This FAQ document provides a structured and comprehensive reference for the Grandstream HT841/HT881 FXO Gateways. It covers essential topics such as hardware capabilities, installation procedures, telephony behavior, SIP/PBX integrations, configuration methods, security features, and maintenance operations. Each question and answer is based solely on official device specifications to help users deploy, manage, and troubleshoot the HT8x1 series efficiently.
Product Overview & Hardware
The HT841 and HT881 are FXO VoIP gateways designed to bridge traditional analog PSTN lines with IP-based phone systems. They convert PSTN calls to SIP and vice versa, enabling integration with IP PBXs, SIP servers, or direct IP calling scenarios. The only difference between them is the FXO port count: the HT841 provides 4 FXO ports, while the HT881 offers 8 FXO ports, making the HT881 suitable for environments needing more PSTN line capacity.
The devices support multiple PSTN interfaces through RJ11 FXO ports. The HT841 includes four FXO ports, while the HT881 doubles this capacity with eight FXO ports. These ports allow the gateway to connect to multiple analog telephone lines from a PBX or PSTN central office.
Both models feature one FXS port, which serves as a connection point for an analog phone or fax machine. This allows users to place or receive calls directly through the gateway or use the port as the lifeline fallback phone during power or SIP outages.
The gateways include two 10/100 Mbps Ethernet ports (NET1 and NET2). These can function as WAN or LAN depending on configuration. By default, the device operates in bridge mode, where both ports behave similarly, but they can also be set to router mode or WAN-only mode to provide DHCP services or perform NAT.
Yes. The NET2 port supports PoE input, allowing the device to be powered using a PoE switch without a separate power adapter. When powered through PoE, the Power LED displays orange instead of green.
The gateways include LEDs for Power, NET1, NET2, FXS, and each FXO port. They indicate statuses such as network connectivity, registration states, off-hook/busy events, voicemail presence, and firmware upgrade mode. For example, a solid green FXS LED means the port is registered and ready, while blinking indicates the phone is off-hook.
The devices use TLS/SIPS/HTTPS to secure signaling and management access, SRTP to encrypt media streams, and AES encryption for provisioning files and configuration downloads. They also support certificate validation, customizable TLS versions, and the option to load trusted CA certificates.
Supported codecs include G.711 (PCMA/PCMU) with PLC/VAD/CNG, G.723.1, G.729A/B, G.726, iLBC, and OPUS. The device also includes advanced media handling features such as dynamic jitter buffer and line echo cancellation for clearer call quality.
The gateways support a wide range of international Caller ID formats, including Bellcore Type 1 & 2, ETSI, BT, NTT, and DTMF-based CID. This ensures compatibility with PSTN providers worldwide.
You can power the devices using either a 12V DC adapter (12V/1A) or 48V PoE on the NET2 port. This flexibility simplifies deployments in different power environments and helps avoid cable clutter when PoE is available.
They operate within 0–40°C and support storage temperatures from –10 to 60°C. Humidity tolerance is 10–90% non-condensing, meaning the device can function reliably in typical office or equipment room conditions.
Both models share the same physical size: 190 mm (L) × 100 mm (W) × 28 mm (H), and weigh approximately 0.46 kg. Their compact form makes them suitable for desktop installations.
Telephony, Calling & FXO/FXS Behavior
Pick up the handset and either dial the full number and wait 4 seconds (default No Key Entry Timeout) or dial the number and press # if “Use # as dial key” is enabled. The gateway will then process the digits — for local extensions, dial the extension (e.g., 1008) and wait or press #; for PSTN numbers include the required prefix (for example 1 for outside line or country code) before the number. The 4-second timeout avoids needing to press # for every call, but pressing # immediately sends the digits if you want faster dialing.
Direct IP Calling lets two endpoints talk peer-to-peer without a SIP server — useful when both devices are on the same LAN or have reachable public IPs. You can initiate it two ways: through the IVR by dialing *** → 47 and entering the target IP, or directly by dialing the star code *47 followed by the IP digits (use * in place of dots). Example: to call 192.168.0.160 dial *47 192*168*0*160 and press # (if configured) or wait 4 seconds. To include a port (e.g., 192.168.1.20:5062) add *5062 at the end. For direct IP calls ensure Use Random SIP/RTP Port = NO.
