This document presents a summary of security measures, factors, and configurations that users are recommended to consider when configuring and deploying our HT8XX series of Analog Telephone Adapters.
The following sections are covered in this document:
- Web UI/SSH Access
Web UI access is protected by username/password and login timeout. Three-level user management is configurable. SSH access is supported for mainly troubleshooting purpose and it is recommended to disable it in normal usage. - Security for SIP Accounts and Calls
The SIP accounts use specific port for signaling and media stream transmission. It also offers configurable options to block anonymous calls and unsolicited calls. - Security for HT8XX Services
HT8XX supports service such as HTTP/HTTPS/TFTP/FTP/FTPS and TR-069 for provisioning. For better security, we recommend using HTTPS/FTPS with username/password and using password-protected XML file. We recommend disabling TR-069 (disabled by default) if not used to avoid potential port exposure. - Deployment Guidelines for HT8XX
This section introduces protocols and ports used on the HT8XX and recommendations for routers/firewall settings.
This document is subject to change without notice.
Reproduction or transmittal of the entire or any part, in any form or by any means, electronic or print, for any purpose without the express written permission of Grandstream Networks, Inc. is not permitted.
WEB UI/SSH ACCESS
Web UI Access
The HT8XX embedded web server responds to HTTP/HTTPS GET/POST requests. Embedded HTML pages allow users to configure the device through a web browser such as Microsoft IE, Mozilla Firefox, Google Chrome and etc. With this, administrators can access and configure all available HT8XX information and settings. It is critical to understand the security risks involved when placing the Analog Telephone Adapters on public networks and it’s recommended not to do so.
Web UI Access Protocols
HTTP and HTTPS are supported to access the HT8XX’s web UI and can be configured under web UI 🡪BASIC SETTINGS🡪 Web/SSH Access.
To secure transactions and prevent unauthorized access, it is highly recommended to:
- Use HTTPS instead of HTTP.
- Avoid using well known port numbers such as 80 and 443.
- Block or restrict WAN Side access (when set to “Yes”) by specifying a Blacklist for blocked addresses and a Whitelist for allowed addresses.

- The HT8XX allow access via SSH for advanced troubleshooting purpose. This is usually not needed unless the administrator or Grandstream support needs it for troubleshooting purpose. SSH access on the device is enabled by default with port 22 used. It’s recommended to disable it for daily normal usage. If SSH access needs to be enabled, changing the port to a different port other than the well-known port 22 is a good practice.
User Login
Username and password are required to log in the HT8XX’s web UI.

The factory default username is “admin” and the default password is “admin”. Changing the default password at first time login is highly recommended.
To change the password for default user “admin”, navigate to Web GUI 🡪 ADVANCED SETTINGS

The password length must between 6 and 32 characters. Strong password with a combination of numbers, uppercase letters, lowercase letters, and special characters is always recommended for security purpose.
User Management Levels
Three user privilege levels are currently supported:
- Admin
- User
- Viewer
User Level | Username | Password | Web Pages Allowed |
End User Level | user | 123 | Only Status & Basic Settings. |
Administrator Level | admin | admin | All pages. |
Viewer Level | viewer | viewer | View all pages. Changes not allowed. |
NOTES:










