The Grandstream GXW42xx series is a high-density analog FXS VoIP gateway family designed to connect legacy analog phones and fax machines to modern SIP-based VoIP networks. This document provides a concise collection of the most common operational, configuration, and troubleshooting questions for both V1 and V2 models. It serves as a quick, practical reference for installers, administrators, and support teams deploying GXW42xx devices.
Product Overview & Models
The GXW42xx series is a line of high-density analog FXS VoIP gateways designed to connect traditional analog telephones or PBX extensions to modern SIP-based VoIP networks. They provide seamless migration from legacy voice systems to IP telephony, offering auto-provisioning, remote management, strong security, and high audio quality. Their purpose is to integrate existing analog infrastructures into IP networks while reducing communication costs.
There are four models, each defined by its port capacity:
- GXW4216 – 16 FXS ports
- GXW4224 – 24 FXS ports
- GXW4232 – 32 FXS ports
- GXW4248 – 48 FXS ports (through RJ21 connectors)
All models have the same core functionality (SIP profiles, codecs, provisioning, etc.), but differ in the number of RJ11/RJ21 interfaces and power requirements. This allows businesses to choose the model size that matches their analog line needs.
The difference between V1 and V2 is important for firmware, security, and support:
How to identify V2:
- The product label explicitly shows “V2” in the model name (e.g., “GXW4216 V2”).
- V2 models include a unique device password printed on the label, while V1 models ship without a preprinted admin password.
Firmware handling:
- V2 uses a different firmware file than V1.
- Once a V2 gateway is upgraded to 1.0.7.2, it cannot be downgraded to 1.0.5.4 or earlier, due to new-generation individual certificates.
These distinctions ensure the right firmware is used and prevent compatibility issues.
Each FXS port can handle one call, so concurrency matches the port count:
- GXW4216 → 16 simultaneous calls
- GXW4224 → 24 simultaneous calls
- GXW4232 → 32 simultaneous calls
- GXW4248 → 48 simultaneous calls
Exception: When using SRTP encryption, the number of usable concurrent calls may be reduced due to processing overhead. This helps maintain voice quality and security.
The GXW42xx series supports a wide set of voice codecs to ensure compatibility with VoIP platforms and various bandwidth conditions:
- G.711 μ/a-law (high quality, standard PCM)
- G.723.1A (low bandwidth)
- G.726 (16/24/32/40 kbps ADPCM)
- G.729 A/B (compressed codec, very bandwidth efficient)
- iLBC (robust codec for packet-loss scenarios)
- G.722 (wideband HD audio)
It also includes:
- G.168 Echo Cancellation,
- VAD/CNG/PLC to reduce bandwidth use and improve call reliability.
These ensure stable voice transmission even over imperfect networks.
All GXW42xx devices include:
- Dual 10/100/1000 Mbps Ethernet ports
These can be used for both the service and management interfaces. High-speed gigabit ports guarantee that the gateway remains stable even under full load, especially on high-density models like the GXW4248.
Yes. The gateway includes a 128×32 pixel two-line LCD that provides:
- IP address
- Network mode
- System information
- Menu navigation using the front buttons
The LCD allows onsite administrators to quickly access basic information without using the web UI, which helps during deployment and troubleshooting.
Supported codecs include G.711 (PCMA/PCMU) with PLC/VAD/CNG, G.723.1, G.729A/B, G.726, iLBC, and OPUS. The device also includes advanced media-handling features, such as a dynamic jitter buffer and line echo cancellation, for clearer call quality.
The GXW4248 exclusively uses two RJ21 (50-pin) connectors to deliver all 48 FXS ports.
Unlike the smaller models, it does not offer individual RJ11 jacks. This design is ideal for PBXs or patch panels where wiring can be centralized using telco cables.
Each FXS port provides:
- 48V on-hook voltage
- 50Vrms ringing voltage
- 20–50 Hz ringing frequency
- Up to 2 REN load support
- Up to 2 km distance over 24-AWG wiring
These electrical characteristics ensure compatibility with nearly all analog telephones and fax machines while maintaining strong ringing performance over long cable runs.
