{"id":1847,"date":"2026-10-11T18:19:25","date_gmt":"2026-10-11T21:19:25","guid":{"rendered":"https:\/\/www.linuxpro.com.br\/?p=1847"},"modified":"2026-10-11T19:09:27","modified_gmt":"2026-10-11T22:09:27","slug":"freepbx-17-central-voip-no-debian-12","status":"publish","type":"post","link":"https:\/\/www.linuxpro.com.br\/en\/2026\/10\/freepbx-17-central-voip-no-debian-12\/","title":{"rendered":"FreePBX 17: VoIP PBX on Debian 12"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" src=\"\/wp-content\/uploads\/2026\/10\/freepbx-17-debian-12-capa-v1.webp\" alt=\"Mascote LinuxPro conecta cabos em um rack de telefonia IP com o logo FreePBX, acompanhado do c\u00e3o caramelo cyborg.\" width=\"1486\" height=\"856\" \/><\/p>\n<p>Setting up an IP phone system on Linux does not need to start with manually editing the dialplan. The <strong>FreePBX 17<\/strong> provides a web interface to manage Asterisk: extensions, trunks, routes, queues, and auto-attendant are organized into modules. The important change in this generation is in the foundation: <strong>Debian 12, installation via script or ISO, and attention to migrating from chan_sip to PJSIP<\/strong>.<\/p>\n<p>In this guide, we will separate the versions involved, choose the installation method, and set up a lab with two extensions. Then, we will look at what changes when migrating an existing PBX and the precautions before connecting to a carrier. The references are the <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/FP\/overview\">official Sangoma documentation<\/a>, the installer maintained by the project, and the two videos indicated at the end.<\/p>\n<div style=\"background:#fff8e1;border-left:4px solid #8b1a1a;padding:.8em 1em;margin:1em 0\"><strong>Reference: October 2026.<\/strong> FreePBX, Asterisk, Debian, and the ISO image each have their own versions and release cycles. Do not confuse the ISO number with the version of all the modules, and do not use an old demo as an automatic indicator of the project's current state.<\/div>\n<h2>FreePBX does not replace Asterisk<\/h2>\n<p>Think of two layers: <strong>Asterisk<\/strong> runs the telephony; <strong>FreePBX<\/strong> provides the panel that organizes your configuration. The first processes calls and dialplan applications. The second lets you manage the PBX without writing every configuration by hand. This is the relationship that the <a href=\"https:\/\/github.com\/FreePBX\/sng_freepbx_debian_install\">official installer repository<\/a> describes.<\/p>\n<p>There is also a difference between open-source software and a telephone service: installing FreePBX does not provide you with a public number or free external calls. Two local extensions can talk to each other without a carrier; to reach the public telephone network, you will need an appropriate service, such as a hired SIP trunk.<\/p>\n<p>The ecosystem combines open components with <a href=\"https:\/\/www.freepbx.org\/downloads\/\">optional commercial modules<\/a>. So, confirm the license of the desired feature before assuming that a function shown in a demo is included in the basic install.<\/p>\n<h2>What changes in FreePBX 17<\/h2>\n<ul>\n<li><strong>Officially supported base: Debian 12 Bookworm.<\/strong> Don't use Debian 13 or Ubuntu as automatic substitutes for this procedure.<\/li>\n<li><strong>PHP 8.2:<\/strong> is the version used in this generation; don't swap the PHP stack on your own in a production PBX.<\/li>\n<li><strong>Open Bash installer:<\/strong> can be run on a fresh Debian 12, physical or virtual.<\/li>\n<li><strong>Available ISO:<\/strong> automates the Debian installation and the execution of this same installer, instead of constituting a completely independent path.<\/li>\n<li><strong>Asterisk 22 by default currently:<\/strong> release examples may show Asterisk 21, but they don't necessarily represent a fresh installation.