configures the alarm prompt tone that will play when this alarm is triggered. (Supported audio file formats: mp3, wav, ogg, wma, mid, m4a)

Play Rules

Specifies how the alarm will play when triggered by choosing one of the following methods:

  • Maximum Duration

  • Number of Loops

The default method is “Maximum Duration”.

Maximum Duration (s)

Defines the maximum duration (in seconds) for this alarm event. The valid range is 1 to 3600 and the default value is 60 seconds.

Number of Loops

Sets how many times the alarm will repeat. The valid range is 1 to 10 and the default value is 1.

Unauthorized QR Code Access Alarm

Unauthorized QR Code Access Alarm

Enables or disables the unauthorized access alarm. When enabled, if the same unauthorized  QR code fails three times within one minute, an alarm will be triggered.

Disabled by default.

Alarm Action Profile

Specifies the action profile that will be executed when the unauthorized access alarm is triggered.

Custom Alarm Tone

Enables customization of the local audio alarm tone. This setting is disabled by default.


Note: An audio alarm action profile must be assigned for this alarm event to hear this prompt.

Alarm Prompt Tone

Configures the alarm prompt tone that will play when this alarm is triggered. (Supported audio file formats: mp3, wav, ogg, wma, mid, m4a)

Play Rules

Specifies how the alarm will play when triggered by choosing one of the following methods:

  • Maximum Duration

  • Number of Loops

The default method is “Maximum Duration”.

Maximum Duration (s)

Defines the maximum duration (in seconds) for this alarm event. The valid range is 1 to 3600 and the default value is 60 seconds.

Number of Loops

Sets how many times the alarm will repeat. The valid range is 1 to 10 and the default value is 1.

High Temperature Alarm

High Temperature Alarm

Enables alarm triggering when the detected device temperature exceeds the supported threshold.

Disabled by default.

Alarm Action Profile

Defines the system’s response to high temperature detection.

Alarm Interval(seconds)

Sets the minimum time interval, in seconds, between consecutive high temperature alarm events.

The valid range is 60 to 3600 and the default setting is 3600 seconds.

Custom Alarm Tone

Enables customization of the local audio alarm tone. This setting is disabled by default.


Note: An audio alarm action profile must be assigned for this alarm event to hear this prompt.

Alarm Prompt Tone

Configures the alarm prompt tone that will play when this alarm is triggered. (Supported audio file formats: mp3, wav, ogg, wma, mid, m4a)

Play Rules

Specifies how the alarm will play when triggered by choosing one of the following methods:

  • Maximum Duration

  • Number of Loops

The default method is “Maximum Duration”.

Maximum Duration (s)

Defines the maximum duration (in seconds) for this alarm event. The valid range is 1 to 3600 and the default value is 60 seconds.

Number of Loops

Sets how many times the alarm will repeat. The valid range is 1 to 10 and the default value is 1.

Insufficient Power Alarm

Insufficient Power Alarm

When enabled, an alarm will be triggered if the device is not powered by DC (12-48V/2A, 24W) or PoE 802.3at (25W), resulting in suboptimal speaker volume and device instability.

Alarm Action Profile

Select the alarm action profile that triggers the alarm.

Custom Alarm Tone

If enabled, a custom alarm tone will sound when alarm triggered. If disabled, the standard alarm tone will be used.

Alarm Prompt Tone

Configure alarm prompt tone. Supports uploading audio files in mp3, wav, ogg, wma, mid and m4a formats.

Play Rules

Select the maximum duration the triggered alarm tone will play for or the number of loops the triggered alarm tone will play for.

Maximum Duration (s)

Configure the maximum duration of alarms tone.

Number of Loops

Configure the number of alarm tone loops.

SD Card Alarm

SD Card Alarm

An alarm will be triggered if the SD card read or write fails.

Alarm Action Profile

Select the alarm action profile that triggers the alarm.

Alarm Interval(s)

Used only in cases where an SD card becomes unavailable.

Custom Alarm Tone

If enabled, a custom alarm tone will sound when alarm triggered. If disabled, the standard alarm tone will be used.

Alarm Prompt Tone

Configure alarm prompt tone. Supports uploading audio files in mp3, wav, ogg, wma, mid and m4a formats.

Play Rules

Select the maximum duration the triggered alarm tone will play for or the number of loops the triggered alarm tone will play for.

Maximum Duration (s)

Configure the maximum duration of alarms tone.

Number of Loops

Configure the number of alarm tone loops.

Alarm Action

Alarm Action→Alarm Action Profile

No.

The index number of the alarm action profile, with up to 10 profiles available.

Name

Custom name for identifying the profile (e.g., “Office Alarm,” “Night Mode Alert”).

Alarm Notification

Specifies the actions to be executed when the profile is triggered. Multiple options can be selected:

  • All: Executes all available alarm notification methods.

  • Audio Alarm: Triggers an audible warning through the device speaker.

  • SIP Alarm: Sends an alarm notification via SIP to configured devices.

  • Linked Alarm Output: Allows the current profile to trigger a digital output, such as activating a connected siren.

  • Email Alarm: Sends an alarm message via email (Email settings must be configured).

  • Snapshot & Upload FTP: Sends a snapshot to a configured FTP server.

  • Snapshot & SD Card Save: Saves the snapshot to the device’s local storage.

  • Sync Alarm Info to Home assistant: Syncs alarm event details to the mobile app.

  • Cloud Call Alarm: Sends the alarm event to the cloud service GDMS SecureAccess and initiates a cloud-based notification call to authorized users or devices associated with the cloud account.

Operation

Available actions for each profile:

  • Edit: Modify the configuration and actions of the profile.

  • Simulation Alarm: Manually trigger the profile for testing or immediate response.

Alarm Action→Alarm Notification Settings

Call Mode

Specified the call mode for the SIP alarm:

  • Serial Hunting: Calls targets one by one until one answers.

  • Parallel Hunting: Calls all targets simultaneously.

Default setting is “Serial Hunting”.

Alarm Calling Timeout(s)

Sets the timeout period, in seconds, for alarm calls. If the remote party does not answer within this period, the call will automatically disconnect. The valid range is 10 to 90 and the default value is 60 seconds.


Note: This setting takes precedence over the call timeout configured in the account settings.

Alarm Prompt Tone

Specifies the audio prompt played when a SIP alarm call is triggered. If set to silent prompt, no prompt is played and normal calls can be made immediately after connection.


If a custom prompt is set, the recipient will first hear a 5-second prompt tone before normal communication begins. (Supported audio formats: MP3, WAV, OGG, WMA, MID, M4A)

SIP Alarm

Call Number

Defines the number called when the SIP alarm is triggered, users can configure up to 4 numbers:

  • Accounts: Select which SIP account to use for the outgoing alarm call.

  • Call Number: Enter the SIP number or IP address to call.

Cloud Call Alarm

Cloud Call Number

Enter the cloud-based number to be used for alarm calls, if applicable. When cloud service is enabled, Account 4 (Cloud Account) is fixed as the call-out account.

Audio Alarm

Alarm Prompt Tone

Select a built-in audio file or upload a custom one to be played when the alarm is triggered. Supported formats: mp3, wav, ogg, wma, mid, m4a.

Play Rules

Define how the audio file will be played during the alarm. The options are

  • Maximum Duration: Plays the sound based on a configured maximum duration.

  • Number of Loops: Plays the selected alarm sound repeatedly for the specified number of times

The default method is “Maximum Duration”.

Maximum Duration (s)

Sets the maximum time (in seconds) the audio prompt will play. The valid range is 1-3600 seconds and the default setting is 60.

Number of Loops

Specifies how many times the audio will repeat. The valid range is 1-10 and the default setting is 1.

Alarm Record

Export

Export alarm record as .csv file.

Clear

Delete all alarm records from the list.

Refresh

Update the list to display the most recent alarm events.

No.

Sequential number of each alarm record.

Alarm Event

Triggered alarm type (e.g., Intrusion, Tamper Alarm).

Alarm triggered

Indicates the source that activated the alarm

Alarm Notification

The action(s) taken in response to the alarm (e.g., SIP Call, Audio Alarm).

Alarm Time

Timestamp when the alarm event occurred.

Audio & Video Settings Page Definition

Audio Settings

Call Volume

Adjusts the speaker volume level during calls.

Doorbell Volume

Adjusts the speaker volume for the doorbell tone.

Open Door Tone Volume

Sets the volume for the confirmation tone played when the door is successfully opened.

Alarm Tone volume

Controls the loudness of general alarm notifications (e.g., intrusion, loitering).

Tamper Alarm Volume

Sets the volume level specifically for tamper alarm events.

System Volume

Adjusts the overall system sounds, including prompts and notifications.

Audio Settings

Doorbell Tone

Configures the doorbell sound (Supports uploading audio files in MP3, WAV, OGG, WMA, MID, and M4A formats).

Internal Open Door Tone

Configures the tone played when the internal open door action is triggered (Supports uploading audio files in MP3, WAV, OGG, WMA, MID, and M4A formats).

External Open Door Tone

Configures the tone played when the external open door action is triggered (Supports uploading audio files in MP3, WAV, OGG, WMA, MID, and M4A formats).

Door Opening Failure Prompt Tone

The sound or prompt played when a door opening attempt fails, such as access denied (Supports uploading audio files in MP3, WAV, OGG, WMA, MID, and M4A formats).

Audio Output Mode

The Audio Output Mode option defines how the device routes its audio signal between the built-in speaker and the Line-out port. This allows flexibility depending on whether you want to use only the internal horn speaker, connect to an external amplifier, or use both simultaneously.

  • SPK + Lineout: Uses both output modes.

  • Speaker Only: The audio output is directed exclusively to the built-in speaker of the device. Use this mode when the horn’s internal speaker alone is sufficient for broadcasting announcements or alarms.

  • Lineout Only: The audio output is sent only to the Line-out port. This mode is used when connecting the device to an external amplifier, PA system, or powered speaker, bypassing the internal horn.

Default setting is “SPK + Lineout”.

IP Announcement

Announcement Time after Startup (s)

Configure the time when IP announcement can be triggered after booting up. Beyond this time, IP announcement cannot be triggered.


Valid Range is 60-300 seconds. Default setting is 60.

Number of Loops

Configure the number of loop broadcasts for IP announcements.


Valid Range is 1-3 times. Default setting is 1.

OSD Settings

Display time

Enables or disables the display of date and time on the video stream.

Enabled by default.