There are many handy star codes. Examples: *47 for Direct IP Calling; *16 / *17 to enable/disable SRTP per call; *02 to force a codec (e.g., *027110 for PCMU); *30/*31 to block or send Caller ID; *69 for call return; *72 to set unconditional call forward and *73 to cancel it; *78/*79 to enable/disable DND. These codes operate from the analog phone and let you control many call behaviors without opening the web UI.
Lifeline maps a PSTN FXO port to the FXS port so an analog phone can still place/receive PSTN calls during outages or SIP registration loss. There are three modes: Auto (default — activates on power loss or SIP registration loss), Always Connected (FXS permanently tied to PSTN; VoIP disabled on FXS), and Always Disconnected (lifeline disabled; FXS only supports VoIP). On HT841 the lifeline maps to FXO4; on HT881 it maps to FXO8.
Incoming PSTN calls on an FXO port are automatically forwarded to a configured IP extension or SIP destination. The gateway receives the incoming digits from PSTN and forwards the call to the SIP destination configured in the device or the connected IP PBX, which can then apply routing, IVR, or hunt groups.
The HT841/HT881 support T.38 Group 3 Fax Relay up to 14.4 kbps for reliable Fax-over-IP. If T.38 fails or is not available, the device can auto-switch to G.711 pass-through for fax transmissions. Use T.38 for best reliability over packet networks.
Disconnect detection supports busy tone detection, polarity reversal/wink, and loop current. For ring/load, the device supports short/long haul ring load with up to 3 REN and can work up to about 1 km on 24 AWG cable, useful for long analog runs.
Caller ID types include Bellcore Type 1 & 2, ETSI, BT, NTT, and DTMF-based CID, covering most international PSTN formats. For DTMF signaling the gateway supports in-audio, RFC2833, and SIP INFO, so it can interoperate with various service providers and PBXs.
If a channel/account is not registered and the setting Outgoing Call without Registration is No, the IVR will announce “Device not registered” when the handset is picked up. If you want to permit outbound calls without SIP registration (for direct FXO dialing or forwarding behaviors), enable Outgoing Call without Registration so the gateway will still process outgoing calls.
The Stage Method determines how the gateway processes the dialed digits for FXO-driven call flows. For certain gateway-to-gateway or FXS/FXO paired scenarios (for example when the HT8x1 is used with an FXS gateway like GXW42xx) the docs recommend Stage Method = 1 so the gateway properly forwards dial strings to the FXO line without extra digit processing. Use Stage Method = 1 in peer gateway forwarding scenarios.
Use per-call star codes: *02 + codec code to force a codec (examples: *027110 = PCMU, *02729 = G.729). *16 enables SRTP for that call and *17 disables SRTP. Other per-call toggles include *67/*82 to block or force caller ID for that specific call.
Yes — you can use a prefix to specify an FXO port when hunting/group dialing. The prefix setting (up to 10 digits) can be combined with the port index so dialing prefix + port + number instructs the gateway to use a specific FXO port for that call. This is useful when you want to route particular outbound calls through a particular PSTN trunk in multi-line deployments.
Installation & Network Setup
The package contains the HT841 or HT881 gateway, Ethernet cable, and quick installation guide. Users should verify that all items are present before installation and report missing components to their administrator.
The device includes a DC 12V power port, NET1/NET2 network ports, a PoE IN port on NET2, one FXS port, and 4 or 8 FXO ports depending on the model. NET ports provide WAN/LAN connectivity, FXO ports connect PSTN lines, and the FXS port connects an analog phone or fax.
By default, the device boots in Bridge Mode, meaning NET1 and NET2 act nearly identically and pass network traffic through. This mode simplifies initial setup by avoiding NAT until the user changes the configuration.
When NET1 is used for WAN, the device acts as a DHCP client.
To install:
- Connect an analog phone to the FXS port.
- Connect NET1 to your router/modem.
- Power on the device (via PSU or PoE).
Once powered, NET1/NET2, FXS, and FXO LEDs will become solid, indicating readiness.