<\/li>\n<\/ul>\n<p>These points are listed on the <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/FP\/pages\/222101505\/FreePBX+17\">official FreePBX 17 page<\/a>. The final version, or GA, was made available at <strong>2 August 2024<\/strong>. The <a href=\"https:\/\/raw.githubusercontent.com\/FreePBX\/sng_freepbx_debian_install\/master\/sng_freepbx_debian_install.sh\">current installer code<\/a> confirms Asterisk 22 and PHP 8.2 as defaults and rejects non-Bookworm systems.<\/p>\n<h2>Architecture: panel, extensions, and carrier<\/h2>\n<p>In the lab, two SIP clients register their extensions on Asterisk. The administrator configures the PBX through FreePBX. The trunk with a carrier is a later step: <strong>it is not required for the first internal call<\/strong>.<\/p>\n<figure><img decoding=\"async\" src=\"\/wp-content\/uploads\/2026\/10\/freepbx17-arquitetura.webp\" alt=\"Arquitetura do FreePBX 17 no Debian 12: administra\u00e7\u00e3o web, Asterisk 22, dois ramais PJSIP e tronco SIP opcional.\" width=\"1200\" height=\"705\" loading=\"lazy\"><figcaption>Administration panel and call flow. The example keeps media on the PBX; the SIP trunk is optional.<\/figcaption><\/figure>\n<p><strong>Signaling is not audio.<\/strong> SIP negotiates the call; RTP carries the media. Thus, an extension can register and make the other one ring, but still have no audio if the network is incorrect. The diagram represents media passing through the PBX; direct media settings can change that path.<\/p>\n<p>Going to virtualize? See also <a href=\"\/en\/2026\/09\/a-historia-do-proxmox\/\">the history of Proxmox<\/a> and <a href=\"\/en\/2026\/09\/a-historia-do-virtualbox\/\">the history of VirtualBox<\/a>. To understand the distribution that underpins the PBX, it's worth reading <a href=\"\/en\/2026\/09\/a-historia-de-ian-murdock\/\">the history of Ian Murdock and Debian<\/a>.<\/p>\n<h2>Prepare a separate lab<\/h2>\n<p>A <a href=\"https:\/\/www.freepbx.org\/downloads\/\">official downloads page<\/a> specifies the minimum of <strong>2 GB of RAM and 20 GB of disk<\/strong> for the Debian host or VM 12. This is not a production sizing: simultaneous calls, transcoding, and recordings change the resource requirement.<\/p>\n<p>As a starting point for this small lab, I suggest <strong>2 vCPUs, 4 GB of RAM and 40 GB of disk<\/strong>. It is a lab choice, not a capacity guarantee or an official requirement. Use a dedicated VM, a stable IP address or DHCP reservation, working DNS, and internet access to download the packages.<\/p>\n<p>Leave the VM and both clients on a lab network that allows communication between them. On networks isolated by the hypervisor's NAT, verify connectivity before investigating SIP. Do not place the PBX directly on the internet to simplify the test.<\/p>\n<h2>Option 1: install with the official script<\/h2>\n<p>Use this path on a <strong>freshly installed, dedicated Debian 12<\/strong>. The installer sets up dependencies and repositories: do not run it on the server that already hosts your website, database, or other PBX. Open an administrative session on the VM; the commands below are for it, not for your workstation. If you use SSH, prepare a persistent session with <code data-no-translation=\"\">tmux<\/code> before starting the installation.<\/p>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\"># Na VM Debian 12, abra uma sess\u00e3o root\nsudo -i\n\n# Confira o sistema e a conectividade local\ncat \/etc\/os-release\nip -br address\nip route\n\n# Instale o utilit\u00e1rio de download, se necess\u00e1rio\napt-get update\napt-get install -y wget ca-certificates less tmux\n\n# Abra a sess\u00e3o persistente antes da instala\u00e7\u00e3o\ntmux new -s freepbx<\/code><\/pre>\n<p>Inside the <code data-no-translation=\"\">tmux<\/code>, execute the following block. If the SSH connection drops, log back into the VM, open the root session, and resume with <code data-no-translation=\"\">tmux attach -t freepbx<\/code>.