OSD Date Format

Specifies the format in which the date is displayed:

  • YYYY-MM-DD

  • MM/DD/YYYY

  • DD MM YYYY

Default setting is “MM/DD/YYYY”.

OSD Time Format

Sets the format for displaying time:

  • 24H: 24-hour format (e.g., 14:00)

  • 12H: 12-hour format with AM/PM

Default setting is “24H”.

OSD Date/Time Position

Selects the on-screen location where the date and time appear:

  • Top Left

  • Bottom Left

  • Top Right

  • Bottom Right

Default setting is “Top Left”.

Display Text

Enables or disables the display of custom text on the video.


Enabled by default.

OSD Text

Allows input of a custom label to display on the video stream. Maximum allowed byte length: 25.

OSD Text Position

Selects where the custom OSD text appears on the screen:

  • Top Left

  • Bottom Left

  • Top Right

  • Bottom Right

Default setting is “Top Right”.

CMOS Settings

Wide Dynamic Range (WDR)

Enhances image visibility in scenes with both bright and dark areas by balancing exposure.

  • WDR (Wide Dynamic Range): Enables wide dynamic range for better image clarity in challenging lighting.

  • Normal: Disables WDR, using standard exposure settings.

WDR Schedule

Defines the schedule of the Wide Dynamic Range Camera view mode. It can be set to either Daily, meaning the Wide Dynamic Range will be enabled all the time. or to select one of the 50 schedules configured under System Settings => TimeTable.
By default, it is set to “Daily”

Power Frequency

Sets the power line frequency to reduce flicker in the video caused by artificial lighting.

  • 60Hz.

  • 50Hz.

Default setting is “60HZ”.

Privacy Masks

Zone Edit 0/4

Configure up to 4 privacy mask zones to block specific areas in the video for privacy (e.g., windows, neighboring properties).

  • Zone ID: Identifier for each mask zone (e.g., Zone 1, Zone 2).

  • Enable: Check to activate the privacy mask for the selected zone.

  • Operation: Remove the selected privacy mask zone.

Monitoring Page Definitions

Onvif

Onvif

Enable or disable ONVIF protocol support for integration with third-party video management systems.


Disabled by default.

Onvif Username

Username used for ONVIF authentication when a third-party system connects to the device.

Onvif Password

Password used for ONVIF authentication.


Note:
It is recommended that the ONVIF account credentials match the RTSP stream credentials to avoid preview or connection issues in third-party software.

RTSP

Note

This configuration is exclusive for the GSC3565 model.

RTSP→RTSP Server

RTSP

Enable or disable the RTSP (Real-Time Streaming Protocol) server for video stream access.


Disabled by default.

RTSP Port

Specifies the port used for RTSP streaming (default is 554).

RTSP Authentication

Select the method of user authentication for accessing the RTSP stream:

  • Basic: Sends credentials in plain text (less secure).

  • Digest: Sends hashed credentials (more secure and recommended).

Default setting is “Digest”.

RTSP Username

Username required to access the RTSP video stream.

RTSP Password

Password required to access the RTSP video stream.

Note: For best compatibility with third-party software, use the same credentials as the ONVIF account.

RTSP→Stream

Stream (1/2)

Preferred Video Codec

Specifies the compression format used for streaming:

  • H.264: Widely supported, good balance of quality and bandwidth.

  • MJPEG: Uses more bandwidth, but offers high image quality per frame.

Default setting is H.264.

Profile

Selects the H.264 profile for encoding:

  • Baseline: Basic compatibility, low complexity.

  • Main Profile: Better compression and quality, standard for most uses.

  • High Profile: Best video quality and efficiency, requires more processing power.

Resolution

Specifies the output video resolution:

  • 1920×1080 (Full HD)

  • 1280×720 (HD)

  • 640×360 (Low resolution)

Default resolution for Stream 1: 1920*1080.

Default resolution for Stream 2: 1280*720.

Bit Rate(kbps)

Sets the target video bitrate in kilobits per second, affecting video quality and bandwidth usage. Options: 256, 512, 1024, 2048, 4096 kbps.


Default setting for Stream 1: 2048.

Default setting for Stream 2: 1024.

Frame Rate(fps)

Number of frames per second. A higher frame rate provides smoother video. Options: 5, 10, 15, 20, 25, 30 fps.


Default setting is 30.

Bit Rate Control

Enables dynamic bitrate adjustment based on scene complexity and motion, optimizing bandwidth usage.

I-frame Interval

Specifies how many frames are sent between two consecutive I-frames (key frames). A lower interval improves seek performance and stream stability but increases bandwidth.


Valid range is 5-150. Default setting is 30.

Accounts Page Definitions

Accounts

Account x→General Settings

Account Register

Account Active

Indicates whether the account is active.

The default setting is “Yes”.

Account Name

The name associated with each account.

SIP Server

The URL or IP address, and port of the SIP server. This is provided by your VoIP service provider (e.g., sip.mycompany.com, or IP address)

Secondary SIP Server

The URL or IP address, and port of the SIP server. This will be used when the primary SIP server fails

Outbound Proxy

Defines IP address or Domain name of the Primary Outbound Proxy, Media Gateway, or Session Border Controller.

Secondary Outbound Proxy

Defines secondary outbound proxy that will be used when the primary proxy cannot be connected.

SIP User ID

User account information, provided by your VoIP service provider.

SIP Authentication ID

SIP service subscriber’s Authenticate ID used for authentication. It can be identical to or different from the SIP User ID.

SIP Authentication Password

The account password required for the GSC356x to authenticate with the SIP server before the account can be registered.

After it is saved, this will appear as hidden for security purpose.

Display Name

The SIP server subscriber’s name (optional) that will be used for Caller ID display (e.g., John Doe).

TEL URI

If the GSC356x has an assigned PSTN telephone number, this field should be set to “user=phone”. A “user=phone” parameter will be attached to the Request-URI and “To” header in the SIP request to indicate the E.164 number. If set to “Enable”, “tel:” will be used instead of “sip:” in the SIP request.

Network Settings

DNS Mode

This parameter controls how the Search Appliance looks up IP addresses for hostnames. If “Use Configured IP” is selected, please fill in Primary IP, Backup IP 1 and Backup IP 2.

  • A Record

  • SRV

  • NAPTR/SRV

  • Use Configured IP

Max Number Of Sip Request Retries

Sets the maximum number of retries for the device to send requests to the server. In DNS SRV configuration, if the destination address does not respond, all request messages are resent to the same address according to the configured retry times. Valid range: 1-10.

DNS SRV Failover Mode

Configures the preferred IP mode for DNS SRV. If set to “default”, the first IP from the query result will be applied. If set to “Saved one until DNS TTL”, previous IP will be applied before DNS timeout is reached. If set to “Saved one until no response”, previous IP will be applied even after DNS timeout until it cannot respond.

  • Default

If the option is set with “default”, it will again try to send register messages to one IP at a time, and the process repeats.

  • Saved one until DNS TTL

If the option is set with “Saved one until DNS TTL”, it will send register messages to the previously registered IP first. If no response, it will try to send one at a time for each IP. This behavior lasts if DNS TTL (time-to-live) is up.

  • Saved one until no responses

If the option is set with “Saved one until no responses”, it will send registered messages to the previously registered IP first, but this behavior will persist until the registered server does not respond.

  • Failback follows failback expiration timer

 If “Failback follows failback expiration timer” is selected, the device will send all SIP messages to the current failover SIP server or Outbound Proxy until the failback timer expires.

Failback Expiration (m)

Specifies the duration (in minutes) since failover to the current SIP server or Outbound Proxy before making failback attempts to the primary SIP server or Outbound Proxy.

Register Before DNS SRV Failover

Configures whether to send REGISTER requests to the failover SIP server or Outbound Proxy before sending INVITE requests in the event of a DNS SRV failover.

Primary IP

Configures the primary IP address where the GSC356x sends DNS query to when “Use Configured IP” is selected for DNS mode.

Backup IP 1

Configures the backup IP 1 address where the GSC356x  sends DNS query to when “Use Configured IP” is selected for DNS mode.

Backup IP 2

Configures the backup IP 2 address where the GSC356x  sends DNS query to when “Use Configured IP” is selected for DNS mode.

Proxy-Require

A SIP Extension to notify the SIP server that the GSC356x is behind a NAT/Firewall.

NAT Traversal

Configures whether NAT traversal mechanism is activated. Please refer to user manual for more details.

If set to “STUN” and STUN server is configured, the GSC356X  will route according to the STUN server. If NAT type is Full Cone, Restricted Cone or Port-Restricted Cone, the GSC356x will try to use public IP addresses and port number in all the SIP&SDP messages.

The GSC356x will send empty SDP packet to the SIP server periodically to keep the NAT port open if it is configured to be “Keep-alive”. Configure this to be “No” if an outbound proxy is used. “STUN” cannot be used if the detected NAT is symmetric NAT. Set this to “VPN” if OpenVPN is used.

Media NAT Traversal

For configuring media NAT traversal strategies: If configured as “No,” media NAT traversal will not be used. If configured as “Auto,” it will follow the business logic of the “NAT traversal(STUN)” configuration. If configured as “STUN,” it will obtain the public IP and port information after NAT through a shared STUN server. If configured as “TURN,” it will forward the data stream through a TURN relay server. If configured as “ICE,” it will collect local IP addresses, STUN-reflected addresses, and TURN relay addresses to dynamically select the optimal connection path.

Account x→SIP Settings

Basic Settings

SIP Registration

Selects whether the GSC356x will send SIP Register messages to the proxy/server. The default setting is “Enabled”.

UNREGISTER on Reboot

  • If set to “No”, the GSC356x will not unregister the SIP user’s registration information before new registration.

  • If set to “All”, the SIP Contact header will use “*” to clear all SIP user’s registration information. 

  • If set to “Instance”, the GSC356x only needs to clear the current SIP user’s info.

REGISTER Expiration

Specifies the frequency (in minutes) in which the GSC356x refreshes its registration with the specified registrar.

The maximum value is 64800 minutes (about 45 days). The default value is 60 minutes.

SUBSCRIBE Expiration

Specifies the frequency (in minutes) in which the GSC356x  refreshes its subscription with the specified registrar.

The maximum value is 64800 minutes (about 45 days). The default value is 60 minutes.

Re-Register before Expiration

Specifies the time frequency (in seconds) that the GSC356x  sends re-registration request before the Register Expiration. The default value is 0.