Hardware, LEDs & Installation
Each GXW42xx package includes everything required for installation:
- GXW42xx gateway unit (V1 or V2 depending on your model)
- RJ45 Ethernet cable for network connection
- Power adapter
- 12V/5A for GXW4216, GXW4224, GXW4232
- 24V/6.25A for GXW4248
- Rack-mount brackets (2 pieces)
- RJ21 telco cables (only for the GXW4248 models)
- Quick Installation Guide
- Regulatory information sheet
This ensures the gateway can be deployed immediately in desktop or rack environments.
Phones and fax machines connect through the FXS interfaces:
- GXW4216 / 4224 / 4232:
These models include RJ11 FXS ports in addition to the main RJ21 connector. You can plug phones directly using standard RJ11 cords or use RJ21 → RJ11 breakout cables for bulk installations. - GXW4248:
Uses only two RJ21 (50-pin) connectors. You must connect analog phones using telco/Amphenol breakout cables.
Each pair of pins on the RJ21 corresponds to one FXS port (TIP/RING mapping).
Each FXS LED indicates the real-time status of its corresponding port:
- Solid green:
The port is busy (off-hook or in a call). - Off:
The port is idle and available. - Slow blinking:
Indicates voicemail waiting for that port. - All FXS LEDs slow blinking simultaneously:
The gateway is provisioning or upgrading firmware.
These indicators help technicians quickly identify port activity and device state.
The GXW42xx includes two Ethernet LEDs:
LINK LED
- Shows Ethernet link activity.
- Blink patterns indicate connection speed:
- 10 Mbps → LINK & ACT blink, ACT faster
- 100 Mbps → Both blink at same speed
- 1000 Mbps → LINK stays solid, ACT blinks only
ACT LED
- Stays ON when the Ethernet cable is plugged in.
- Blinks to show network activity.
These LEDs let installers verify network connectivity without logging into the system.
You can reset the device using:
Physical Button
Hold the Reset/Factory Reset button for several seconds until LEDs indicate the reset.
IVR Method
- Pick up the phone connected to any FXS port.
- Dial
***to enter the voice menu. - Dial
099. - Either:
- Press 9 to reboot, or
- Enter the device’s MAC address to restore full factory defaults.
This erases all configuration unless “Keep Security Settings After Reset” is enabled.
Yes. The GXW42xx includes:
- Over-voltage protection
- Surge immunity
This prevents damage from lightning or line surges on analog cabling, especially important when using long-distance wiring.
Power requirements vary by model:
- 4216 / 4224 / 4232 → 12V DC, 5A adapter
- 4248 → 24V DC, 6.25A adapter
All accept 100–240VAC input at 50/60Hz. Ensuring the correct adapter is crucial for device stability and safety.
No. Grandstream explicitly warns against using third-party adapters. Using an incorrect power supply can permanently damage the unit and void the warranty. Always use the included official adapter.
Each RJ21 connector contains 50 pins, with each FXS port assigned:
- RING → Odd-numbered pin
- TIP → Even-numbered pin
Example mapping:
- Port 1 → Pins 1 (RING1) & 26 (TIP1)
- Port 2 → Pins 2 & 27
- … and so on.
Depending on the model:
- 4216 uses the first 16 pairs
- 4224 uses first 24 pairs
- 4232 uses 32 pairs across two RJ21 connectors
- 4248 uses all 48 pairs across two RJ21 connectors
This is essential for structured cabling or PBX integration.
This state indicates that the device is either:
- Provisioning configuration, or
- Performing a firmware upgrade
During this process:
- Calls may not function normally
- Power should not be disconnected
- The gateway automatically reboots if required
This visual indication helps identify upgrade stages without logging in.
Yes.
The devices support:
- SNMP v1 / v2c / v3 with configurable trap servers
- SSH remote access with customizable privileges (e.g., limiting PValue modifications)
Admins can enable/disable these services, assign custom ports (SSH default: 22), and restrict SNMP access by IP. This makes the GXW appropriate for managed enterprise networks.
To access the web interface:
- Retrieve the IP address:
- Pick up FXS phone
- Dial
***→ then02(IP Address) - IVR reads a 12-digit IP (remove zeros: e.g., 192.168.001.014 → 192.168.1.14)
- Open a browser and enter:
http://<Gateway-IP> - Login using:
- admin / admin (V1 units)
- admin / [sticker password] (V2 units)
- user / 123 or viewer / viewer (if enabled)
Only the admin account can access full configuration menus.