<\/p>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\"># Baixe o instalador oficial, sem execut\u00e1-lo diretamente do download\nwget -O \/tmp\/sng_freepbx_debian_install.sh \\\n  https:\/\/github.com\/FreePBX\/sng_freepbx_debian_install\/raw\/master\/sng_freepbx_debian_install.sh\n\n# Leia o script; pressione q para sair\nless \/tmp\/sng_freepbx_debian_install.sh\n\n# Depois da revis\u00e3o, execute a instala\u00e7\u00e3o\nbash \/tmp\/sng_freepbx_debian_install.sh<\/code><\/pre>\n<p>If your minimal installation does not have <code data-no-translation=\"\">sudo<\/code> or <code data-no-translation=\"\">less<\/code>, use the administrative access configured during the Debian installation and install the necessary utilities. The <a href=\"https:\/\/github.com\/FreePBX\/sng_freepbx_debian_install\">official README<\/a> documents the download and execution as root. Do not add <code data-no-translation=\"\">--testing<\/code> for a normal installation.<\/p>\n<p>If the installer indicates that a newer version exists, download the file again instead of bypassing the check with <code data-no-translation=\"\">--skipversion<\/code>. In another administrative terminal, monitor the most recent file created in <code data-no-translation=\"\">\/var\/log\/pbx\/<\/code>:<\/p>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\">ls -lt \/var\/log\/pbx\/freepbx17-install*.log\n# Use o nome exato listado acima:\n# tail -f \/var\/log\/pbx\/freepbx17-install-DATA-HORA.log<\/code><\/pre>\n<p>A <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/FP\/pages\/230326391\/FreePBX+17+Installation\">installation documentation<\/a> explains the options. <code data-no-translation=\"\">--opensourceonly<\/code> selects only open FreePBX modules; <code data-no-translation=\"\">--dahdi<\/code> is relevant for compatible telephony hardware. Do not add DAHDI in a purely SIP lab without need: the drivers have specific kernel dependencies.<\/p>\n<h2>Option 2: install via ISO<\/h2>\n<p>Prefer to boot a VM from a ready-made media? Get the current link and the SHA-256 at <a href=\"https:\/\/www.freepbx.org\/downloads\/\">download page<\/a>, verify the integrity of the image and follow the <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/FP\/pages\/713326867\/FreePBX+Open+Source+-+Install+v17+with+ISO+Distro\">official ISO guide v17<\/a>. The installation still depends on the network to download components.<\/p>\n<p>Set the VM firmware to <strong>UEFI<\/strong>. The ISO menu offers installation profiles, called <em>spice levels<\/em>. For a SIP-only lab, without physical telephony cards, the guide suggests <strong>Basic \u2192 FOG<\/strong>.<\/p>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\"># No diret\u00f3rio onde voc\u00ea salvou a ISO:\nsha256sum SNGDEB-PBX17-*.iso\n# Compare o resultado com o SHA-256 da mesma imagem no site oficial.<\/code><\/pre>\n<p>The <a href=\"https:\/\/downloads.freepbxdistro.org\/ISO\/\">ISO directory<\/a> also contains historical images. Being available for download does not mean it is still supported. To get started, follow the file indicated on the current page, not an old ISO chosen by name.<\/p>\n<div style=\"background:#fff8e1;border-left:4px solid #8b1a1a;padding:.8em 1em;margin:1em 0\"><strong>Pay attention to the disks:<\/strong> the documentation warns that multiple disks will be incorporated into RAID and that USB sticks of 100 GB or more will be treated as members and wiped. Use a USB media smaller than 100 GB; the guide also reports possible issues with NVMe. For the lab, keep only one empty virtual disk. On physical hardware, disconnect disks that will not be used and read the options before confirming.<\/div>\n<p>ISO v17 disables the root login by default. Depending on the profile, the installation may display a generated password for the user <code data-no-translation=\"\">sangoma<\/code>: if this screen appears, save the password. Follow the guide to set or change the credentials and use <code data-no-translation=\"\">sudo<\/code> for administrative tasks. It is not necessary to resort to GRUB password recovery just because the root login is not available.<\/p>\n<h2>First access and two PJSIP extensions<\/h2>\n<p>Once the installation is complete, open the VM's IP address in the browser on the lab network. Create the administrative credentials and configure secure access. In production, use HTTPS with a valid certificate and restrict administration to the management network or VPN.