When NET2 is used as LAN, the gateway operates as a router with a DHCP server enabled.
To set up LAN/Router mode:
- Connect an analog phone to the FXS port.
- Connect a computer or switch to NET2.
- Power on the device (or provide PoE power).
In this mode, any devices connected to NET2 will automatically obtain IP addresses from the HT841/HT881 DHCP server.
Important: Make sure NAT Router mode is enabled under:
Web GUI → Basic Settings → NAT/DHCP Server Information & Configuration → Device Mode
Users may switch which port acts as WAN or LAN through Web UI → Network Settings → LAN Settings. This allows reversing network roles for flexible installation scenarios.
The Power LED color indicates the power source:
- Orange = powered using PoE on NET2
- Green = powered by the 12V PSU
LEDs provide visual diagnostics:
- FXS/FXO LEDs show registration, busy status, or voicemail (slow blinking).
During firmware upgrades, specific LEDs stay solid while FXO LEDs blink to show progress. - Power LED blinks during boot.
- NET LEDs light when the port is active.
Connect a phone to the FXS port, dial *** to open IVR, then press 02. The system announces the current IP. If DHCP is enabled, this is the address assigned by your network; in LAN mode, the default is 192.168.2.1.
To access via WAN (NET1):
- Get the device IP via IVR.
- Enter the IP in a browser.
- Log in with the admin password.
To access via LAN (NET2):
- Connect directly to NET2.
- Use default IP 192.168.2.1.
- Ensure your PC has an IP in the 192.168.2.x range.
SIP, IP PBX & GATEWAY SCENARIOS
When paired with an IP PBX (such as a UCM series), the SIP server manages registration and call routing, while the HT841/HT881 handle the conversion between SIP and PSTN audio. Outbound VoIP calls received from the PBX are forwarded through the FXO ports to the PSTN, and incoming PSTN calls are converted into SIP INVITEs sent to the PBX for further routing (IVR, ring groups, extensions, etc.).
(1) With SIP Accounts on Channels Page:
Each FXO channel registers as a SIP endpoint using SIP User ID, Password, etc. The server routes calls to these accounts, and the gateway sends them out through FXO lines.
(2) Without SIP Accounts:
Instead of registering, the SIP server simply forwards call INVITEs directly to the gateway’s IP address. The gateway immediately sends the digits out through FXO. In this mode, the Stage Method must be set to 1, and the SIP Server field must contain the PBX IP address.
VoIP devices call a SIP extension on the PBX → PBX forwards the call to the SIP account registered on the FXO channel → HT841/HT881 receives it → gateway dials out through the corresponding FXO line to reach the PSTN destination.
When PSTN calls arrive on an FXO line, the HT8x1 automatically generates a SIP INVITE toward a configured destination (such as a PBX extension or main IVR). The PBX then applies its own routing logic (ring groups, queues, or attendants).
The gateway can operate in a serverless “Gateway-to-Gateway” mode, typically paired with an FXS gateway (ex: GXW42xx). Each gateway uses the other’s IP address as the SIP Server. No SIP registration is required. The two devices exchange SIP messages directly to transfer calls between an analog phone (GXW) and PSTN lines (HT8x1).
Both gateways must be able to reach each other (same LAN or public IPs).
Configuration Requirements:
- SIP Server = the other gateway’s IP
- SIP Registration = No
- NAT traversal = No
- Stage Method = 1
- FXS gateway uses “Outgoing Call without Registration = Yes”
This allows analog phones on the FXS side to dial PSTN calls through the FXO gateway remotely.
A user picks up an analog phone on the FXS gateway → dials the PSTN number → GXW forwards the INVITE to the HT841/HT881 → gateway receives digits → sends them out via FXO to PSTN.
Reverse direction: PSTN → HT8x1 → auto-forward to FXS gateway → analog phone rings.
Stage Method 1 ensures the gateway sends the full digit string directly to the PSTN side without waiting for extra processing. This is critical for peer devices where the FXO gateway must immediately dial the digits supplied by the FXS gateway (no second stage dialing).