Registration Retry Wait Time

Specifies the interval to retry registration if the process is failed. The valid range is 1 to 3600. The default value is 20 seconds.

Add Auth Header on Initial REGISTER

If enabled, the GSC356x will add Authorization header in initial REGISTER request.

Default is “Disabled”.

Enable OPTIONS Keep-Alive

Configures whether to enable SIP OPTIONS to track account registration status. If enabled, the GSC356x will send periodic OPTIONS messages to server to track the connection status with the server.

Default is “Disabled”.

OPTIONS Keep-Alive Interval

Configures the time interval the GSC356x sends OPTIONS message to the server. If set to 30 seconds, it means the GSC356x will send an OPTIONS message to the server every 30 seconds.

OPTIONS Keep-Alive Max Tries

Configures the maximum number of times the GSC356x will try to send OPTIONS message consistently to server without receiving a response. If set to “3”, the GSC356x will send OPTIONS message 3 times. If no response from the server, the GSC356x will re-register.

SUBSCRIBE for Registration

When set to “Yes”, a SUBSCRIBE for Registration will be sent out periodically.

The default setting is “No”.

Use Privacy Header

Configures whether the “Privacy Header” is present in the SIP INVITE message.

  • Default: the GSC356X will add “Privacy Header” when special feature is not “Huawei IMS”.

  • Yes: the GSC356X will always add “Privacy Header”.

  • No: the GSC356X will not add “Privacy Header”.

The default setting is “default”.

Use P-Preferred- Identity Header

Configures whether the “P-Preferred-Identity Header” is present in the SIP INVITE message.

  • Default: the GSC356X will add “P-Preferred-Identity header” when special feature is not “Huawei IMS”.

  • Yes: the GSC356x will always add “P-Preferred-Identity header”.

  • No: the GSC356x will not add “P-Preferred-Identity header”.

Add MAC in User-Agent

  • If Yes except REGISTER, all outgoing SIP messages will include the GSC356X’s MAC address in the User-Agent header, except for REGISTER and UNREGISTER.

  • If Yes to All SIP, all outgoing SIP messages will include the GSC356X’s MAC address in the User-Agent header.

  • If No, the GSC356X’s MAC address will not be included in the User-Agent header in any outgoing SIP messages.

The default setting is “No”.

SIP Transport

Selects the network protocol used for the SIP transport.

The default setting is “UDP”.

Enable TCP Keep-alive

Configures whether to enable TCP Keep-alive for the TCP connection between the terminal and the SIP server.

Local SIP Port

Configures the local SIP port used to listen and transmit.

SIP URI Scheme when using TLS

Specifies if “sip” or “sips” will be used when TLS/TCP is selected for SIP Transport. The default setting is “sips”.

Use Actual Ephemeral Port in Contact with TCP/TLS

Configures whether the actual ephemeral port in contact with TCP/TLS will be used when TLS/TCP is selected for SIP Transport.

The default setting is “No”.

Support SIP Instance ID

Configures whether SIP Instance ID is supported or not.

The default setting is “Yes”.

SIP T1 Timeout

SIP T1 Timeout is an estimate of the round-trip time of transactions between a client and server. If no response is received the timeout is increased and request re-transmit retries would continue until a maximum amount of time define by T2. The default setting is 0.5 seconds.

SIP T2 Timeout

SIP T2 Timeout is the maximum retransmit time of any SIP request messages (excluding the INVITE message). The re-transmitting and doubling of T1 continues until it reaches the T2 value. Default is 4 seconds.

SIP Timer D Interval

Sets the wait time for response retransmissions when the INVITE receives a 3xx ~ 6xx response. Valid range is 32-64 seconds. Default is 32.

Outbound Proxy Mode

Configures whether to put the Outbound Proxy in the Route header, or if SIP messages should always be sent to Outbound Proxy.

  • In route

  • Not in route

  • Always send to

Default is “in route”.

Enable 100rel

When enabled, the 100rel tag is appended to the value of the Supported header of the initial signaling messages.

The default setting is “No”.

Session Timer

Enable Session Timer

Configures whether to enable session timer function. It enables SIP sessions to be periodically “refreshed” via a SIP request (UPDATE, or re-INVITE). If there is no refresh via an UPDATE or re-INVITE message, the session will be terminated once the session interval expires. If set to “Yes”, the GSC356X will use the related parameters when sending session timer according to “Session Expiration”. If set to “No”, session timer will be disabled.

The default setting is “No”.

Session Expiration

Session Expiration is the time (in seconds) where the session is considered timed out, provided no successful session refresh transaction occurs beforehand.

The default setting is 180. The valid range is from 90 to 64800.

Min-SE

The minimum session expiration (in seconds). The default value is 90 seconds. The valid range is from 90 to 64800.

Caller Request Timer

If set to “Yes” and the remote party supports session timers, the GSC356X will use a session timer when it makes outbound calls.

The default setting is “No”.

Callee Request Timer

If set to “Yes” and the remote party supports session timers, the GSC356X will use a session timer when it receives inbound calls.

The default setting is “No”.

Force Timer

If set to “Yes”, the GSC356X will use the Session Timer even if the remote party does not support this feature. Otherwise, Session Timer is enabled only when the remote party supports it.

The default setting is “No”.

UAC Specify Refresher

As a caller, select UAC to use the GSC356X as the refresher, or select UAS to use the callee or proxy server as the refresher. When set to “Omit”, the refresh object is not specified.

The default setting is “UAC”.

UAS Specify Refresher

As a callee, select UAC to use caller or proxy server as the refresher, or select UAS to use the GSC356X as the refresher.

The default setting is “UAC”.

Force INVITE

Select “Yes” to force using the INVITE method to refresh the session timer.

The default setting is “No”.

Account x→Codec Settings

Audio

Preferred Vocoder

(Choice 1 – 5)

Multiple vocoder types are supported on the GSC356X, the vocoders in the list is a higher preference. Users can configure vocoders in a preference list that is included with the same preference order in SDP message.
The vocoders supported are:

  • PCMU

  • PCMA

  • G.722 (wide band)

  • G.729A/B

  • G.726-32

Codec Negotiation Priority

Configures the GSC356X to use which codec sequence to negotiate as the callee. When set to “Caller”, the GSC356X  negotiates by SDP codec sequence from received SIP Invite. When set to “Callee”, the GSC356X negotiates by audio codec sequence on the GSC356X. The default setting is “Callee”.

Use First Matching Vocoder in 200OK SDP

When set to “Yes”, the device will use the first matching vocoder in the received 200OK SDP as the codec. The default setting is “No”.

G.726-32 Packing Mode

Selects “ITU” or “IETF” for G.726-32 packing mode.

The default setting is “ITU”.

G.726-32 Dynamic Payload Type

Specifies G.726-32 payload type. Valid range is 96 to 126. Default is 126.

Send DTMF

Specifies the mechanism to transmit DTMF digits. There are 3 supported modes:

  • In audio: DTMF is combined in the audio signal (not very reliable with low-bit-rate codecs).

  • RFC2833 sends DTMF with RTP packet. Users can check the RTP packet to see the DTMFs sent as well as the number pressed.

  • SIP INFO uses SIP INFO to carry DTMF.

Default setting is “RFC2833”.

DTMF Payload Type

Configures the payload type for DTMF using RFC2833. Cannot be the same as iLBC or OPUS payload type.

Enable Audio RED with FEC

If set to “Yes”, FEC will be enabled for audio call.

Audio FEC Payload Type

Configures audio FEC payload type. The valid range is from 96 to 126.

The default value is 121.

Audio RED Payload Type

Configures audio RED payload type. The valid range is from 96 to 126.

The default value is 124.

Silence Suppression

Configures G.729 silence suppression, also known as dynamic voice detection (VAD). When set to “Yes”, the device detects periods of no voice activity during a call and sends a minimal number of VAD packets instead of continuous voice packets.

Default setting is “No”.

Voice Frames Per TX

Configures the number of voice frames transmitted per packet. It is recommended that the IS limit value of Ethernet packet is 1500 bytes or 120 kbps. When configuring this, it should be noted that the “ptime” value for the SDP will change with different configurations here. This value is related to the codec used in the codec table or negotiate the payload type during the actual call. For example, if set to 2 and the first code is G.729, G.711 or G.726, the “ptime” value in the SDP datagram of the INVITE request is 20 ms. If the “Voice Frame/TX” setting exceeds the maximum allowed value, GSC356X will use and save the maximum allowed value for the selected first codec. It is recommended to use the default setting provided, and incorrect setting may affect voice quality.

The default setting is 2.

Preferred Video Codec

Preferred Video Codec

Specifies the prefered video codec used for GSC356X. The supported codec for this device is H.264.

Enable Video FEC

When enabled, the video sender will temporarily allocate part of the bandwidth to one data channel to send FEC data to system, thus, to improve the video quality the receiver gets. Enabling this function will take up part of bandwidth and reduce call rate. The default setting is “Yes”.

FEC Payload Type

Configures FEC payload type. The range is 96-126. Default setting is 120.

Packetization Mode

Configures video packetization mode. If set to “Single NAL Unit Mode”, the packetization mode will be negotiated as single NAL unit mode when dial video calls, if the other party does not support the negotiation, then single NAL unit mode will be used for video encoding by default. If set to “Non-Interleaved Mode”, the packetization mode will be negotiated as Non-interleaved mode when dial video calls, If the other party does not support negotiation, then the Non-interleaved mode will be used for video encoding by default. The default setting is “Non-Interleaved Mode”.

Image Size

Sets the image size. It can be selected from the dropdown list.

  • 1080P

  • 720P

  • 4CIF

  • VGA

The default setting is 1080P.

Use H.264 Constrained Profiles

Configures that whether to set H.264 constrained profiles.

The default setting is “Yes”.

H.264 Profile Type

Selects the H.264 profile type from the dropdown list.

  • Baseline Profile

  • Main Profile

  • High Profile

  • BP/MP/HP (Default Setting)

Note: Lower levels are easier to decode, but higher levels offer better compression. Usually, for the best compression quality, choose “High Profile”; for playback on low-CPU machines or mobile devices, choose “Baseline Profile”. If “BP/MP/HP” is selected, all three profiles “Baseline Profile” “Main Profile” and “High Profile” will be used for negotiation during video decoding to achieve the best result. This is usually used in video conference when there is higher requirement on the video.

Video Bit Rate

Configures the bit rate for video call. It can be selected from the dropdown list. The default setting is 2048 kbps.


