What is 2talk Lyra?
Lyra is 2talk's new voice platform, replacing 2talk+. It powers all new 2talk accounts from April 2026 and is where future development — including AI voice features — will happen. Existing customers can migrate from 2talk+ to Lyra at any time.
If you're on 2talk+, Lyra is where you're headed. It's the new home of the 2talk voice platform, and where all future development — including AI Voice features — will happen.
Transitioning from 2talk+
As 2talk+ is phased out, all 2talk voice users will need to move to Lyra.
How to see which voice platform your are connected to
To find out which platform your account is on, log in to your 2talk account and open the Cloud PBX module. If you're on Lyra, you'll see the banner displayed below.
![]()
New accounts
From 15 April 2026, all new 2talk accounts are created on Lyra by default.
Opt-In Migrations
Any 2talk retail account on 2talk+ can opt in to migrate to Lyra ahead of the staged migrations. If your account uses a Teams or BYOC trunk, contact the support team for migration assistance. For other connection types, read the Migrating to Lyra article before you start your move. For opt-in migrations, update all end-user devices, such as phones or PBX systems, to point to the new SIP proxy: lyra.2talk.co.nz.
Staged Migrations
Staged migrations for the 2talk voice proxies, sip.2talk.co.nz and peering.2talk.co.nz, start on Monday 12 October 2026. During a staged migration, you do not need to update your SIP proxy details. We recommend you check the staged migrations checklist below. This ensures that the move will run smoothly.
Staged Migrations Checklist
For staged migrations, 2talk moves customer accounts automatically. Please check the following configuration items beforehand to help the move run smoothly.
1. TLS version
Lyra requires TLS 1.2 or above. TLS 1.0 is deprecated and no longer supported. Audit your devices for TLS 1.0 usage. Where a device cannot upgrade to TLS 1.2, reconfigure it to use UDP or TCP instead of TLS, or replace the device.
If your firewall or router only allows call audio (media) from a single IP address, such as the SIP proxy address, update this rule. After the move, call audio comes from a range of addresses instead. Allow the IP network 27.111.14.0/24, using source ports 20000 to 50000, to send media.
This change most affects accounts that connect to 2talk using SIP peering, meaning IP-based SIP trunks, with their own PBX. If this applies to your account, check that your firewall allows traffic from 27.111.14.0/24 through to your PBX.
Presence and dialog are separate event types and cannot be used interchangeably. Both endpoints in a BLF relationship must use the same event type. If they do not, state monitoring will not work. Confirm your devices use a consistent event type before migration.
4. Shared Line Appearance (SLA)
The "-x" suffix is no longer required when registering additional devices on a shared line. Existing SLA configurations that use "-x" continue to work as they are. No action is needed unless you set up new registrations.
New Features
Lyra introduces several enhancements.
Multisite BLF
Multisite BLF is fully supported. It allows line state monitoring across multiple locations. Lines must be in the same group and on the same account.
Secure Media (SRTP)
Secure Media (SRTP) encrypts media between the device and 2talk. TLS transport is recommended.
Expanded SLA Capacity
Expanded SLA Capacity supports up to 10 SLA numbers, up from 6.
New Voice Connections Module
The Voice Connections Module adds failover and load balancing options for accounts using SIP peering. It also improves account and group based registered trunking, and adds portal configuration for BYOC trunks with Genesys, Twilio, MS Teams, and ElevenLabs.
SIP Peering
SIP Peering now supports up to 3 IPs for failover, up from 2.
A new Load Balancing Algorithm setting supports Sequential or Round Robin load balancing.
A new Extended Outbound Authentication setting allows selection of a method to authenticate outbound calls, in addition to permitting calls only from the configured source IPs. This defaults to none. Set it to Auth Token if authentication is required.