<\/p>\n<ol>\n<li>In <strong>Applications \u2192 Extensions<\/strong>, choose to add an extension <strong>PJSIP<\/strong>.<\/li>\n<li>Create the extension <strong>1001<\/strong>, with an identification name. Keep the generated <strong>Secret<\/strong> or use another equally strong and unique one. Do not use the number itself as a password.<\/li>\n<li>Repeat the procedure for the extension <strong>1002<\/strong>, with another password.<\/li>\n<li>Save and apply the changes with <strong>Apply Config<\/strong>.<\/li>\n<li>Configure a SIP client for each extension: server\/domain = VM IP; password = the matching Secret. Use the extension number as the username in the default configuration; if there is custom authentication, check the user defined in the PBX. Also verify the port and transport.<\/li>\n<li>With both registered, call from <strong>1001 to 1002<\/strong> and then in the opposite direction. Check the audio on both sides.<\/li>\n<\/ol>\n<p>The extension, caller ID, and password fields are described in the <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/PG\/pages\/22020636\/PBX+GUI+-+Extensions+Module+-+PJSIP+Extension\">PJSIP extensions guide<\/a>. Some screenshots from the wiki belong to earlier versions; follow the PJSIP type, not old tutorials that choose chan_sip.<\/p>\n<p>For a first check from the PBX terminal:<\/p>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\">sudo asterisk -rx 'core show version'\nsudo asterisk -rx 'pjsip show endpoints'\nsudo asterisk -rx 'pjsip show contacts'<\/code><\/pre>\n<p>If you are already root and do not have <code data-no-translation=\"\">sudo<\/code>, skip that prefix. These commands help check the installed Asterisk, the endpoints, and their contacts. The functional proof is still the call being completed with bidirectional audio, not just the presence of the extension in the list.<\/p>\n<h2>Softphones for Debian and Ubuntu<\/h2>\n<p>The MicroSIP shown in the video is an option for Windows. To participate in the same lab from a Linux desktop, you can use one of the SIP clients below. <strong>The client runs on the user's workstation, not on the FreePBX server.<\/strong><\/p>\n<table>\n<thead>\n<tr>\n<th>Client<\/th>\n<th>Profile<\/th>\n<th>How to get<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Linphone<\/strong><\/td>\n<td>Open softphone for audio and video over SIP.<\/td>\n<td><a href=\"https:\/\/www.linphone.org\/en\/download\/\">Official download<\/a>, with AppImage for Linux, or a package <code data-no-translation=\"\">linphone-desktop<\/code> from the distribution when available.<\/td>\n<\/tr>\n<tr>\n<td><strong>Twinkle<\/strong><\/td>\n<td>SIP voice telephony-focused alternative, with transfer and conference.<\/td>\n<td>Package <code data-no-translation=\"\">twinkle<\/code>; check the catalog of <a href=\"https:\/\/packages.debian.org\/bookworm\/twinkle\">Debian 12<\/a> or verify availability on your Ubuntu workstation 24.04 with <code data-no-translation=\"\">apt-cache policy twinkle<\/code>.<\/td>\n<\/tr>\n<tr>\n<td><strong>Blink<\/strong><\/td>\n<td>SIP client with additional communication features.<\/td>\n<td>The <a href=\"https:\/\/icanblink.com\/download\/index.php\">official site<\/a> points Debian and Ubuntu to the <a href=\"https:\/\/packages.ag-projects.com\/\">AG Projects repository<\/a>. Check the support for your version before adding it.<\/td>\n<\/tr>\n<tr>\n<td><strong>GOnnect<\/strong><\/td>\n<td>VoIP client integrated with the desktop, with file-based provisioning and integration with compatible contacts and headsets.<\/td>\n<td><a href=\"https:\/\/github.com\/gonicus\/gonnect\">GONICUS Project<\/a> distributed for Linux via <a href=\"https:\/\/flathub.org\/apps\/de.gonicus.gonnect\">Flathub<\/a>.