Note: The video bit rate can be adjusted based on the network environment. Increasing the video bit rate may improve video quality if the bandwidth is permitted. If the bandwidth is not permitted, the video quality will decrease due to packet loss. For some network environment, the default setting “1080P” might be too high that causes no video or video quality issue during video call. In this case, please change “H.264 Image Size” to “VGA” or “CIF” and change “Video Bit Rate” to “384kbps” or lower.

SDP Bandwidth Attribute

Specifies the SDP (Session Description Protocol) bandwidth attribute used for video streaming.

  • Standard: Uses AS format at the session level and TIAS format at the media level.

  • Media Stream Level: Uses AS format at the media level only.

  • Session Level: Uses AS format at the session level only.

  • None: No changes are made to the session format.

The default Setting is “Media Stream Level”.


Note: Please do not modify this setting without knowing the session format supported by the server. Otherwise, it might cause video decoding failure.

H.264 Payload Type

Enter H.264 codec payload type. The valid range is from 96 to 126. Default is 99.

Packet Retransmission

If set to “NACK”, the signaling will carry NACK info. After negotiation, the media will use NACK to retransmit lost packets.

If set to “NACK+RTX (SSRC-GROUP) “, the signaling will carry both NACK and RTX info. After negotiation, the media will use NACK+RTX (SSRC-GROUP), which is the default setting, to achieve packet loss retransmission.

If set to “Disabled”, packet loss retransmission cannot be used.

RTP Settings

SRTP Mode

Enable SRTP mode based on your selection from the drop-down menu.

  • No

  • Enabled but Not Forced

  • Enabled and Forced

  • Optional

The default setting is “No”.

SRTP Key Length

Allows users to specify the length of the SRTP calls. Available options are:

  • AES 128&256 bit

  • AES 128 bit

  • AES 256 bit

Default setting is AES 128&256 bit

Crypto Life Time

Enable or disable the crypto lifetime when using SRTP. If users set to disable this option, GSC356X does not add the crypto lifetime to SRTP header. The default setting is “No”.

RTCP Destination

Configures the server address. When there is a call, the RTCP package sent from the GSC356X will also be sent to this address. Note: The address should contain port number.

RTCP Keep-Alive Method

Configures the RTCP channel keep-alive packet type.

  • Receiver Report: The RTCP channel will sends “receiver report+source description+RTCP extension” as keep-alive data.

  • Sender Report: The RTCP channel will sends “Sender report+source description+ RTCP extension” as keep-alive data.

Default setting is “Receiver Port”.

RTP Keep-Alive Method

Configures the RTP channel keep-alive packet type.

  • No: No data will be sent

  • RTP Version 1: The wrong version infor “1” will be carried when sending RTP data packets.

Default setting is “RTP Version 1”.

Symmetric RTP

Configures whether Symmetric RTP is used or not. Symmetric RTP means that the UA uses the same socket/port for sending and receiving the RTP stream. The default setting is “No”.

RTP IP Filter

Configures whether to filter the received RTP. If set to “Disable”, the device will receive RTP from any address; If set to “IP Only”, the device will receive RTP from certain IP address in SDP with no port limited; If set to “IP and Port”, the device will only receive RTP from IP address & port in SDP.
Disabled by Default

RTP Timeout (s)

Configures the RTP timeout of the GSC356X. If the GSC356X does not receive the RTP packet within the specified RTP time, the call will be automatically disconnected. The default range is 0 and 6-600. If set to 0, the GSC356X will not hang up the call automatically.

Account x→Call Settings

General

Video Send/Receive Capability

Configures the video sending and receiving capability for the account to ensure SIP proxy compatibility.

The default setting is “sendonly”.

  • send only: Send video only.

  • send and recieve: Send and receive video.

Auto Answer

Specifies whether the GSC356X automatically answers incoming calls. Options:

  • Yes: The device automatically answers incoming calls after a short reminder beep (Default setting).

  • No: The device does not automatically answer incoming calls.

  • Intercom/Paging Only: The device automatically answers only intercom or paging calls.

Custom Alert-Info for Auto Answer

Specifies the Alert-Info content used to trigger automatic answering for paging/intercom calls (Maximum allowed length is 20 characters).


Notes:

  • Only when the Alert-Info header of an incoming call matches the configured content will the device automatically answer the call.

  • If left blank, paging calls will ring according to the Incoming Call Rules instead of being auto-answered.

Play warning tone for Auto Answer Intercom

If enabled, GSC356X will play warning tone when auto answering Intercom.

Send Anonymous

If set to “Yes”, the “From” header in outgoing INVITE messages will be set to anonymous. Default is “No”.

Anonymous Call Rejection

If set to “Yes”, anonymous calls will be rejected.

The default setting is “No”.

Call Log

Configures Call Log setting on the GSC356X.

  • Log All Calls

  • Log incoming/outgoing only (missed calls will NOT be logged)

  • Disable Call Log

The default setting is “Log All Calls”.

Mute on Intercom Answer

If enabled, the GSC356X will mute the mirophone after answer an intercom call via Call-Info/Alert-Info.

Ring Timeout

Configures the timeout (in seconds) for the GSC356X to ring when an incoming call is not answered. Valid range is 30 to 3600. The default setting is 60.

Call Timeout

Set the SIP call timeout(in seconds). When the SIP call exceeds the set time, the call will be automatically hung up. When set to 0, the call will not be automatically hung up. Valid range is 0 to 65535. Default setting is 0.

Calling Timeout (s)

Specifies the maximum duration, in seconds, the system will wait for the call to be answered. If the call is not answered within this period, it will automatically disconnect. The valid range is 10 to 300 seconds, and the default is 90 seconds.

Ringtone

Account RingTone

Allows users to configure the ringtone for the account. Users can choose from different ringtones from the dropdown menu.

Note: User can also choose silent ring tone or doorbell.

Ignore Alert-Info header

Configures to play default ringtone by ignoring Alert-Info header.

The default setting is “No”.

Account x→Advanced Settings

Security Settings

Check Domain Certificates

Configures whether the domain certificates will be checked when TLS/TCP is used for SIP Transport. The default setting is “No”.

Validate Certificate Chain

Validate certification chain when TCP/TLS is configured.

The default setting is “No”.

Validate Incoming SIP Messages

Specifies if the GSC356X will check the incoming SIP messages Caller ID and CSeq headers. If the message does not include the headers, it will be rejected. The default setting is “No”.

Allow Unsolicited REFER

Configures whether to dial the number carried by Refer-to header after receiving out-of-dialog SIP REFER request actively.

If set to “Disabled“, the GSC356X will send error warning and stop dialing.

If set to “Enabled/Force Auth“, the GSC356X will dial the number after sending authentication. If the authentication fails, it will stop dialing.

If set to “Enabled“, the GSC356X will dial all numbers carried by SIP REFER.

Accept Incoming SIP from Proxy Only

When set to “Yes”, the SIP address of the Request URL in the incoming SIP message will be checked. If it does not match the SIP server address of the account, the call will be rejected. The default setting is “No”.

Check SIP User ID for Incoming INVITE

If set to “Yes”, SIP User ID will be checked in the Request URI of the incoming INVITE. If it does not match the GSC356X’s SIP User ID, the call will be rejected. The default setting is “No”.

Allow SIP Reset

Allow SIP Notification message to perform factory reset.

The default setting is “No”.

Authenticate Incoming INVITE

If set to “Yes”, the GSC356X will challenge the incoming INVITE for authentication with SIP 401 Unauthorized response.

The default setting is “No”.

SIP Realm Used For Challenge INVITE & NOTIFY

Configures this option to verify incoming INVITE, only take effect when enabled incoming INVITE first. It is used to verify provision NOTIFY information, including check-sync, resync and reboot, but only effective when enabled SIP authentication.

MOH

MOH Mode

Configures MOH mode:

  • If set to “Local MOH“, a local MOH audio file needs to be uploaded for this mode to work.

  • If set to “Disable” the MOH will be disabled.

Default setting is “Disable”.

Upload Local MOH Audio File

Click to upload audio file from PC. The MOH audio file should be “.ogg” format.

Advanced Features

Special Feature

Different soft switch vendors have special requirements. Therefore, users may need select special features to meet these requirements. Users can choose from the drop down list:

  • Standard Mode

  • Nortel MCS

  • Broadsoft

  • CBCOM

  • RNK

  • Sylantro

  • Huawei IMS

  • PhonePower

  • UCM Call center

  • Zoom

Reboot on check-sync event without “reboot=”

If enabled, the device will reboot when receiving a SIP NOTIFY check-sync event without the “reboot=” header. If disabled, the device will update its configuration without rebooting.
Enabled by default.

Calls Page Definitions

Outgoing Calls

This page allows users to place outgoing calls from the GSC356X device using the Web UI.

  • Account Selection:
    Choose the SIP account to use when making a call from the available configured accounts.
  • Dial Number/IP:
    Enter the phone number or IP address of the destination you want to call.
  • Call Button:
    Initiates the call using the selected account and the entered number/IP.
  • Recent Calls List:
    Displays a history of recently dialed numbers for quick redial. You can click on an entry to automatically populate the dial field.
GSC356X Outgoing Calls Page

Call History

Call History→Call History

Delete

Removes selected call records from the list.

Delete All

Clears all call history records.

Add to Allowlist

Adds selected numbers to the allowlist to permit future calls.

Call Status

Indicates the direction of the call: Outgoing, Incoming.

Name

Displays the contact name if available.

Number

The phone number or IP address involved in the call.

Time

Timestamp of when the call occurred.

Operation

Available actions for each record:

  • Dial: Dial the number.

  • Details: View full call information.

  • Add to Allowlist: Permit future calls from this number/IP.

  • Add Users of the Access Control: Create an access control user entry with this number.

  • Delete: Remove the individual call record.

Call History→Intercept record

Delete

Removes selected intercepted call records from the list.

Add to Allowlist

Adds selected numbers to the allowlist, allowing future calls from them.

Name

Displays the caller’s name if available.

Number

The intercepted phone number or IP address.

Time

Timestamp of when the call was intercepted.

Operation

Available actions for each record:

  • Dial: Call the intercepted number.

  • Details: View more information about the intercepted call.

Call Settings

Video Call

Enables the video call feature on the GSC356X. The default setting is “Yes”.

Video Frame Rate

The video frame rate is adjustable based on network condition. Increasing the frame rate will significantly increase the amount of data transmitted, therefore consuming more bandwidth.

