Start your EVOTECH request in under a minute.
Cloud PBX Setup in Houston, TX 77099
When a hosted phone system misbehaves in an office-suite or flex building off Beltway 8, the platform is almost never at fault. The trouble sits in the sixty feet between your handset and the internet handoff — a router doing something helpful, a second router nobody remembers, a tenant account with every dialling permission switched on. This page is the network and security half of a cloud PBX build: keeping phones registered, and keeping the account yours.
The first thing that has to work: staying registered
A hosted handset is not connected to anything the way an old analog line was. It announces itself to the platform on a schedule, and the platform remembers where to send an incoming call until that announcement expires. Everything you experience as reliability is really that announcement arriving on time.
The announcement is a SIP REGISTER, and it carries an expiry — how long the platform should hold the address it just learned. Between announcements, the only thing keeping the path open is a hole your firewall punched outward when the phone first spoke. Firewalls close those holes on their own timer, and a great many small-business gateways close them faster than the default registration interval. The result is a signature fault we see constantly in 77099 suites:
Outbound calls work perfectly. Inbound calls go straight to voicemail, or ring once and stop. Outbound works because the phone opens a fresh path itself. Inbound fails because the platform is sending the call to a doorway that quietly closed. Nothing about that looks like a network problem to the person holding the phone, so it usually gets blamed on the provider.
The fix is boring and permanent: shorten the registration interval so it comfortably beats the firewall’s idle timer, or enable the keepalive the handset already supports, and then confirm from the platform’s registration log that the device is re-announcing on the schedule we expect rather than on the schedule we assume.
The second router nobody remembers
Office condominiums and flex units along Boone Road and West Bellfort change hands often, and the networking hardware usually stays behind. We routinely find the building’s handoff feeding a leftover consumer router, which feeds the router the current tenant actually bought. Two layers of address translation means two sets of timers, two firewalls, and a phone whose registration is rewritten twice on the way out. It is survivable with careful configuration and far better simply removed — one device doing the translating, chosen deliberately.
Turn off the feature your router calls a SIP helper
Nearly every gateway sold to small business ships with a module that inspects voice signalling and edits it in flight, believing it is being useful. Manufacturers name it differently — SIP ALG, SIP Transformations, SIP Helper, Consistent NAT — and on modern hosted platforms it causes far more damage than it prevents, because the platform already knows how to handle a phone behind a translated address.
What it looks like when it is on and nobody has noticed:
- Calls that connect but where only one party can hear the other.
- A handset that shows a call in progress for a few seconds, then drops it with no error.
- Transfers that put a caller on hold and never bring them back.
- Registrations that flap — the device list showing a phone online, offline, online, in the space of a morning, with nothing changing in the room.
Disabling it is a single setting on most gateways. Finding it is the work, because on some models it lives under a submenu that mentions neither voice nor SIP, and on a handful of ISP-supplied units it is not exposed at all — which is a genuine reason to replace the gateway rather than a preference.
Why we move you to encrypted signalling anyway
Running signalling over TLS and the audio itself over SRTP does two things at once. It protects the credentials that let a device place calls on your account, which matters more than most owners realise. And because the router can no longer read what it wanted to edit, an ALG somebody re-enables during a future firmware update simply passes the traffic through untouched. It removes a whole category of future fault rather than fixing today’s.
One caution that belongs with it: a handset offering a long list of codecs produces large signalling packets, and oversized packets across an encrypted path can fragment and fail in ways that look random. We trim each device’s codec list to what the platform and your circuit will actually use, which keeps those packets small and the behaviour predictable.
Toll fraud is a configuration problem, not bad luck
The pattern is consistent enough to be boring. Credentials for a single extension are obtained — guessed, reused from somewhere else, or left at a factory default on a phone bought secondhand. Nothing happens for days. Then, beginning late on a Friday, the account places a long run of calls to international destinations that bill at premium rates, and it continues until somebody notices on Monday. It is not a sophisticated attack and it is not aimed at you personally; it is automated, and it finds accounts that were left open.
Every control that stops it is available in the tenant on day one and costs nothing but the decision to use it.
| Control | What it actually prevents |
|---|---|
| International dialling off by default, enabled per user on request | The entire premium-rate scenario. Most staff in a Houston office have never needed to dial abroad from a desk phone. |
| Per-device credentials, machine-generated, never reused | One compromised phone becoming the whole account. |
| A ceiling on simultaneous calls, set a little above your real busy hour | Turns a runaway event into a small bill instead of a large one. |
| Restricting where devices may register from | Registrations arriving from countries your business does not operate in. |
| Spend and volume alerts sent to a person, not to a shared inbox | The gap between Friday night and Monday morning. |
| Blocking premium and pay-per-call ranges outright | Domestic variants of the same trick that people assume cannot happen inside the country. |
We set all six during the build and write down which ones you asked us to relax, so that a year later there is a record of why something is open rather than an argument about whether it always was.