Yes. The GXW42xx can support 4-wire analog phones, but only the TIP and RING pair is actually used by the hardware. This means that although the phone may have 4 wires available, the gateway only uses the standard two middle wires (pins 2 and 3 in RJ11) to provide the analog FXS signal. The extra two wires are simply ignored, so the phone will operate normally as long as the TIP/RING pair is correctly connected.
SIP, Calling & Voice Features
Direct IP Calling lets two VoIP devices communicate without a SIP server.
To dial an IP address:
- Pick up the phone
- Dial *47
- Enter the IP using * instead of dots
Example:
192.168.0.160 → 192*168*0*160
Optional port:
192.168.1.20:5062 → 192*168*1*20*5062
You may press # to send, or wait 4 seconds.
Note: “Use Random Port” must be set to NO in the SIP profile.
The GXW42xx series supports 4 independent SIP profiles, allowing the gateway to register different groups of FXS ports to different VoIP service providers or PBXs.
Each port can be assigned to any of the four profiles, providing flexibility in mixed-environment deployments (e.g., one provider for local calls, another for international routing).
Each FXS port can be configured with:
- Its own SIP User ID / Authentication ID, OR
- Belong to a Hunting Group sharing a single SIP account
If a port uses a SIP profile with a configured SIP account, it becomes an Active port.
Other ports can attach themselves to that account by setting their Hunting Group number to match the active port’s number.
This allows setups where many ports share the same extension or phone number.
To place an outbound call:
- Pick up the analog phone connected to an FXS port.
- Dial the destination number.
- Either:
- Wait 4 seconds for the dial timeout, OR
- Press # to send immediately (only if “Use # as Dial Key” is enabled).
The device follows the configured dial plan, so prefix behavior may depend on service provider settings.
Direct IP calls work only if:
- Both devices are on the same LAN, OR
- Both devices have public IP addresses, OR
- NAT routers are configured with port forwarding or a DMZ.
If these conditions aren’t met, the call will not reach the target. This feature is mainly used for local testing or peer-to-peer communication.
Yes.
- Call Hold: Press FLASH to put the current call on hold and FLASH again to resume.
- Call Waiting: If a second call comes in, you hear a “beep.” Press FLASH to switch between calls; the other call is placed on hold.
This works as long as call waiting is enabled through feature codes or configuration.
Yes. To perform a blind transfer:
- Press FLASH to get dial tone
- Dial *87
- Dial the destination number
- Press # or wait 4 seconds
You will hear a confirmation tone indicating the transfer has been initiated.
Blind transfer requires “Enable Call Features” to be set to Yes in the web UI.
Yes. For attended transfer:
- FLASH to get dial tone
- Dial the destination number
- When the destination answers, speak with them
- Hang up to complete the transfer
If the destination does not answer, FLASH again to return to the original call.
If the transfer fails and user A hangs up, the GXW rings them back so they can resume the call.
Yes, the GXW supports local 3-way conferencing, similar to traditional PBX systems.
Steps:
- During a call, FLASH to get a second dial tone
- Dial third party (C)
- When C answers, FLASH again to merge all three calls
- FLASH again during the conference will drop C
- If A hangs up, the conference ends unless “Transfer on Conference Hangup” is enabled
This allows conference calls without PBX features.
A Hunting Group allows several ports to share one SIP account. Incoming calls to the single number are distributed across the ports.
Hunting Groups are useful for:
- Shared office lines
- Connecting analog PBXs expecting multiple lines
- Call distribution across many analog phones
You configure one Active port with SIP credentials, and other ports join by selecting that port’s number.
Linear Hunting (Serial Hunting):
- Always starts with the lowest-numbered available port in the group.
- Moves upward sequentially each time a call is received.
Circular Hunting (Round-Robin):
- Distributes calls evenly across all group members.
- After dialing one port, the next incoming call starts from the next port, even if lower-number ports are free.
This prevents one phone from receiving all calls. Both modes are configurable per SIP Profile.
Yes. Hunting Groups do not require ports to be in numerical order.
Example: Ports 3, 5, and 7 can all belong to Hunting Group 1 if Port 1 is the Active account.
This is useful when wiring or numbering doesn’t allow sequential grouping.
Yes. This allows calls between phones connected to the same gateway without a SIP server.