The video quality will deteriorate due to packet loss if extra bandwidth is not allocated.

Call Waiting

Enables the call waiting feature. If it is not checked, the GSC system will reject the second incoming call during an active session without user’s knowledge. But this missed call record will be saved to remind users.


The default setting is “Yes”.

Call Waiting Tone

Specifies whether the GSC356X plays a call waiting tone when another incoming call is received while a current call is in progress.


The default setting is “Yes”.

DND

Enable/disable the DND (Do not disturb) feature. If enabled, this device will block all incoming calls.


Disabled by default.

DND Prompt Sound

Enable/disabed the sound or tone played when a call is received while the device is in Do Not Disturb (DND) mode.

Enabled by default.

Multicast Tone

Enables/disables multicast tone.If enabled, there will be a prompt tone at the beginning and end of the multicast.


Disabled by default.

Automatic Answer Ringing Time (s)

Configures a ringing timer after which the GSC356X will answer an incoming call automatically.

Valid range is 0 to 10 seconds and the default setting is 0.

Filter Characters

Specifies characters to be automatically removed when dialing numbers. These characters are not part of the actual phone number and will be filtered out during dialing (Multiple characters can be set for filtering).


For example: if set to “[()-]”, when dialing (0571)-8800-8888, the character “()-” will be automatically filtered and dial 057188008888 directly.


Notes:

  • Filtering applies to calls initiated from call history or Click2Dial.

  • Dialing directly from the keypad will not filter any characters.

Noise Suppression Mode

The Noise Suppression Mode parameter determines how background noise is filtered during audio communication, helping to improve voice clarity and overall call quality. Users can choose between Classic Noise Suppression and AI Noise Suppression depending on the environment and application requirements.

  • Classic Noise Suppression: Uses traditional digital signal processing (DSP) algorithms to reduce common background noises such as fan noise, air conditioning, or low-level ambient sounds. This mode provides stable and efficient noise reduction with low processing overhead, making it suitable for most standard indoor environments.

  • AI Noise Suppression: Utilizes advanced artificial intelligence algorithms to distinguish human speech from surrounding noise in real time. It can more effectively suppress dynamic and complex noises such as conversations, traffic, machinery, or crowded environments while preserving voice quality. This mode is recommended for challenging acoustic conditions where maximum speech intelligibility is required.

Call Settings→Allowlist Management

Allowlist

Enable or disable allowlist functionality. If enabled, only the allowlist numbers are be able to call in, other numbers will be blocked. (Disabled by default)

Add

Manually add a new entry to the allowlist (name and number/IP).

Delete

Remove selected entries from the allowlist.

Delete All

Clear all entries from the allowlist.

Name

The label or identifier for the allowed contact.

Number

The phone number or IP address to allow.

Operation

Available actions for each entry:

  • Edit: Modify the name or number/IP.

  • Delete: Remove the specific allowlist entry.

Phone Settings Page Definitions

General Settings

Local RTP Port

This parameter defines the local RTP port used to listen and transmit. It is the base RTP port for channel 0.


When configured, channel 0 will use this port _value for RTP; channel 1 will use port_value+2 for RTP. Local RTP port ranges from 1024 to 65400 and must be even. Default value is 5004.

Local RTP Port Range

Gives users the ability to define the parameter of the local RTP port used to listen and transmit.


This parameter defines the local RTP port from 24 to 10000. This range will be adjusted if local RTP port + local RTP port range is greater than 65486. Default setting is 200.

Use Random Port

When set to “Yes”, this parameter will force random generation of both the local SIP and RTP ports. This is usually necessary when multiple phones are behind the same full cone NAT. The default setting is “No”


Note: This parameter must be set to “No” for Direct IP Calling to work.

Keep-alive Interval

Specifies how often the GSC356X sends a blank UDP packet to the SIP server to keep the “ping hole” on the NAT router to open. The default setting is 20 seconds. The valid range is from 10 to 160.

STUN Server

The IP address or Domain name of the STUN server. STUN resolution results are displayed in the STATUS page of the Web GUI.

Only non-symmetric NAT routers work with STUN.

STUN Server Username

The username to validate the STUN server.

STUN Server Password

The password to validate the STUN server.

Use NAT IP

The NAT IP address used in SIP/SDP messages. This field is blank at the default settings. It should ONLY be used if it is required by your ITSP.

Ringtone

Auto Config CPT by Region

Configures whether to choose Call Progress Tone automatically by region. If set to “Yes”, the phone will configure CPT (Call Progress Tone) according to different regions automatically. If set to “No”, you can manually configure CPT parameters.

The default setting is “No”.

Call Progress Tones:

  • Ring Back Tone

  • Busy Tone

  • Reorder Tone

  • Call-Waiting Tone

Configures tone frequencies according to user preference. By default, the tones are set to North American frequencies. Frequencies should be configured with known values to avoid uncomfortable high pitch sounds.

Syntax: f1=val,f2=val [,c=on1/off1[-on2/off2[-on3/off3]]]. (Frequencies are in Hz and cadence on and off are in 10ms)

ON is the period of ringing (“On time” in “ms”) while OFF is the period of silence. In order to set a continuous ring, OFF should be zero. Otherwise it will ring ON ms and a pause of OFF ms and then repeats the pattern.

Please refer to the document below to determine your local call progress tones: https://www.itu.int/ITU-T/inr/forms/files/tones-0203.pdf

Call-Waiting Tone Gain

Adjusts the call waiting tone volume. Users can select “Low”, “Medium” or “High”. The default setting is “Low”.

Default Ring Cadence

Defines the ring cadence for the phone. The default setting is: c=2000/4000.

Multicast Paging

Multicast Paging→Multicast Paging

Paging Barge

During an active call, if an incoming multicast paging has higher priority (Disable being the highest and 1 being the second), then the device will be hung up and multicast paging will be played.

The default setting is “Disabled”.

Paging Priority Active

If enabled, during a multicast page if another multicast is received with higher priority (1 being the highest) that one will be played instead.

Enabled by default.

Multicast Paging→Multicast Listening

Priority

Indicates the priority level for the multicast listening. A lower number (1) indicates higher priority, while a higher number (10) indicates lower priority.

Listening Address

Specifies the multicast IP address that the device listens to for paging or announcements. This address allows the device to receive audio from a multicast stream.

Label

A user-defined label or name to identify the multicast listening configuration. This can be helpful for organizing multiple multicast streams.

Network Settings Page Definitions

Ethernet Settings

Internet Protocol

Selects whether to prefer IPv4 or IPv6.


Default is IPv4 Only.

IPv4

IPv4 Address Type

Users could select “DHCP”, “Static IP” or “PPPoE”.

  • DHCP: Obtain IP address via a DHCP server in the LAN. All domain values for static IP/PPPoE are unavailable, even though the values have been saved in the flash.

  • PPPoE: Configures PPPoE account/password. Obtain the IP address from the PPPoE server via dialing.

  • Static IP: Manually configures IP Address, Subnet Mask, Default Router’s IP Address, DNS Server 1, and DNS Server 2.

By default, it is set to “DHCP“.

DHCP VLAN Override

Selects the DHCP Option VLAN mode. When set to “DHCP Option 132 and DHCP option 133”, the GSC356X will get DHCP option 132 and 133 as VLAN ID and VLAN priority. When set to “Encapsulated in DHCP Option 43”, the GSC356X will get values from Option 43 which encapsulate VLAN ID and VLAN priority.


Note: Please make sure the “Allow DHCP Option 43 and Option 66 to Override Server” setting under maintenance→upgrade is checked. The default setting is “Disable”.

Hostname (Option 12)

Sets the name of the client in the DHCP request. It is optional but may be required by some Internet Service Providers.


The field is empty by default.

Vendor Class ID

(Option 60)

Configures the vendor class ID header in the DHCP request.

The default setting is “Grandstream GSC3565”.

IP Address

Defines the GSC356X’s static IP address if the static IP is used.

Subnet Mask

Determines the network’s subnet mask if the static IP is used.

Default Gateway

Defines the network’s gateway address if the static IP is used.

DNS Server 1

Configures the primary DNS IP address if the static IP is used.

DNS Server 2

Configures the secondary DNS IP address if the static IP is used.

Preferred DNS Server

Enter the Preferred DNS server.

PPPoE Account ID

Configures the PPPoE account ID if the PPPoE is used.

PPPoE Password

Sets the PPPoE password if the PPPoE is used.

Layer 2 QoS 802.1Q/VLAN Tag

Assigns the VLAN Tag of the Layer 2 QoS packets for Ethernet.


The Default value is 0.

Layer 2 QoS 802.1p Priority Value

Assigns the priority value of the Layer 2 QoS packets for Ethernet.


The Default value is 0.

IPv6

IPv6 Address

Configures the appropriate network settings on the GSC356X. Users could select from “Auto-configured” or “Statically configured”.

Static IPv6 Address

Enter the static IPv6 address in “Statically configured” IPv6 address type.

IPv6 Prefix Length

Enter the IPv6 prefix length in “Statically configured” IPv6 address type.


This field is empty by default.

IPv6 Prefix (64 bits)

Enter the IPv6 Prefix (64 bits) when Prefix Static is used in “Statically configured” IPv6 address type.


This field is empty by default.

IPv6 Gateway

The gateway when static IPv6 is used.

DNS Server 1

Enter DNS Server 1 when static IP is used.

DNS Server 2

Enter DNS Server 2 when static IP is used.

Preferred DNS Server

Enter the Preferred DNS server.

802.1X

802.1x Mode

Enables and selects the 802.1x mode for the GSC356X system. The supported 802.1x modes are:

  • EAP-MD5

  • EAP-TLS

  • EAP-PEAPv0/MSCHAPv2


The default setting is “Disable”.

802.1x Identity

Enters the identity information for the selected 802.1x mode. (This setting will be displayed only if 802.1 X mode is enabled).

MD5 Password

Enters the MD5 password for this 802.1x mode

802.1X CA Certificate

Uploads the CA Certificate file to the GSC356X. This certificate is used only when the 802.1X authentication mode is set to TLS or PEAP. It is not required for MD5 mode.

802.1X Client Certificate

Loads the Client Certificate file to the GSC356X. (This setting will be displayed only if the 802.1 X TLS mode is enabled)

OpenVPN® Settings

OpenVPN® Enable

Enables/Disables OpenVPN® feature. Default is “No”.