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>To get started, I would choose the <strong>Linphone available in the station's own repository<\/strong>. The package is documented in <a href=\"https:\/\/packages.debian.org\/bookworm\/linphone-desktop\">Debian 12<\/a> and is available in Ubuntu 24.04; in Ubuntu, it belongs to the Universe component. This does not mean that it will be available in every version of Debian or Ubuntu. Check the candidate before installing:<\/p>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\"># Na esta\u00e7\u00e3o gr\u00e1fica Debian\/Ubuntu, n\u00e3o no servidor PBX\nsudo apt-get update\napt-cache policy linphone-desktop twinkle\n\n# Escolha um cliente com candidato dispon\u00edvel:\nsudo apt-get install linphone-desktop\n# Alternativa, em vez do Linphone:\n# sudo apt-get install twinkle<\/code><\/pre>\n<p>Do not install an <code data-no-translation=\"\">.deb<\/code> of Ubuntu on Debian, nor from another version of the distribution for convenience: the required libraries may be different. The distribution's package may also have an earlier version than the one provided directly by the project.<\/p>\n<p><strong>GOnnect deserves a note:<\/strong> the project was designed for provisioning by file, rather than a wizard to register the SIP account. With Flatpak and the Flathub repository already configured on the station, the installation can be done as follows:<\/p>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\">flatpak install flathub de.gonicus.gonnect<\/code><\/pre>\n<p>Then, adapt the <a href=\"https:\/\/github.com\/gonicus\/gonnect\/blob\/main\/docs\/modules\/ROOT\/examples\/sample.conf\">official example file<\/a> to your extension's credentials and transport and save it in <code data-no-translation=\"\">~\/.var\/app\/de.gonicus.gonnect\/config\/gonnect\/99-user.conf<\/code>, as per the README. See the <a href=\"https:\/\/github.com\/gonicus\/gonnect#overview\">GOnnect guidelines<\/a> before starting and protect the file because it contains credentials. It is not enough to install the application and look for a screen to register the SIP account. Desktop and hardware integrations depend on the environment and the supported devices.<\/p>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\"># Crie o diret\u00f3rio antes de salvar a configura\u00e7\u00e3o adaptada\nmkdir -p ~\/.var\/app\/de.gonicus.gonnect\/config\/gonnect\n# Depois de salvar 99-user.conf com suas credenciais:\nchmod 600 ~\/.var\/app\/de.gonicus.gonnect\/config\/gonnect\/99-user.conf\nflatpak run de.gonicus.gonnect<\/code><\/pre>\n<p><strong>Update (11\/10\/2026) \u2014 experimental AppImage:<\/strong> we contributed the <a href=\"https:\/\/github.com\/gonicus\/gonnect\/pull\/764\">PR #764<\/a> to build GOnnect as an AppImage for Ubuntu 24.04 x86_64. The proposal is still open: it is not an official release nor does it provide a downloadable binary in the PR. Flatpak remains the official distribution indicated above.<\/p>\n<p>In local testing with the initial AppImage build on Ubuntu 24.04 with KDE\/X11 and an EKSA headset, we confirmed a call with two-way audio after selecting the correct devices in GOnnect and using <code data-no-translation=\"\">QT_AUDIO_BACKEND=pulseaudio<\/code>. The tweak selects the PulseAudio interface only for the application, without changing the system default audio. Afterwards, the same pattern was incorporated into the rebuilt AppImage, which passed startup and shutdown tests, but has not yet had a new manual call validated.<\/p>\n<p>It is a result specific to this environment, not a guarantee for other desktops or headsets nor a definitive diagnosis of a failure in Qt\/PipeWire. Refer to the PR for requirements, limitations, and build instructions; SIP credentials and personal settings are not part of the contribution.<\/p>\n<p>If you need the binary distributed by Linphone itself, the <a href=\"https:\/\/download.linphone.org\/releases\/linux\/RELEASE\">official Linux release reference<\/a> consulted for this article points to <a href=\"https:\/\/download.linphone.org\/releases\/linux\/app\/Linphone-6.2.3-x86_64.AppImage\">Linphone 6.2.3 in AppImage x86_64<\/a>. It is an alternative to the native package, not a guarantee of compatibility with any system: check the architecture and version requirements. The <a href=\"https:\/\/github.com\/belledonnecommunications\/linphone-desktop\">indicated GitHub<\/a> contains the source code; the official binaries are on the project's downloads domain.