Phones & Devices 2 min read

Cisco SPA Phones and SPA112 / SPA122 Adapters

Older Cisco SPA phones (SPA301 to SPA525G) and the SPA112 and SPA122 phone adaptors still work with Click2Call, and the portal can configure them for you. Cisco no longer updates these devices, so read the security note before you start.

Last reviewed: October 2026

Before you start: security

Cisco stopped releasing updates for the SPA range years ago, and they have known security weaknesses. Keep them behind your router — never make them reachable from the internet, and don't forward ports to them. If you're buying new equipment, choose a supported model instead, such as a Grandstream HT801 or HT802 adaptor (Connecting an Analogue Phone or Fax with a Grandstream HT801 / HT802).

Step 1: add the device in the portal

Go to Voice → Phones → Add a new phone, set Phone Manufacturer to Cisco, pick your model, and enter the MAC Address (on the back of the device, in the phone's menu, or in its web interface), a Description and the number for Account 1.

On SPA phones, every account you want active needs its own Phone Line key. Use spare keys for BLF, speed dials and so on (see Programming Phone Keys). Click Add Phone.

Step 2: copy your Profile Rule

The phone's settings page in the portal shows Provision Enable: Yes and a Profile Rule — a web address starting http://cisco.securevoip.nz/ followed by a long code. The code is unique to your account and protects your configuration, so copy it from the portal rather than typing it.

Step 3: factory-reset the device

On a phone, use the menu key and scroll to Factory Reset. On an SPA112/122 adaptor, use the reset option in its web interface.

Step 4: enter the Profile Rule on the device

Log in

Find the IP address — on SPA504G: menu option 9, Network → Current IP; on SPA525G: Settings → Status → Network Status; on an SPA112/122, plug in a phone and dial **** then 110#. Enter the address in a browser and log in as admin (default password admin). Choose admin / advanced to see all settings.

Set provisioning

Open Voice → Provisioning and set:

Click Submit All Changes. The device downloads its settings within about a minute — restart it if it doesn't.

Adaptors set up manually, without the portal

If an SPA112 or SPA122 was configured by hand, it needs a certificate before it can use TLS, because its built-in certificate list is out of date. Under Voice → Provisioning → CA Settings, set Custom CA URL to http://www.securevoip.nz/sip.securevoip.nz-rootca-2023.pem, save and restart. Devices set up through the portal don't need this.

Still need help?

Our Australian support team is available to assist you.