Manual Import

Import OpenVPN® Configuration

Imports the configuration file from the current computer. After importing, the local configuration will be overwritten and OpenVPN® function is automatically enabled.

Local Configuration

OpenVPN® Server Address

Specify the IP address or FQDN for the OpenVPN® Server.

OpenVPN® Port

Specify the listening port of the OpenVPN® server. The valid range is 1 – 65535. The default value is “1194”.

OpenVPN® Transport

Specifies whether OpenVPN® connections use TCP or UDP as the transport protocol.


The default value is “UDP”.

OpenVPN® CA

Click on “Upload” to upload the Certification Authority of OpenVPN®. For a new upload, users could click on “Delete” to erase the last certificate, and then upload a new one.

OpenVPN® Certificate

Click on “Upload” to upload OpenVPN® certificate. For a new upload, users could click on “Delete” to erase the last certificate, and then upload a new one.

OpenVPN® Client Key

Click on “Upload” to upload OpenVPN® Key.
For a new upload, users could click on “Delete” to erase the last certificate, and then upload a new one.

OpenVPN® Client Key Password

Allows user to set password for client.key file

OpenVPN® TLS Key

Uploads the OpenVPN® TLS .key file

OpenVPN® TLS Key Type

Selects the encryption type of the OpenVPN® TLS key. it can be set to : TLS-Auth, TLS-Crypt, TLS-Crypt V2

OpenVPN® Cipher Method

Specifies the Cipher method used by the OpenVPN® server. The available options are:

  • Blowfish

  • AES-128

  • AES-256

  • Triple-DES

The default setting is “Blowfish”.

OpenVPN® Username

Configures the optional username for authentication if the OpenVPN server supports it.

OpenVPN® Password

Configures the optional password for authentication if the OpenVPN server supports it.

OpenVPN® Comp-lzo

Configures enable/disable the LZO compression. When the LZO Compression is enabled on the OpenVPN server, you must turn on it at the same time. Otherwise, the network will be abnormal. Default value is YES.

Additional Options

Additional options to be appended to the OpenVPN® config file, separated by semicolons. For example, comp-lzo no;auth SHA256

Note: Please use this option with caution. Make sure that the options are recognizable by OpenVPN® and do not unnecessarily override the other configurations above.

Advanced Settings

Advanced Network Settings

DNS Refresh Timer (m)

Configures the refresh time (in minutes) for DNS query. If set to “0”, the GSC356X will use the DNS query TTL from DNS server response.
the Default value is “0”

DNS Failure Cache Duration (m)

Configures the duration (in minutes) of the previous DNS cache when the DNS query fails. If set to “0”, the feature will be disabled. Note: Only valid for SIP registration.
The Default value is “0”

Enable LLDP

Enables/Disables the LLDP (Link Layer Discovery Protocol) service.

Enabled by default.

LLDP TX Interval

Configures LLDP TX Interval (in seconds). Valid range is 1 to 3600. Default is 60.

Enable CDP

Enables/Disables the Cisco Discovery Protocol feature.

Enabled by default.

Layer 3 QoS for SIP

Configures the Layer 3 QoS parameter for SIP. This value is used for IP Precedence, Diff-Serv or MPLS.


Valid range is 0 to 63, and default value is 26.

Layer 3 QoS for Audio

Configures the Layer 3 QoS parameter for audio. This value is used for IP Precedence, Diff-Serv or MPLS.


Valid range is 0 to 63, and default value is 46.

Layer 3 QoS For Video

Configures the Layer 3 QoS parameter for video packets. This value is used for IP Precedence, Diff-Serv or MPLS.


Valid range is 0 to 63, and default value is 34.

HTTP/HTTPS User-Agent

Configures the user-agent for HTTP/HTTPS request.

SIP User-Agent

This sets the user-agent for SIP. If the value includes word “$version”, will replace it with the real system version.

Proxy

HTTP Proxy

Specifies the HTTP proxy URL for the GSC356X to send packets to. The proxy server will act as an intermediary to route the packets to the destination.

HTTPS Proxy

Specifies the HTTPS proxy URL for the GSC356X to send packets to. The proxy server will act as an intermediary to route the packets to the destination.

Bypass Proxy for

Configures the destination IP address where no proxy server is needed. The GSC356X will not use a proxy server when sending packets to the specified destination IP address.

Remote Control

Action URI Support

Configures whether to enable GSC356X to handle Action URI request.

Default is “Enabled”.

Action URI Allowed IP List

List of allowed IP addresses from which the GSC356X receives the Action URI.


Maximum allowed length is 512, and default setting is “any”.

System Settings Page Definitions

Time Settings

NTP Server

Configures the URL or IP address of the NTP server. The GSC356X may obtain the date and time from the server.


The default server is “pool.ntp.org”.

Enable Authenticated NTP

Configures whether to enable NTP authentication. If enabled, a cryptographic signature appended to each network packet. If the key is incorrectly configured, the GSC356X  will refuse to use the time provided by the NTP server.


This setting is disabled by default.

Authenticated NTP Key ID

Configures the key ID for authenticated NTP.


The default value is “1”.

Authenticated NTP Key

Upload the key file for authenticated NTP.


Note: Only supports MD5 key type.

Allow DHCP Option 42 to Override NTP Server

Obtains NTP server address from a DHCP server using DHCP Option 42; it will override configured NTP Server. If set to “No”, the GSC356X will use configured NTP server to synchronize time and date even if an NTP server is provided by DHCP server.


The default setting is “Yes”.

DHCP Option 2 to Override Time Zone Setting

Obtains time zone setting (offset) from a DHCP server using DHCP Option 2; it will override the selected time zone.

If set to “No”, the GSC356X will use the selected time zone even if provided by the DHCP server. The default setting is Yes.

Time Zone

Configures the date/time display according to the specified time zone.


The default setting is “Auto”.

Self-defined Time Zone

When the Time Zone option is set to “Self-Defined”, this parameter allows users to specify their own custom time zone using the following syntax:


std offset dst [offset], start [/time], end [/time]

  • std: Abbreviation for standard time (e.g., MTZ).

  • offset: The difference (in hours) from UTC for standard time.

  • dst: Abbreviation for daylight saving time (e.g., MDT).

  • [offset]: The difference (in hours) from UTC for daylight saving time (usually 1 hour ahead of standard time).

  • start [/time]: The rule that defines when daylight saving time begins.

  • end [/time]: The rule that defines when daylight saving time ends.


The default self-defined time zone is “MTZ+6MDT+5,M4.1.0,M11.1.0”.


Note:

  • A positive (+) offset value means the local time zone is west of the Prime Meridian (Greenwich Meridian).

  • A negative (–) offset value means the local time zone is east of the Prime Meridian.

Date Display Format

Determines which format will be used to display the date.

It can be selected from the drop-down list.


  • YYYY-MM-DD: 2012-01-31

  • MM-DD-YYYY: 01-31-2012

  • DD-MM-YYYY: 31-01-2012

  • ddd, mmm DD: Tue, Jan 31

The default setting is “YYYY-MM-DD”.

Time Display Format

Specifies which format will be used to display the time. It can be selected from a 12-hour or 24-hour format.


The default setting is 24 Hour format.

Timetable

Timetable

Users can configure up to 50 timetables with different schedules and assign specific holidays to each one.
Edit a schedule under Operation, then select Custom Time to define the days of the week and the time periods during which the schedule is active.

Holidays

Users can manually define up to 10 custom holidays by specifying date intervals.
These holidays can later be assigned to specific schedules for customized access control.

Security Settings

Security Settings→Web/SSH Access

Enable SSH

Enables SSH access to the GSC356X. Default setting is “Yes”.

SSH Port

Customizes SSH port. Valid range: 1 – 65535.

Default port is 22.

HTTP Web Port

Configures the HTTP port under the HTTP web access mode. Valid range: 80-65500

Default port is 80.

HTTPS Web Port

Configures the HTTPS port under the HTTP web access mode.Valid range: 80-65500

Default port is 443.

Web Access Mode

Determines which protocol will be used to access the GSC356X’ s Web GUI. It can be selected from HTTP and HTTPS or Both.


The default setting is HTTPS.

User Login Timeout

Set login timeout (in minutes) for user. If there is no activity within the specified amount of time, the user will be logged out, and the system will jump to the login page automatically. Default is 15 minutes.

Enable User Web Access

Toggle to enable or disable user web UI access.

Default Settings is “Disabled”.

Validate Server Certificates

Verify the server certificate using the trusted certificates for TLS. If disabled, the device will bypass certificate verification.

Enabled by default.

Security Settings→User Info Management

Current Password

Enter the current password.

User

User Account

Displays the name of the user account.

New Password

Allows the administrator to set the password for user-level web GUI access. This field is case sensitive with a maximum length of 512 characters. The default password is “123”.

Confirm Password

Enter the new User password again to confirm.

Administrator

Admin Account

Displays the name of the admin account.

New Password

Allows the user to change the admin password. The password field is purposely blank after clicking the “Save” button for security purpose. This field is case sensitive with a maximum length of 512 characters.

Confirm Password

Enter the new Admin password again to confirm.

Security Settings→Client Certificate

Minimum TLS Version

Configures the minimum TLS version supported by the GSC356X.


The default setting is “TLS 1.2”.

Maximum TLS Version

Configures the maximum TLS version supported by the GSC356X.


The default setting is “Unlimited”.

Enable Weak TLS Cipher Suite

This setting controls how the GSC356X handles weak TLS cipher suites for encryption. The options are:

  • Enable Weak TLS Cipher Suites: Allows the device to use weak TLS cipher suites for encrypting data.

  • Disable Symmetric Encryption RC4/DES/3DES: Disables weak symmetric ciphers RC4, DES, and 3DES.

  • Disable Symmetric Encryption SEED: Disables the SEED symmetric cipher.

  • Disable All Weak Symmetric Encryption: Disables all weak symmetric ciphers.

  • Disable Symmetric Authentication MD5: Disables the weak MD5 authentication method.

  • Disable All Weak TLS Cipher Suites: Disables all weak TLS cipher suites (default setting).

SIP TLS Certificate

Defines the SSL certificate used for SIP over TLS.

SIP TLS Private Key

Defines the SSL Private key used for SIP over TLS.

SIP TLS Private Key Password

Defines the SSL Private key password used for SIP over TLS.

Custom Certificate

Allows to upload a Custom Certificate file to GSC356X.

Security Settings→Trusted CA Certificates

Index ID

A unique identifier for each CA (Certificate Authority) certificate entry in the list.