<\/p>\n<p>To access your extensions, configure the SIP account of <strong>your FreePBX<\/strong> in the client: central address, extension number, authentication user and Secret defined previously. There is no need to create an account on the manufacturer's public service to make internal calls between 1001 and 1002.<\/p>\n<p><strong>Network with problematic IPv6?<\/strong> To test HTTP access over IPv4, use <code data-no-translation=\"\">curl -4 -I https:\/\/github.com\/belledonnecommunications\/linphone-desktop<\/code>. In APT, the option <a href=\"https:\/\/manpages.debian.org\/bookworm\/apt\/apt.conf.5.en.html\"><code data-no-translation=\"\">Acquire::ForceIPv4<\/code><\/a> forces downloads over IPv4, without disabling IPv6 on the system:<\/p>\n<pre data-no-translation=\"\"><code class=\"language-bash\" data-no-translation=\"\">sudo apt-get -o Acquire::ForceIPv4=true update\nsudo apt-get -o Acquire::ForceIPv4=true install linphone-desktop<\/code><\/pre>\n<p>Forcing IPv4 alone does not fix a DNS resolver failure. Distinguish a name resolution error, a connection failure, and a SIP authentication error before changing the network or firewall.<\/p>\n<h2>Firewall and NAT: do not solve it by turning off protection<\/h2>\n<p>The SR TECH LAB lab video includes shortcuts to a learning environment. <strong>Do not adopt disabling the firewall as a final configuration.<\/strong> In <strong>Connectivity \u2192 Firewall<\/strong>, register the required hosts and networks, check the zones and preserve an administrative path before applying changes. The <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/PG\/pages\/26148986\/PBX+GUI+-+Firewall+Getting+Started+Guide\">official guide<\/a> warns that leaving an entire interface in the Trusted zone is an incorrect configuration.<\/p>\n<p>The guide informs that new interfaces are added to Trusted by default. <strong>Before changing the interface's zone<\/strong>, register the laboratory network in <strong>Networks<\/strong>, in the appropriate Local or Internal zone, and the admin host\/network with the necessary permissions. The External zone does not allow SIP by default; moving the interface without preparing these rules can disrupt registrations.<\/p>\n<p>For audio problems, review <strong>Settings \u2192 Asterisk SIP Settings<\/strong>: local networks, external address when applicable, codecs, and the RTP range. The <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/PG\/pages\/26542239\/PBX+GUI+-+Asterisk+SIP+Settings+User+Guide\">module documentation<\/a> reports <strong>10000\u201320000\/UDP<\/strong> as the default RTP range; confirm the actual value on your PBX. The SIP port depends on the transport and configuration adopted.<\/p>\n<ul>\n<li><strong>Does not register:<\/strong> check address, user, password, transport, and firewall rules.<\/li>\n<li><strong>It rings, but there is no audio:<\/strong> investigate RTP, NAT, codecs, and advertised addresses.<\/li>\n<li><strong>Only one side hears:<\/strong> check the media path in both directions, including the client firewall.<\/li>\n<\/ul>\n<p>Do not create public forwards for a test between local machines. For remote extensions, consider a VPN. The FreePBX firewall handles configured trunks automatically, according to the guide; this does not eliminate the need to review the <strong>edge firewall, NAT, and cloud rules<\/strong>, allowing only the necessary flows and sources. If using TLS and SRTP, confirm support and configuration on all participants: enabling HTTPS in the panel does not automatically encrypt calls.<\/p>\n<h2>From internal call to SIP trunk<\/h2>\n<p>After the local test, a PBX connected to the public telephone network needs three elements: <strong>trunk<\/strong>, <strong>outbound route<\/strong> and <strong>inbound route<\/strong>. The trunk describes the connection to the carrier; the outbound route defines which numbers will use that connection; the inbound route forwards received calls to an extension, group, queue, or IVR.