Emergency server help: get in touch

Install Asterisk 22 LTS on Debian 13: Step-by-Step Guide

Build Asterisk 22 LTS from source on Debian 13, run it as a non-root service, register two PJSIP phones, add a simple dialplan and lock down the SIP and RTP ports.

Published Updated 5 min read

This guide shows how to install Asterisk 22 LTS on Debian 13 from source and make the first call between two softphones. Asterisk is the open-source PBX engine behind FreePBX, Issabel and many hosted phone systems. Asterisk 22 is the current long-term support branch, released in October 2024 and supported until October 2029, so it is the right choice for a new server. Asterisk 20 LTS moves to security-fix-only status in October 2026.

Short answer: On a fresh Debian 13 server, download asterisk-22-current.tar.gz, run contrib/scripts/install_prereq install, then ./configure --with-jansson-bundled, make menuselect, make && make install && make samples && make config. Create an asterisk user, set it in asterisk.conf, start the service, add PJSIP endpoints and a dialplan, and open UDP 5060 plus the RTP range only to trusted networks.

Before you start

ItemRecommendation
ServerDebian 13 minimal install, 2 vCPU, 2–4 GB RAM, 20 GB disk for a small office
NetworkStatic IP; if behind NAT, a known public IP or DNS name
AccessSSH as a sudo user; run the commands below as root
PhonesTwo SIP softphones or desk phones for testing

Step 1: update and download the source

apt update && apt -y full-upgrade
apt -y install wget build-essential
cd /usr/src
wget https://downloads.asterisk.org/pub/telephony/asterisk/asterisk-22-current.tar.gz
tar xzf asterisk-22-current.tar.gz
cd asterisk-22.*/

Step 2: install build dependencies

Asterisk ships a script that installs every package it needs for the detected distribution:

contrib/scripts/install_prereq install
contrib/scripts/get_mp3_source.sh     # optional: MP3 music on hold

The script ends with “install completed successfully”. If it asks for a country code, enter your ITU-T country calling code.

Step 3: configure, choose modules and build

./configure --with-jansson-bundled
make menuselect

In menuselect, keep the defaults and add what you need: format_mp3 under Add-ons if you downloaded the MP3 source, extra sound packs (for example CORE-SOUNDS-EN-WAV and MOH-OPSOUND-WAV) and codecs. chan_sip no longer exists in Asterisk 21 and later; PJSIP (chan_pjsip) is the SIP channel driver. Save and exit with x, then build:

make -j"$(nproc)"
make install
make samples       # sample configs in /etc/asterisk (useful as reference)
make config        # installs the systemd/init service
make install-logrotate
ldconfig

Step 4: run Asterisk as a non-root user

groupadd asterisk
useradd -r -d /var/lib/asterisk -g asterisk asterisk
usermod -aG audio,dialout asterisk
chown -R asterisk:asterisk /etc/asterisk /var/{lib,log,spool}/asterisk /usr/lib/asterisk
sed -i 's/^;runuser = asterisk/runuser = asterisk/; s/^;rungroup = asterisk/rungroup = asterisk/' /etc/asterisk/asterisk.conf
systemctl enable --now asterisk
asterisk -rvvv

The console prompt shows the running version. Type core show version to confirm it reads Asterisk 22, and exit to leave the console without stopping the service.

Step 5: create two PJSIP extensions

Keep the sample file for reference and start a clean /etc/asterisk/pjsip.conf:

mv /etc/asterisk/pjsip.conf /etc/asterisk/pjsip.conf.sample
cat > /etc/asterisk/pjsip.conf <<'EOF'
[transport-udp]
type=transport
protocol=udp
bind=0.0.0.0:5060
; behind NAT, uncomment and set your addresses
;external_media_address=203.0.113.10
;external_signaling_address=203.0.113.10
;local_net=192.168.1.0/24

[endpoint-template](!)
type=endpoint
context=internal
disallow=all
allow=g722,ulaw,alaw
direct_media=no
rtp_symmetric=yes
force_rport=yes
rewrite_contact=yes

[1001](endpoint-template)
auth=1001-auth
aors=1001
[1001-auth]
type=auth
auth_type=userpass
username=1001
password=ChangeMe-Long-Random-1
[1001]
type=aor
max_contacts=2

[1002](endpoint-template)
auth=1002-auth
aors=1002
[1002-auth]
type=auth
auth_type=userpass
username=1002
password=ChangeMe-Long-Random-2
[1002]
type=aor
max_contacts=2
EOF

Use long random passwords. SIP scanners try weak extension passwords within minutes of a server going online.

Step 6: a minimal dialplan

mv /etc/asterisk/extensions.conf /etc/asterisk/extensions.conf.sample
cat > /etc/asterisk/extensions.conf <<'EOF'
[internal]
exten => _10XX,1,NoOp(Internal call to ${EXTEN})
 same => n,Dial(PJSIP/${EXTEN},30)
 same => n,Hangup()

exten => 600,1,Answer()
 same => n,Playback(demo-echotest)
 same => n,Echo()
 same => n,Hangup()
EOF
chown asterisk:asterisk /etc/asterisk/*.conf
asterisk -rx "core reload"
asterisk -rx "pjsip show endpoints"

Register one softphone as 1001 and another as 1002 to the server IP on port 5060. Dial 600 for the echo test, then call 1002 from 1001. If calls connect with no audio, work through the one-way audio guide; it is almost always NAT or the RTP range.

Step 7: firewall and security

Asterisk uses UDP 5060 for SIP signalling and UDP 10000–20000 for RTP media by default (set in rtp.conf). Allow SIP only from your office network and SIP trunk provider where possible. An example with nftables, assuming an existing inet filter table with an input chain:

apt -y install nftables fail2ban
nft add rule inet filter input ip saddr 198.51.100.0/24 udp dport 5060 accept
nft add rule inet filter input udp dport 10000-20000 accept

Enable the asterisk jail in fail2ban so repeated failed registrations are banned, and never let unauthenticated inbound calls land in a context that can dial out. Add an outbound SIP trunk only after these rules are in place.

Install Asterisk 22 at a glance

Install Asterisk 22 LTS on Debian 13 summary card: On a fresh Debian 13 server, download asterisk-22-current.tar.gz, run contrib/scripts/install_prereq install, then…
In short: On a fresh Debian 13 server, download asterisk-22-current.tar.gz, run contrib/scripts/install_prereq install, then ./configure –with-jansson-bundled, make menuselect, make && make install && make samples && make config.

Official documentation: Asterisk documentation, Asterisk downloads.

Related guides: SIP ports and firewall rules · Fix one-way audio on VoIP calls · Disable SIP ALG on your router.

Frequently asked questions

Which Asterisk version should I install in 2026?

Asterisk 22 LTS for new servers. It is supported until October 2029. Asterisk 23 is a standard release with a shorter support window, and Asterisk 24 LTS is due in mid-October 2026.

Why is chan_sip missing?

chan_sip was deprecated for years and removed in Asterisk 21. Use chan_pjsip with pjsip.conf; the sip_to_pjsip conversion script in contrib/scripts can turn an old sip.conf into a starting point.

Do I need FreePBX to use Asterisk?

No. Asterisk runs with plain text configuration files as shown here. FreePBX or Issabel add a web interface on top, which suits teams that prefer not to edit configuration files.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.