Dial:*** → then 7XX
- 701 = Port 1
- 724 = Port 24
- 732 = Port 32, etc.
This is invaluable for testing wiring or verifying a gateway during installation.
Yes. It supports multiple Caller ID formats to ensure regional compatibility:
- Bellcore Type I & II
- ETSI
- BT (UK)
- NTT (Japan)
- FSK and DTMF-based CID
The gateway sends Caller ID based on the settings in the FXS Port configuration and SIP profile.
The GXW supports all major DTMF signaling methods:
- In-Audio (tones carried inside the RTP audio stream)
- RFC2833 / RTP Event (most common in VoIP)
- SIP INFO (DTMF encoded as SIP messages)
You can set priority order (1–3) per SIP profile to match the SIP server requirements.
The GXW includes multiple DSP algorithms:
- VAD (Voice Activity Detection) — reduces bandwidth by sending packets only when speech is detected
- CNG (Comfort Noise Generation) — generates background noise during silence to avoid “dead air”.
- PLC (Packet Loss Concealment) — masks audio loss when packets drop
- Dynamic Jitter Buffer — smooths inconsistent network latency
- G.168 Echo Cancellation — removes echo for clearer calls
These features ensure stable audio quality even under poor network conditions.
Yes. The GXW supports the following:
- Unconditional Forward → *72
- Cancel Unconditional → *73
- Busy Forward → *90
- Cancel Busy → *91
- Delayed Forward → *92
- Cancel Delayed → *93
A dial tone confirms activation, and all forwarding works per-port.
Yes.
- Enable DND: *78
- Disable DND: *79
When DND is active, all incoming calls are rejected automatically before reaching the analog phone. This is a per-FXS port feature.
Faxing, IVR & Configuration
Yes. The GXW42xx supports fax using two methods:
1. T.38 Fax Relay (Recommended)
- This is the preferred and most reliable method.
- Supports Group 3 fax up to 14.4 kbps.
- Automatically switches to T.38 when fax tones are detected (if the provider supports it).
2. Fax Pass-Through (G.711)
- Used when the SIP server or provider does not support T.38.
- Encodes fax tones as normal audio using G.711 µ-law or a-law.
- Works best on stable, low-loss networks.
The device supports fax datapump standards V.17, V.21, V.27ter, V.29, which improves compatibility with most fax machines.
If faxes are failing or appearing corrupted:
- Try switching between T.38 and Pass-Through to align with your provider’s support.
- Adjust the Fax Tone Detection Mode setting in the SIP profile.
- Ensure jitter buffer settings and packet loss concealment are not overly aggressive for fax traffic.
Fax reliability strongly depends on the VoIP provider’s T.38 implementation and network stability.
The GXW42xx includes a built-in Voice Prompt/IVR system for quick configuration.
To enter IVR mode:
- Pick up an analog phone connected to any FXS port.
- Dial
***(three stars). - You will hear “Enter a menu option.”
From here, you can navigate through configuration options without needing Web UI access.
This is essential during initial setup or network troubleshooting.
The IVR offers specific menu codes for network configuration:
- 001 → Toggle DHCP, Static IP, or PPPoE
- 002 → Set static IP address
- 003 → Subnet Mask
- 004 → Gateway
- 005 → DNS Server
IP entries must be entered as 12 digits, with no dots and padded zeros.
Example: 192.168.5.7 → 192168005007
This is useful when the device is not yet reachable via web interface.
To hear the current firmware version:
- Dial
*** - Enter 016
The device will announce the firmware version installed on the gateway.
This is helpful when verifying upgrades or troubleshooting mismatches between V1 and V2 units.
In the IVR menu, option 017 allows choosing how the device handles upgrades:
- Always Check
The device checks the firmware server on every boot. - Check When Pre/Suffix Changes
It checks only if the configured firmware filename prefix or postfix has changed. - Never Upgrade
The unit will not check the server automatically.
This is useful when controlling upgrade behavior in large deployments.
The GXW IVR follows a simple navigation logic:
- * → Next menu option
- # → Return to main menu
- 9 → Confirm selection
- 12 digits → Required for any IP address entry
- Incorrect entries trigger an “Invalid Entry” and return to the menu
Understanding these rules helps avoid common configuration mistakes.