<\/p>\n<p>Use the parameters provided by the carrier: authentication or IP identification, server, transport, codecs, numbering format, and caller ID. Do not copy addresses and credentials from an example of another provider. Restrict allowed destinations and test real calls before releasing use to users. The <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/PG\/pages\/14417926\/Configuring+Your+PBX\">PBX configuration guide<\/a> is a starting point for navigating the modules.<\/p>\n<h2>Migrating from the old FreePBX requires a new installation<\/h2>\n<p>The documented path for leaving previous versions is <strong>Backup &amp; Restore on a fresh FreePBX 17<\/strong>. There is no direct in-place update from those versions to the 17. This guidance is in the <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/FP\/pages\/230850573\/FreePBX+Open+Source+-+Upgrading+to+FreePBX+17\">official migration guide<\/a>.<\/p>\n<ol>\n<li>Inventory extensions, trunks, routes, recordings, certificates, commercial modules, and customizations.<\/li>\n<li>Generate the backup using the appropriate module and keep a copy off the PBX.<\/li>\n<li>Install FreePBX 17 on another VM. Before restoring, isolate the lab to prevent concurrent registrations on the carrier and unwanted calls.<\/li>\n<li>Restore the backup and review the conversion of chan_sip extensions and trunks to PJSIP.<\/li>\n<li>Revise dialplans and custom scripts, including AGI, that use <code data-no-translation=\"\">Macro()<\/code>; with Asterisk 22, they require adaptation to <code data-no-translation=\"\">Gosub()<\/code>.<\/li>\n<li>Validate the call flows and plan the swap with a maintenance window and rollback procedure.<\/li>\n<\/ol>\n<p><strong>PJSIP is not a new protocol that the carrier needs to invent.<\/strong> It is the SIP stack\/driver used by Asterisk. The <a href=\"https:\/\/docs.asterisk.org\/Configuration\/Channel-Drivers\/SIP\/Configuring-chan_sip\/\">Asterisk documentation<\/a> confirms the removal of chan_sip starting with Asterisk 21. Phones continue to speak SIP, but parameters and behaviors need to be checked during the migration. A completed backup is not the same as an approved restore \u2014 the same distinction discussed in the article about <a href=\"\/en\/2026\/09\/databasus-backup-de-postgresql-mysql-e-mariadb-com-restore-testado\/\">backup with tested restore<\/a>.<\/p>\n<p>The documentation describes the version swap with <code data-no-translation=\"\">asterisk-version-switch<\/code> for legacy transitions, but does not recommend staying on chan_sip. Do not choose an older version without checking its support. For this guide, the target is the default Asterisk 22, with PJSIP and the adapted customizations.<\/p>\n<h2>Support: FreePBX, operating system, and Asterisk<\/h2>\n<p>A <a href=\"https:\/\/sangomakb.atlassian.net\/wiki\/spaces\/FP\/pages\/653197359\/FreePBX+Open+Source+-+FreePBX+Versions\">official version matrix<\/a> lists FreePBX 17 as supported and points to <strong>30 of June 2028<\/strong> as expected EOL. This is the situation consulted for this article, not an immutable promise.<\/p>\n<p>Do not conclude that an old FreePBX is safe just because its modules still receive some maintenance: the matrix distinguishes application support from the SNG7 system, already discontinued. It also presents future versions as <strong>planned<\/strong>. Planning is not an available release. Before deploying or migrating, check the matrix and dependency cycles again.<\/p>\n<p><strong>Do not update the base of a FreePBX 17 PBX from Debian 12 to Debian 13:<\/strong> this combination is not officially supported. Package updates within Bookworm and migration to another distribution version are different operations.