Who may dial what, and who may listen to it
Dialling permission is one axis. The other is access to what the system stores, and in a business with an office side and a warehouse side those two axes rarely line up with job titles.
Permission classes are worth writing as a short list and applying to roles rather than individuals, so that hiring somebody does not mean re-deciding it. A shipping desk phone that dials internal extensions, local numbers and nothing else is not a restriction anybody will complain about. A front-office position that needs long distance gets long distance. Exactly two people need the class that includes everything.
Voicemail is the part that gets overlooked. A voicemail box with a four-digit PIN left as the extension number is trivially opened, and once opened it is not only a message store — on many platforms a mailbox can be used to place an outbound call. Enforce a PIN that is not the extension, not sequential, and changed from whatever was set during the build.
If you record calls, decide before go-live who may play a recording back, how long recordings are kept, and where they are stored. Recording that is on for everyone, retained forever and audible to anyone with an admin login is a liability sitting quietly in a portal. Texas is a one-party-consent state, so a business recording its own calls is generally on solid footing — but calls that cross state lines are not automatically covered, and the policy itself is a question for your attorney rather than your phone installer.
Finally, turn on two-factor authentication for every administrative login, including ours. An email address and a reused password is the weakest point in an otherwise well-built system.
What we check on a 77099 site before we put a number on anything
We do not quote a hosted build from a phone call, because the things that decide the price are not visible from a phone call. A visit to a suite off Bissonnet or a flex unit behind Beltway 8 covers:
- Where the internet actually enters, whose equipment it lands on, and whether the building or the tenant controls it. Shared-building circuits are common here and they change what we can promise.
- Upload as well as download, measured over long enough to catch the busy hour, plus latency variation and loss. A circuit that tests beautifully at 7 a.m. is not evidence of anything.
- How many routers are in the path, and whether any of them are someone else’s.
- The switch. Powered ports available, their power budget against the phones being proposed, and whether voice can be separated onto its own segment or has to share.
- Cabling. Live jacks at each intended position, their length, and what is on the other end — in a converted warehouse office the answer is often a spool in the ceiling.
- The far corners. A cordless base has to cover the places people actually stand, and a tilt-wall building is unkind to cordless in ways a floor plan will not reveal.
Those findings become an itemised written quote. We will not name a figure before we have them.
Related services
Frequently asked questions
Our calls sound fine some days and terrible on others. Is that the internet plan?
Rarely the size of it. Voice needs very little bandwidth but is intolerant of variation in packet timing and of loss. Intermittent trouble usually traces to something else on your own network taking the circuit at a predictable hour — a backup, a large upload, a camera system syncing — or to a router doing address translation twice. We measure across a working day rather than taking one speed test.
Do we need a separate internet connection just for the phones?
Usually not. Giving voice its own segment and priority on the switch achieves the same outcome for far less, and a second circuit only earns its keep as a failover path. If the circuit is genuinely saturated every afternoon, the honest answer is to fix the circuit rather than to add a phone system on top of it.
Somebody told us to disable SIP ALG. Is that safe?
Yes, and on a hosted platform it is the recommended state. The feature exists for older on-premises systems that could not handle being behind a translated address; modern platforms handle it themselves, and leaving the router to rewrite signalling causes one-way audio and dropped transfers. The one thing to check is that the setting stays off after a firmware update.
What happens to our phones during a power cut on Bissonnet?
Handsets draw power over their network cable from the switch, so the switch and the router are what need protecting — a battery backup sized for them keeps desk phones alive far longer than one sized for a whole rack. Beyond that, the advantage of hosted voice is that the call logic is not on your premises: if the building is dark, we can have the platform send calls to mobiles automatically, which is configured during the build rather than improvised during an outage.
How would we even know if our account was being used for fraud?
Only if somebody told the system to tell you. Spend and concurrent-call alerts addressed to a named person are the difference between noticing in twenty minutes and noticing on the next invoice. We set them during the build and test that the alert genuinely arrives, because an alert nobody has ever seen fire is not a control.
Free on-site network readiness check in Houston 77099
Before you commit to a platform, let us measure the circuit, trace what is between your jacks and the street, and tell you honestly what has to change first. Written, itemised, and no figure quoted sight-unseen. Call (832) 359-2425.
Book a Free Consultation
Ready for EVOTECH to help?
Before you leave, send the quick version. We will review the page you came from and reply with the clean next step.