If the primary SIP server becomes unreachable, the device automatically switches to a secondary SIP server. This ensures PSTN-to-SIP and SIP-to-PSTN routing continues working without user intervention or manual re-registration.
The gateway supports UDP, TCP, TLS, and full SIP over TLS (SIPS), allowing secure signaling when needed. SRTP can also be enabled for secure media streams, giving full encrypted SIP operation end-to-end.
The device supports NAT traversal through STUN, or can operate without NAT traversal when servers and gateways are on the same LAN. For gateway-to-gateway scenarios, NAT traversal is often set to No, while traditional PBX deployments may use STUN or rely on local network routing.
The HT8x1 supports a wide variety of Caller ID standards (Bellcore, ETSI, BT, NTT, DTMF-based), ensuring correct caller identification during PSTN–SIP conversion. Likewise, disconnect methods (busy tone detection, polarity reversal, loop current loss) ensure accurate line supervision so the SIP side knows when a PSTN caller hangs up or the line becomes idle.
Configuration, Web UI & IVR
The device supports two main configuration methods:
- IVR Menu via the telephone connected to the FXS port for basic network and diagnostic operations.
- Web GUI through a browser for full configuration of accounts, FXO/FXS behavior, security settings, provisioning, VLAN, QoS, and advanced parameters.
This dual method allows quick on-site adjustments as well as complete remote administration.
Pick up the analog phone connected to the FXS port and dial ***. You’ll hear “Enter the menu option.”
From there you can:
- Check IP address (02)
- Change IP mode (01)
- Set static IP, subnet, gateway, DNS (02–05)
- Play MAC address (10)
- Choose vocoders (07)
- Perform firmware checks/upgrades (15–17)
- Reboot device (99)
- Make Direct IP calls (47)
The IVR is primarily used for basic configuration and diagnostics when physical access is required.
In the IVR system:
- Press * to move to the next option.
- Press # to return to the main menu.
- Press 9 to confirm or toggle options.
- IP addresses must be entered as 12 digits without dots (e.g., 192.168.0.26 →
192168000026).
These rules ensure uniform input and prevent accidental configuration errors.
Check the device’s IP via IVR, connect your PC in the same network, then enter the IP in a browser. Authentication with the admin password grants access to all configuration menus. This method is used when the device is deployed behind a router or PBX system.
When NET2 is acting as the LAN port (in router mode), connect your PC directly to NET2 and enter the default LAN IP 192.168.2.1 in your browser. Your PC must have an IP in the 192.168.2.x range to access the GUI. This is the recommended method for first-time or isolated configuration.
Network changes such as IP address, subnet mask, gateway, DNS, or IPv6 settings require a device reboot. This ensures the new configuration is fully applied to the network stack.
The Status Page provides detailed system diagnostics, including:
- Device model, serial number, hardware version
- Software versions (Program, Core, Bootloader, Base, CPE)
- System uptime, memory usage, CPU load
- Port registration and hook status (FXS/FXO)
- SIP destination ports
- Network info (IPv4/IPv6 address, NAT type, cable status)
- This page is essential for troubleshooting and system validation.
Port Status shows real-time behavior of the FXS and FXO interfaces, including:
- Hook state (on-hook/off-hook)
- SIP User ID registered to the port
- Registration state
- Destination SIP port
This is useful for diagnosing registration issues or verifying line supervision.
Under Basic Settings, you can set Disable Voice Prompt = Yes to turn off IVR announcements. This is often used in secure or controlled environments to prevent unauthorized users from hearing configuration details when lifting the handset.
The device allows full customization of tone frequencies and cadences under the Ringtone / CPT Settings section. You can modify:
- Dial, Busy, Reorder, Ringback tones
- Frequencies (10–4000 Hz)
- On/Off cadences (0–64000 ms)
This flexibility ensures compliance with international telephony standards and prevents audio mismatches with regional PSTN providers.
There are two ways:
- Hardware reset button: Press and hold for 7 seconds (quick press only triggers a reboot).
- IVR Method: Dial 99, press 9, and enter the device’s MAC address to confirm full factory reset.
A factory reset restores all parameters including network, SIP accounts, FXO settings, and provisioning paths.