Issued By

Displays the name of the Certificate Authority that issued the trusted certificate.

Expiration

Shows the expiration date of the CA certificate, indicating until when it is valid for secure communications.

Light Settings

Call Button Light Brightness

Set the brightness level of the LED light surrounding the doorbell button on the device. This feature allows users to adjust visibility according to ambient lighting conditions. The available options are:

  • Dark: Lowest brightness, suitable for low-power environments.

  • Moderate: Balanced brightness for typical indoor or shaded outdoor conditions.

  • Bright: Enhanced visibility for most outdoor settings.

  • High Bright: Maximum brightness for very bright or low-visibility environments.

The default setting is “Moderate”.

LED Fill Light Mode

Controls the fill light near the camera:

  • Disabled: Turns off the fill light.

  • Auto: Automatically turns on the fill light based on lighting conditions.

  • Manual: The fill light will remain on continuously for a configured duration.

Default setting is “Auto”.

LED Fill Light Duration

Defines the time range during which the LED fill light remains continuously active when LED Fill Light Mode is set to “Manual”. Users can configure up to 3 non-conflicting time periods.

TR-069

Enable TR-069

Sets the GSC356X system to enable the “CPE WAN Management Protocol” (TR-069).


Enabled by default.

ACS URL

Specifies URL of TR-069 ACS (e.g., http://acs.mycompany.com), or IP address.

Default URL is “https://acs.gdms.cloud”.

TR-069 Username

Enters username to authenticate to ACS.

TR-069 Password

Enters password to authenticate to ACS.

Periodic Inform Enable

Sends periodic inform packets to ACS.


This setting is enabled by default.

Periodic Inform Interval

Configures how often the GSC356X sends “Inform” packets to the ACS. The interval determines the frequency of these periodic status updates.


The valid range is 1 to 4294967295, and the default value is 86400 seconds.

Connection Request Username

Enters username for the ACS to connect to the GSC356X.

Connection Request Password

Enters password for the ACS to connect to the GSC356X.

Connection Request Port

Enters the port for the ACS to connect to the GSC356X. Valid range: 1-65535


Default port is 7547.

CPE SSL Certificate

Uploads Cert File for the GSC356X to connect to the ACS via SSL.

CPE SSL Private Key

Uploads Cert Key for the GSC356X to connect to the ACS via SSL.

Start TR-069 at Random Time

If enabled, TR-069 will send out the first INFORM message to the server on randomized timing between 1 to 3600 seconds after the GSC356X boots up.


Disabled by default.

Backup/Restore

This page allows users to back up or restore the device configuration.

  • Backup:
    Click this button to download and save the current configuration settings of the GSC356X. The file will be saved in .uf format, which can later be used to restore the same settings.
  • Restore:
    Click this button to upload a previously saved .uf configuration file and apply it to the device. This will overwrite the current settings.
GSC356X BackupRestore Page

Email Settings

SMTP Server

The address of the outgoing mail server used to send email notifications (e.g., smtp.gmail.com).

SMTP Server Port

The port number used by the SMTP server (commonly 465 for SSL, 587 for TLS).

From Email Address

The email address shown as the sender in outgoing email notifications.

Sender Email Username

The username used to authenticate with the SMTP server.

Sender Email Password

The password or app-specific password used for SMTP authentication.

SSL

Enables/Disables SSL/TLS encryption for secure email transmission. (Enabled by default)

Test Email

A button to send a test email using the configured settings to verify that email notifications are working.

Email Notification Address

Recipient Address 1

The email addresses of the recipient 1 that will receive notifications (e.g., snapshots, alarms).

Recipient Address 2

The email addresses of the recipient 2 that will receive notifications (e.g., snapshots, alarms).

Email Notification Address

Email Subject

Allows configuration of the subject line used in alarm notification emails. This field supports dynamic variables that will be automatically replaced with actual values when the email is generated:

  • ${MAC}: Device MAC address

  • ${WARNING_MSG}: Event message details

  • ${IP_ADDR}: Device IP address

  • ${DATE}: Date and time of the event

  • ${USERNAME}: Username associated with the event

  • ${MODEL}: Device model information

  • ${OSD}: On-Screen Display text

The default email subject is “${MODEL}_${MAC}_${WARNING_MSG}_${OSD}”

Email Content

Allows configuration of the body text used in alarm notification emails. This field supports dynamic variables that will be automatically replaced with actual values when the email is generated:

  • ${MAC}: Device MAC address

  • ${WARNING_MSG}: Event message details

  • ${IP_ADDR}: Device IP address

  • ${DATE}: Date and time of the event

  • ${USERNAME}: Username associated with the event

  • ${MODEL}: Device model information

  • ${OSD}: On-Screen Display text

The default email content template is:

“Detected: ${WARNING_MSG}

Model: ${MODEL}

MAC Address: ${MAC}

Alarm Time: ${DATE}”

FTP Settings

FTP Server

The domain name or IP address of the FTP server used to store snapshots or recorded data.

FTP Server Port

The communication port used to connect to the FTP server (default is port 21).

FTP Server Username

The username required to authenticate and access the FTP server.

FTP Server Password

The password associated with the FTP server username for login authentication.

Storage Path

The directory or folder path on the FTP server where the files will be stored (e.g., /snapshots).

Test FTP Server

A button to verify the FTP connection and ensure that the credentials and path are correct.

Maintenance Page Definitions

Upgrade and Provisioning

Upgrade and Provisioning→Firmware

Current Version

Displays the current firmware version of the GSC356X.

Upgrade via Manual Upload

Upload Firmware File to Update

Allows users to load the local firmware to the GSC356X to update the firmware.

Upgrade via Network

Firmware Upgrade Mode

Allows users to choose one of the following the firmware upgrade methods: TFTP, HTTP, HTTPS, FTP, or FTPS.


The default setting is “HTTPS”.

Firmware Server Path

Set the IP address or domain name of the firmware server. The URL of the server that hosts the firmware release. This field is empty by default.


Administrators can also configure variables in the URL. The following variables are supported:

• $PN: is replaced with the GSC356X model.

• $MAC: is replaced with the MAC address of the GSC356X.

Firmware Server Username

Enters the username for the firmware server.

Firmware Server Password

Enters the password for the firmware server.

Firmware File Prefix

Checks if the firmware file is with matching prefix before downloading it.
This field enables users to store different versions of firmware files in one directory on the firmware server.

Firmware File Postfix

Checks if the firmware file is with matching postfix before downloading it. This field enables users to store different versions of firmware files in one directory on the firmware server.

Upgrade Detection

Upgrade

Click the “Start” button to check whether the firmware in the firmware server has an updated version, if so, update immediately.

Upgrade and Provisioning→Config File

Configure Manually

Download Device Configuration

Click to download the device configuration file in .txt format.

Upload Device Configuration

Upload the configuration file to the GSC356X.

Configure via Network

Config Upgrade Via

Selects the provisioning method: TFTP, HTTP or HTTPS, FTP, FTPS. The default setting is “HTTPS”.

Config Server Path

Sets IP address or domain name of the configuration server. The server hosts a copy of the configuration file to be installed on the GD372x. This field is empty by default.


Administrators can also configure variables in the URL. The following variables are supported:

• $PN: is replaced with the GSC356X model.

• $MAC: is replaced with the MAC address of the GSC356X.

Config Server Username

Configures the username for the config server.

Config Server Password

Configures the password for the config server.

Config File Prefix

Checks if configuration files are with matching prefix before downloading them.
This field enables users to store different configuration files in one directory on the provisioning server.

Config File Postfix

Checks if configuration files are with matching postfix before downloading them. This field enables user to store different configuration files in one directory on the provisioning server.

Authenticate Conf File

Sets the GD372x system to authenticate configuration file before applying it. When set to “Yes”, the configuration file must include value P1 with GD372x system’s administration password. If it is missed or does not match the password, the GD372x system will not apply it. The default setting is “No”.

XML Config File Password

Decrypts XML configuration file when encrypted. The password used for encrypting the XML configuration file is using OpenSSL.

Upgrade and Provisioning→Provision

Auto Upgrade

Automatic Upgrade

Specifies when the firmware upgrade process will be initiated; there are 4 options:

  • No: The GD372x will only do upgrade once at boot up.

  • Yes, check for upgrade periodically: User needs to set an automatic check interval in minutes.

  • Yes, check for upgrade every day: User needs to specify “Hour of the day (0-23)”.

  • Yes, check for upgrade every week: User needs to specify “Hour of the day (0-23)” and “Day of the week (0-6)”.

Notes:

  • Day of week setting starts from Sunday.

  • The default setting is “No”.

Start Upgrade at Random Time

Configures whether the GD372x will upgrade automatically at random time point within the configured period.

Automatic Upgrade Check Interval (m)

Configures how often the GSC356X checks for firmware upgrade (in minutes).


This setting is only valid if the user selects “Yes, check for upgrade periodically” in the “Automatic Upgrade”.


The valid range is 60-86400, and the default setting is 10080 (namely 7 days).

Hour of the Day (0-23)

Defines at which hour of the day the GD372x system will check the HTTP/HTTPS/TFTP/FTP/FTPS server for firmware upgrades or configuration files changes.

Day of the Week (0-6)

Defines which day of the week the GD372x system will check the HTTP/HTTPS/TFTP/FTP/FTPS server for firmware upgrades or configuration files changes.

Firmware Upgrade and Provisioning

Defines the GD372x system’s rules for automatic upgrade. It can be selected from:

  • Always check for new firmware.

  • Check new firmware only when F/W pre/suffix changes.

  • Always skip the firmware Check.

The default setting is “Always check for new firmware”.

DHCP Option

Allow DHCP Option 43 and Option 66 to Override Server

If DHCP option 43, and 66 is enabled on the LAN side, the device will reset the CPE, upgrade, network VLAN tag, and priority configuration according to option 43 sent by the server.

At the same time, the update mode and server path of the configuration upgrade mode will be reset according to the option 66 sent by the server. Default is “Yes”.

DHCP Option 120 Override SIP Server

Configures the GD372x system to allow the DHCP offer message to override the SIP Server Path via the Option 120 header.


The default setting is “No”.

Additional Override DHCP Option

Configures additional DHCP Options (150 or 160) to be used for firmware server instead of the configured firmware server or the server from DHCP Option 43 and 66.

This option will be effective only when “Allow DHCP Option 43 and Option 66 to Override Server” is enabled.

The default setting is “Option 150”.