Yes. IVR option 012 controls WAN-side web access.
- Press 9 to toggle Enable/Disable.
- Default: Enabled
Disabling this can increase security by restricting remote access to the Web UI from external networks.
Yes. The GXW42xx has full flexible provisioning support via:
- TFTP
- HTTP
- HTTPS
Administrators can configure:
- Firmware server path
- Configuration server path
- Upgrade method and schedule
- Prefix/postfix filtering
- Authentication credentials (HTTP/HTTPS)
This enables automated updates across large deployments or cloud management platforms.
If “Allow DHCP Option 66/43 to Override Server” is set to Yes:
- The gateway will download its configuration from the server provided by DHCP, overriding the manually configured server path.
This is beneficial in tightly controlled enterprise networks where DHCP is used for centralized provisioning, but administrators should be aware that misconfigured DHCP can redirect devices to the wrong addresses.
Yes. You can enable certificate validation for secure provisioning.
The gateway supports:
- Validating hostname in server certificate
- Uploading custom CA certificates
- Selecting whether to trust built-in, custom, or all CAs
- Setting minimum TLS version (default TLS 1.2)
This ensures encrypted and authenticated communication with provisioning servers.
Yes. The GXW offers optional strict password enforcement, including:
- Minimum password length
- Required character classes (upper/lowercase, numbers)
- Rules required by GXW42xx V2 (8–30 characters, mixed-case + number mandatory)
These rules enhance device security, especially when exposed to remote management.
Networking & Security
Yes. The GXW42xx includes full 802.1Q VLAN tagging and 802.1p QoS priority for both the Service Interface and the Management Interface.
You can configure:
- VLAN IDs for Service and Management interfaces (default 0 and 10, respectively).
- 802.1p priority values for:
- SIP signaling
- RTP media
- Management packets
This allows the gateway to integrate into enterprise networks where voice traffic is isolated or prioritized.
Yes. The GXW includes robust NAT traversal options, essential when placed behind firewalls.
Supported STUN features:
- STUN server (IP or FQDN)
- NAT type detection (based on STUN algorithm)
- Keep-alive UDP packets (default 20 seconds)
- Allowed STUN response failures before re-acquiring IP (“Number of Misses Allowed”)
When NAT Traversal is enabled in the SIP Profile, the device will correctly discover and advertise its external IP/port, helping avoid issues like one-way audio or failed registrations.
The gateway includes several firewall and access-control features:
- WAN-side blocklist — Block specific IPs/subnets from accessing the device.
- WAN-side allowlist — Only listed IPs can access Web/SSH.
- ICMP reply control — Control whether the device responds to ping on the WAN.
- Syslog routing over Management interface (V2 only) — Ensures logs stay isolated on secured networks.
These functions help administrators secure remote access pathways and meet organizational security policies.
Yes. The GXW supports PPPoE authentication, commonly used for DSL or direct ISP connections.
You can configure:
- PPPoE Account ID
- PPPoE Password
- Service Name (optional)
When PPPoE mode is selected via IVR or Web UI, the device establishes its own WAN session and obtains its IP via the ISP.
Yes. Dynamic DNS (DDNS) is supported for situations where the WAN IP changes frequently.
Supported DDNS providers include:
- dyndns.org
- no-ip.com
- zoneedit.com
- freedns.afraid.org
- oray.net
You configure:
- DDNS username
- DDNS password
- DDNS hostname
- (Optional) DDNS hash
This helps maintain remote management access even with dynamic IP addresses.
Yes. The GXW42xx includes an advanced OpenVPN® client with full authentication and encryption options:
Supported parameters include:
- Primary and secondary VPN servers
- UDP or TCP transport
- TUN (router mode) or TAP (bridge mode)
- LZO compression
- BF-CBC or other available encryption methods
- SHA1 or other digest methods
- Uploading CA certificate, client certificate, and client key
- TLS-Auth or TLS-Crypt static key support
- Randomized server selection for redundancy
This ensures secure tunneling for deployments needing protected VoIP or remote management.
Yes. The GXW supports enterprise-grade 802.1X port authentication, allowing it to operate on networks requiring secure identity validation.
Supported modes:
- EAP-MD5
- EAP-TLS (client certificate required)
- EAP-PEAPv0/MSCHAPv2
You can upload:
- CA certificates
- Client certificates
- Private keys
This is essential in environments using NAC (Network Access Control).