Verify:
- Your PC is in the same subnet as the device.
- WAN Side Access is enabled if accessing from NET1.
- Web Access Mode (HTTP/HTTPS) is correctly configured.
- The Web Access Attempt Limit or Lockout Duration didn’t block you.
- NET1/NET2 cable status (UP/DOWN).
- If still inaccessible, retrieve the IP via IVR (option 02) and try again, or perform a controlled reboot.
Security, Provisioning & Maintenance
The device supports SRTP for encrypting media streams and TLS/SIPS/HTTPS for securing SIP signaling and Web UI access. This combination ensures both call audio and control messages are protected against interception. The unit also includes AES-encrypted provisioning, allowing secure configuration downloads from remote servers.
Under Security Settings, you can choose HTTP, HTTPS, or disable web access entirely. You can also configure:
- Web session timeout
- Attempt limits and lockout duration
- SSH enable/disable
- SSH/Telnet ports (cannot conflict)
- User-level and viewer-level access restrictions
You can further restrict management access through WAN-side whitelist/blacklist rules, limiting which IPs can remotely access the device.
The system supports strict password rules, allowing you to define:
- Minimum password length (4–30 characters)
- Required character classes (uppercase, lowercase, numbers, symbols)
These ensure strong password policies for admin, user, and viewer accounts, reducing the risk of unauthorized access.
The gateway includes built-in certificates and supports uploading custom CA certificates, private keys, and TLS client certificates. You can also:
- Enable weak cipher blocking (DES, 3DES, RC4, etc.)
- Set minimum/maximum TLS versions (e.g., TLS 1.2 only)
- Validate server certificates against built-in or imported CAs
This ensures secure authentication when connecting to SIP servers or provisioning servers.
The HT8x1 supports full TR-069, allowing Auto Configuration Servers (ACS) to provision and monitor the gateway. Administrators can define:
- ACS URL and credentials
- Inform intervals (default 86400s)
- SSL certificates for secure ACS connections
TR-069 also allows remote triggering of test features such as false ring signals for troubleshooting.
The device supports SNMP v1, v2c, and v3. You can configure trap destinations (up to 3), authentication/privilege settings (MD5/SHA, AES/DES), trap intervals, and community names. SNMPv3 adds secure authentication and encryption for enterprise-grade monitoring.
Provisioning can use TFTP, HTTP, HTTPS, FTP, FTPS, with HTTPS as default. You can configure:
- DHCP Options (66/160/43) for automatic server discovery
- The device can download config files in multiple priority sequences depending on whether “Download and Process All Config Files” is enabled.
- Firmware/config server paths
- File prefixes/postfixes
- Authentication credentials
- XML config file decryption password
You can schedule upgrades in different ways:
- Only at boot
- Every X minutes
- Daily between a specified time window
- Weekly on a chosen day
Upgrades can also be randomized to reduce simultaneous traffic. During firmware updates, LEDs follow a specific pattern and the process can take 20–30 minutes.
Several controls are available:
- Enforce HTTPS and validate host certificates
- Require authentication for config files
- Restrict config file types (XML-only)
- Allow only specific DHCP options for provisioning
- Use a whitelist/blacklist for WAN configuration access
These measures prevent unauthorized interception or tampering with configuration data.
You can specify a syslog server IP or URL, then choose log verbosity from NONE up to EXTRA DEBUG. The gateway reports key events such as boot information, NAT activity, SIP events, and error states. Syslog is essential for troubleshooting call failures, FXO line issues, or provisioning problems.
The HT841/HT881 can operate as a VPN client with options including:
- Primary and Secondary OpenVPN server addresses
- UDP or TCP transport
- TAP or TUN interface types
- LZO compression
- Encryption options (default BF-CBC 128-bit)
- Client certificates, CA files, and key authentication
This allows the device to securely integrate into remote VoIP infrastructures.
The device allows:
- Uploading configuration files (
.txtor.xml) - Downloading current config in text or XML
- Exporting backup configuration in
.xml - Restoring from backup anytime
- This ensures administrators can easily migrate settings, roll back to known working states, or maintain consistent configurations across multiple units.