Allow DHCP Option 242 (Avaya IP Phones)

Enables DHCP Option 242. Once enabled, the GD372x will use the configuration info issued by the local DHCP in Option 242 to configure the proxy, transport protocol, and server path.

The default setting is “No”.

Config Provision

Config Provision

Device will download the configuration files and provision by the configured order.

Download and Process All Available Config Files

By default, the device will provision the first available config in the order of cfgMAC.xml, cfgMODEL.xml, and cfg.xml (corresponding to device specific, model specific, and global configs).

If set to “Yes”, the device will download and apply (override) all available configs in the order of cfg.xml, cfgMODEL.xml, cfgMAC.xml.


The default setting is “No”.

3CX Auto Provision

If enabled, the GD372x will send SUBSCRIBE requests to the multicast address in LAN during bootup for automatic provisioning. This feature requires 3CX server support.

Upgrade and Provisioning→Advanced Settings

Send HTTP Basic Authentication By Default 

Specifies whether the device should always include HTTP/HTTPS authentication credentials when using wget to download firmware or configuration files.

  • Yes: Always send the username and password, regardless of whether the server requests authentication.

  • No: Only send the username and password when the server requires authentication.

The default setting is “No”.

Enable SIP NOTIFY Authentication

Enables the GSC356X to challenge SIP NOTIFY with 401. The default setting is “Yes”.

Validate Certification Chain

Configures whether to validate the server certificate when download the firmware/config file. If it is set to “Yes”, the GD372x will download the firmware/config file only from the legitimate server. Default setting is “No”.

Allow AutoConfig Service Access

Configures whether to allow access to the AutoConfig service. If not checked, access to service.ipvideotalk.com will be disabled. Default value is “Enabled”.

Factory Reset 

Resets the GSC356X system to the default factory setting mode.

System Diagnostics

System Diagnostics→Syslog

Syslog Protocol

Select the transport protocol over which log messages will be carried. The options are:

  • UDP: Syslog messages will be sent over UDP.

  • SSL/TLS: Syslog messages will be sent securely over TLS connection.

The default setting is “UDP”.

Syslog Server

Configures the URI which the GSC356X system will send the syslog messages to.

Syslog Level

Selects the level of logging for syslog. The default setting is “None”. There are 4 levels from the dropdown list: DEBUG, INFO, WARNING and ERROR. The following information will be included in the syslog packet:

  • DEBUG (Sent or received SIP messages).

  • INFO (Product model/version on boot up, NAT related info, SIP message summary, Inbound and outbound calls, Registration status change, negotiated codec, Ethernet link up).

  • WARNING (SLIC chip exception).

  • ERROR (SLIC chip exception, Memory exception).

Note: Changing syslog level does not require a reboot to take effect.

Syslog Keyword Filter

Only send the syslog with keyword, multiple keywords are separated by comma.

Example: set the filter keyword to “SIP” to filter SIP log.

Syslog Header Format

Configures the preferred header format for Syslog. The options are:

  • Legacy (Default setting)

  • RFC3164 Compliant

The RFC3164 compliant header begins with “PRI” which represent both the Facility (0 – 23) and severity level (0 – 7) of the event. The message includes the timestamp, hostname, process id and the log message.

For more information regarding the representation of the numerical values for the facility and severity, please refer to RFC3164.

Send SIP Log

Configures whether the SIP log will be included in the syslog messages. The default setting is “No”.

System Diagnostics→Packet Capture

With RTP Packets

Includes Real-time Transport Protocol (RTP) packets used for audio/video streams in the packet capture file.

With Secret Key Information

If enabled, includes encrypted key information in the capture (useful for debugging but should be used with caution due to security concerns).

Start

Begins the packet capture process.

Stop

Stops the ongoing packet capture.

Download

Downloads the captured packet file in a .tar archive. After extraction, the capture file will be available in .pcapng format for offline analysis.

Delete

Deletes the saved packet capture file from the device.

System Diagnostics→Ping

Input

Enter a domain name or IP address to test network connectivity (e.g., 8.8.8.8 or example.com).

Start

Initiates the ping test to check if the device can reach the specified address and measure the packet loss.

System Diagnostics→Traceroute

Input

Enter a domain name or IP address to trace the network path (e.g., 8.8.8.8 or example.com).

Start

Begins the traceroute process to identify the route and intermediate hops taken to reach the destination from the device.

System Diagnostics→Remote Diagnostics

Start

Enables remote diagnostics, allowing remote access the device and collection of diagnostic logs. Access will automatically expire after a set period for security purposes.

System Diagnostics→Audio Diagnosis

Audio Diagnostic Server

Specifies the server address used for audio diagnosis, typically provided by the system administrator or support team.

Audio Diagnosis

Enables or disables the audio diagnostic feature. When enabled, the device connects to the specified server for troubleshooting purposes.

Event Notification

Device Status

Bootup Completed

Configures the event URL when GSC356X boots up.

Registered

Configures the event URL when an account in the GSC356X is registered successfully.

Unregistered

Configures the event URL when an account in the GSC356X is unregistered.

Log On

Configures the event URL when users log on the GSC356X successfully.

Log Off

Configures the event URL when users log off the GSC356X.

Access control operation

Relay Trigger

Configures the Action URL to send when the relay is triggered.

Relay Off

Configures the Action URL to send when the relay is turned off.

Input Trigger

Configures the Action URL to send when digital input is triggered.

Input Off

Configures the Action URL to send when digital input is turned off.

Call Operation

Incoming Call

Configures the event URL when GSC356X has an incoming call.

Outgoing Call

Configures the event URL when GSC356X has an outgoing call.

Missed Call

Configures the event URL when the GSC356X has new a missed call.

Established Call

Configures the event URL when a call is established.

Terminated Call

Configures the event URL when a call is disconnected.

Application Page Definitions

Account Sharing

Account Sharing→Account Sharing

General Settings

Enable Account Sharing

Select whether to enable Account Sharing. This feature is disabled by default.

Role in Account Sharing 

Specifies the role of the device in an account sharing setup.

  • Host Device: Registers an account on the IP PBX and allows guest devices to make calls through its account.

  • Guest Device: Does not register an account on the IP PBX and relies on the host device to place and receive calls within the network.

The default option is “Guest Device”.

SIP Server Port

Specifies the SIP service port used for account sharing. A value of 0 means a random port will be assigned. Valid range is 0–65535. Default port is 15060.

Group Name

Set the group name, in the host-guest mode, devices with the same group name can discover each other.


Note:
This item is mandatory if using Account Sharing. The verification format is domain type

Group Password

In the host-guest mode, after setting the group password, the guest device with the same group password as the host device can successfully register an account on the host device.


Note:
This item is mandatory if using Account Sharing.

Account Settings

Associated account

Specifies the account behavior in Account Sharing:

  • Host Device Role: Specifies which host account will be used as the outgoing and incoming account for calls outside of the Account Sharing network.

  • Guest Device Role: Specifies which host account the guest device will register to for making and receiving calls.

Host Device Number

Sets the number for the host device. This setting will be synchronized with the SIP Authentication ID and SIP User ID, and any modifications will be made simultaneously.  he SIP authentication ID and SIP user ID are kept synchronized, and any modifications will be made simultaneously.

Guest Account Name

This setting specifies the account name corresponding to the account used by the guest device.

Ringing tone Settings

Sync Ringing In Group

Specifies whether the ringtones of all successfully registered guest devices in the group will play in synchronization when a call is received. The default setting is “No”.

Ringtone

Select an existing ringtone or upload a custom audio file. (Supported formats include MP3, WAV, OGG, WMA, MID, and M4A)

Account Sharing→Account Sharing List

Discover Device list

Refresh

Click to refresh the list of discovered devices.

Diagnostic Page Definitions

Microphone Test

Tests the microphone’s functionality by capturing and playing back audio input.

Speaker Test

Tests the speaker by playing a sample sound to confirm output functionality.

Reset Key Test

Checks if the hardware reset button is responsive and functioning correctly.

Light Test

Activates the LED lights to verify their operation (e.g., indicator or fill light).

Certificate Test

Verifies the integrity and validity of installed security certificates.

SD Card Test

Checks if an inserted SD card is recognized and functioning properly.

Relay Out Test

Tests the relay output by triggering it manually to ensure proper response (e.g., unlocking a door).

Alarm Input Test

Verifies the functionality of alarm input interfaces by detecting signal changes.

Key Test

Tests the physical keypad buttons to ensure each key press is detected.

Tamper Test

Simulates or detects a tamper event to confirm the tamper switch is operational.

Line Out Test

Connect an external active speaker to the Line Out port and click Test to verify audio output.
If sound is heard, the function is working correctly; otherwise, check volume and connections.

GSC356X HTTP API

Grandstream Door Systems supports HTTP API (Application Programming Interface).

For more details, please refer to the following guide:

https://documentation.grandstream.com/knowledge-base/gds37xx-http-api/

The document explains in detail the external HTTP-based application programming interface and parameters of functions via the supported method. The HTTP API is firmware-dependent. Please refer to the related firmware Release Note for the supported functions.

Administrator Privilege is required, and administrator authentication verification has to be executed before any operation on the related parameter configuration.

FACTORY RESET

Restore to Factory Default via Web GUI

To perform a factory reset to the GSC356X via the Web GUI, please refer to the following steps:

  1. Access to GSC356X Web GUI using admin username and password.
  2. Navigate to Maintenance 🡪Advanced Settings.
  3. Press the Factory Reset button as displayed in the following screenshot.
GSC356X Web UI Factory Reset

Factory Reset via the Reset Button

To perform a hard factory reset on the GSC356X device:

  1. Power on the device.
  2. Press and hold the RESET button (located on the right rear side of the device) for about 10 seconds until the LED indicators flash.
Rear view of a device with a highlighted reset button on the right and a magnified inset of the switch?
Factory Reset via the Reset Button
  1. Release the button. The device will reboot and restore to factory default settings.
Important Notes

  • Power must NOT be lost while performing a hard factory reset.
  • This process erases all settings and configurations. Ensure you back up any important data before proceeding.

CHANGE LOG

This section documents significant changes from previous versions of the user manual for GSC356X. Only major new features or major document updates are listed here. Minor updates for corrections or editing are not documented here.

Firmware Version 1.0.1.8

  • This is the initial version for GSC356X.

Was this article helpful?

Related Articles

Need Support?
Can’t find the answer you’re looking for? Don’t worry we’re here to help!
Contact Support