Yes. The GXW42xx supports secure VoIP through:
SIP over TLS
- Uses built-in certificates or custom uploaded X.509 certificates
- Allows customizing private keys and enabling certificate validation
- Supports minimum TLS version enforcement (default: TLS 1.2)
- Enabled via feature code:
- *16 → Enable SRTP
- *17 → Disable SRTP
Encrypted signaling + encrypted audio ensures confidentiality for VoIP traffic in secure deployments.
Yes. The GXW allows fine-grained SSH security controls. You can choose:
- Allow only SSH private IP users to set system P-Values
- Allow all SSH users to set only system P-values
- Allow all SSH users to set any PValue
- Prohibit setting PValues entirely (read-only SSH)
This helps administrators control whether SSH users can modify system-level provisioning parameters.
Yes. The GXW supports RADIUS for both:
1. Web/SSH Login Authentication
You can configure:
- RADIUS server IP, port (1812)
- Shared secret
- PAP / CHAP / MSCHAPv1 / MSCHAPv2 authentication protocols
- Behavior when RADIUS server fails (local vs block)
2. RADIUS for Call Control & Accounting
Supports:
- Primary + secondary RADIUS servers
- Separate authentication and accounting ports (1812/1813)
- Retry/timeout values
This is commonly used in carriers, large enterprises, and operator-managed deployments.
Provisioning, Maintenance & Troubleshooting
The Provision button performs an immediate configuration fetch from the configured provisioning server without requiring a reboot.
When clicked:
- The GXW42xx sends a provisioning request to the server
- Retrieves the configuration file(s)
- Applies settings instantly when possible
- If a provisioning operation is already active, the system notifies that provisioning is in progress
This is useful for quick configuration testing or template validation.
The GXW42xx supports several upgrade mechanisms:
1. Automatic provisioning upgrades
Configured under Maintenance → Upgrade & Provisioning.
You can choose:
- Always Check for New Firmware
- Check Only When Prefix/Postfix Changes
- Always Skip Firmware Check
2. Manual server-based upgrade
You can set:
- Firmware Server Path (TFTP, HTTP, HTTPS)
- Upgrade protocol
- Authentication credentials for HTTP/HTTPS
- Hostname validation for secure HTTPS provisioning
3. Direct manual upload
You can upload a .bin firmware file through the web UI.
Automatic upgrade scheduling is also supported (daily/weekly), with options to randomize upgrade timing to reduce server load.
Yes. The GXW42xx supports applying multiple config files in a defined sequence.
If “Download and Process All Available Config Files” is enabled:
The device processes files in the following order:
cfgMAC.xmlcfgMACcfgMODEL.xmlcfg.xmlcfgMAC_override.xml- DHCP Option 67 config file (if provided)
Each file overwrites settings applied by the previous one, allowing layered configuration approaches (global → model → device-specific → override).
This is very useful for mass deployments.
The GXW42xx supports multiple backup and restore options:
1. Download (Export) Configurations
- Text Format (.txt)
- XML Format (.xml)
- Encrypted XML (for security)
2. Restore Configuration
- Upload a configuration file to immediately restore settings
- Restore from backup configuration files stored earlier
3. Upload Firmware
- Uploading firmware is separate but available under the same Maintenance section
These tools make it easy to migrate configurations or maintain templates for provisioning.
Syslog is configured under Maintenance → Syslog:
You can specify:
- Syslog server IP address (up to 3 servers)
- Syslog port
- Trap interval (for SNMP-like periodic sending)
- Whether to send syslog through the Management Interface (V2 only)
Syslog allows administrators to:
- Capture SIP messaging
- Debug registration issues
- Monitor provisioning behavior
- Analyze reboot reasons
- Track firmware upgrade operations
This is essential for troubleshooting in enterprise networks.
Under Status → System Info, you can download a detailed information file containing:
- Product model and hardware version
- Part number
- Software/firmware version (Program, Boot, Core)
- System uptime
- System time (synced via NTP)
- Device MAC address
- Network configuration (IP, DNS, gateway)
- VoIP service status
- Port status and recent activity
You can also use the LCD screen to check basic information onsite.
This summary is invaluable when submitting support tickets or performing remote diagnosis.