<\/p>\n<h2>Videos: practical installation and migration<\/h2>\n<blockquote><p><strong>Video complement \u2014 SR TECH LAB:<\/strong> <a href=\"https:\/\/www.youtube.com\/watch?v=kPqkkYaDJzw\">FreePBX 17 Complete Installation in VMware | PJSIP Extensions &amp; First VoIP Call<\/a>, published on 12 August 2026. It demonstrates a VM, two PJSIP extensions and the first call with MicroSIP. It is a lab, not a security model for production.<\/p><\/blockquote>\n<div class=\"lp-freepbx-video\" style=\"position:relative;width:100%;height:0;padding-bottom:56.25%;overflow:hidden;margin:1.5em 0;\"><iframe width=\"1280\" height=\"720\" style=\"position:absolute;top:0;left:0;width:100%;height:100%;border:0;display:block;\" src=\"https:\/\/www.youtube.com\/embed\/kPqkkYaDJzw\" title=\"FreePBX 17: installation on VMware and first call \u2014 SR TECH LAB\" loading=\"lazy\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen><\/iframe><\/div>\n<blockquote><p><strong>Official webinar \u2014 Sangoma:<\/strong> <a href=\"https:\/\/www.youtube.com\/watch?v=Tr779qSzrH8\">FreePBX 17 Hands-on: Installing &amp; Migrating<\/a>, published on 27 June 2024. It explains installation, PJSIP, switching from Macro to Gosub, and migration by backup and restore. The video predates the August 2024 GA; versions, screens, and feature availability must be cross-checked with current documentation.<\/p><\/blockquote>\n<div class=\"lp-freepbx-video\" style=\"position:relative;width:100%;height:0;padding-bottom:56.25%;overflow:hidden;margin:1.5em 0;\"><iframe width=\"1280\" height=\"720\" style=\"position:absolute;top:0;left:0;width:100%;height:100%;border:0;display:block;\" src=\"https:\/\/www.youtube.com\/embed\/Tr779qSzrH8\" title=\"FreePBX 17: installation and migration \u2014 Sangoma\" loading=\"lazy\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen><\/iframe><\/div>\n<h2>Checklist before going to production<\/h2>\n<ul>\n<li>Debian and modules updated through supported paths, with a backup taken prior to changes.<\/li>\n<li>Administrative access restricted, HTTPS and unique passwords for the panel and extensions.<\/li>\n<li>Active firewall, reviewed zones, and no entire interface set to Trusted for convenience.<\/li>\n<li>Inbound, outbound and internal calls tested with bidirectional audio, transfer and pickup.<\/li>\n<li>Routes limited to the necessary destinations, with alerts and consumption limits on the carrier when available.<\/li>\n<li>Backups protected outside the PBX, rehearsed restore procedure, and retention policy for recordings.<\/li>\n<li>Monitoring of disk, availability, certificates and registration failures.<\/li>\n<\/ul>\n<p>The first goal is simple: <strong>two extensions talking with active protection<\/strong>. The jump to production comes afterwards, with trunks, routes, security and recovery tested. FreePBX makes telephony administration easier; it does not eliminate the responsibility of operating the PBX.<\/p>","protected":false},"excerpt":{"rendered":"<p>Install FreePBX 17 on Debian 12 via script or ISO, create PJSIP extensions, and plan the migration safely with backup and restore.<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,21,2,120],"tags":[535,15,534,537,539,538,536],"class_list":["post-1847","post","type-post","status-publish","format-standard","hentry","category-debian","category-infra","category-linux","category-servidores","tag-asterisk","tag-debian","tag-freepbx","tag-pjsip","tag-sip","tag-telefonia","tag-voip"],"_links":{"self":[{"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/posts\/1847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/comments?post=1847"}],"version-history":[{"count":5,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/posts\/1847\/revisions"}],"predecessor-version":[{"id":1854,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/posts\/1847\/revisions\/1854"}],"wp:attachment":[{"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/media?parent=1847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/categories?post=1847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.linuxpro.com.br\/en\/wp-json\/wp\/v2\/tags?post=1847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}