Emergency server help: get in touch

Asterisk and FreePBX Toll Fraud Prevention: 10-Point Checklist

A 10-point toll-fraud checklist for Asterisk and FreePBX: SIP allow-lists, passwords, outbound patterns, channel limits, working fail2ban, alerts and incident steps.

Published 8 min read

Short answer: Toll fraud happens when someone places calls through your trunks, usually to expensive international or premium numbers, often overnight. Stop it in layers: SIP reachable only from known IPs, long random SIP and voicemail passwords, no wide-open outbound patterns, international calling blocked or PIN-protected, per-trunk channel limits, fail2ban that actually reads the right log, provider-side spend limits, and an alert when an international call goes out.

We ran the Asterisk and FreePBX commands below on our lab server (Debian 12, FreePBX 17.0.33 open source, Asterisk 22.11) on 6 October 2026, and took FreePBX field names from its module code. Dialplan advice follows the Asterisk project’s security documentation (linked below).

How toll fraud usually happens

Most incidents follow one of a few paths. Knowing which one you are defending against tells you which control matters most:

  • Guessed SIP credentials. Scanners send REGISTER attempts for common extension numbers with weak passwords. One success gives them a “phone” on your PBX.
  • Open or over-broad dialplan. An inbound context that reaches outbound routes, anonymous SIP calls allowed into the wrong context, or a _X. pattern passed straight to Dial().
  • Remote access features. DISA, call-back, follow-me to external numbers and voicemail “call back” options with weak PINs.
  • Admin interface compromise. An exposed web GUI with a weak password lets an attacker create their own extension or route.
  • Stolen provisioning files. Phone config files served over HTTP or TFTP to the internet contain SIP passwords.

The checklist below covers each path. Work through it in order; the first four items prevent most incidents.

1-3: Close the network doors

1. Allow SIP only from known IPs

A SIP port open to the whole internet is scanned within minutes. Allow 5060/udp (and any TCP/TLS ports) only from your providers’ signalling IPs and your office networks. Keep RTP (10000-20000/udp on FreePBX by default) open as needed. Remote phones should use a VPN or come from fixed IPs. Our SIP firewall rules generator writes rules for nftables, iptables, UFW, firewalld, CSF and pfSense.

2. Lock down the web GUI and provisioning

Restrict the FreePBX admin GUI to admin networks or a VPN. Never serve phone provisioning (HTTP, HTTPS or TFTP) to the internet without authentication: those files hold SIP passwords. Sangoma’s own security post says provisioning should “never” be enabled for the internet zone.

3. Refuse anonymous and guest SIP calls

In FreePBX, open Settings > Asterisk SIP Settings and set Allow Anonymous Inbound SIP Calls and Allow SIP Guests to No unless you have a specific need. On plain Asterisk, make sure no anonymous endpoint exists and that unauthenticated requests do not land in a context with outbound access.

Check what is knocking on the door:

asterisk -rx "pjsip show unidentified_requests"

4-5: Credentials and PINs

4. Long random SIP passwords

The Asterisk best-practices file recommends passwords with at least 12 characters mixing upper and lower case, numbers and symbols, and warns that many compromises start from a forgotten test extension with a weak password. Use generated secrets of 16 or more characters for every extension and trunk. Never set a secret to the extension number or “1234”.

5. Voicemail PINs, DISA and call-back features

  • Voicemail PINs: 6+ digits, not the extension number, not 1234 or 0000.
  • DISA: disable it unless needed. If you use it, set a long PIN, restrict the Context (FreePBX labels it “Experts Only” and defaults to from-internal, which can reach every outbound route), and record its use.
  • Follow-me and call forwarding to external numbers: review who can forward off-net; forwarded calls use your trunks.
  • Remove any test extensions and demo contexts before go-live.

6-7: Outbound routes and dial patterns

6. No catch-all patterns to your trunk

The Asterisk documentation’s rule is to keep toll services in contexts that untrusted callers cannot reach. In FreePBX terms:

  • Build outbound routes with specific patterns (for example NXXNXXXXXX and 1NXXNXXXXXX for North America) rather than a single X. route.
  • Put international dialling (011. or 00.) in its own route, placed last, and protect it with a Route Password or remove it if nobody needs it.
  • Do not create routes for premium-rate prefixes in your country. Ask your provider which ranges are premium.
  • Mark the emergency route with Emergency Route and test it, but never leave a fallback route that accepts anything.
  • Use the Custom Contexts module (installed on FreePBX 17) to give limited extensions, such as lobby phones, only local routes.

In your own dialplan, never pass an unfiltered ${EXTEN} from a wildcard pattern into Dial(). The Asterisk best-practices file shows how 500&PJSIP/itsp/14165551212 sent as a dialled string turns one call into two. Use ${FILTER(0-9,${EXTEN})} or a strict pattern. Our dialplan pattern matching guide shows how to test which pattern a number hits:

asterisk -rx "dialplan show 011442071234567@from-internal"

7. Limit concurrent calls

Fraud runs many calls in parallel. Cap that:

  • FreePBX trunks have a Maximum Channels field; set it to your real need, not blank.
  • Ask your provider for a channel limit and a daily spend cap on the account. This is the control that still works if the PBX is fully compromised.
  • In custom dialplan, GROUP() and GROUP_COUNT() (both present on Asterisk 22) can cap international calls per extension or system-wide.

Size real needs with our Erlang calculator so limits do not block normal traffic.

8: fail2ban that actually works

fail2ban bans IPs that keep failing authentication. It only works if Asterisk writes the log file the jail watches. On our open-source-only FreePBX 17 lab, the installed asterisk-iptables jail read /var/log/asterisk/fail2ban, but Asterisk was not writing that file, so the jail counted nothing. We fixed it with a logger channel:

echo "fail2ban => notice,security" >> /etc/asterisk/logger_logfiles_custom.conf
asterisk -rx "logger reload"
fail2ban-client status asterisk-iptables

Within minutes the jail showed failures and bans. The lab’s jail settings were maxretry 5, findtime 600 and bantime 1800 seconds; long-running scanners justify a longer ban plus the recidive jail. Full setup: fail2ban for Asterisk and FreePBX. If you run FreePBX with commercial modules, the Firewall module’s Responsive Firewall and Intrusion Detection add similar protection; see Responsive Firewall vs Intrusion Detection.

PJSIP also raises a security event when one IP sends many unidentified requests. The defaults in Asterisk 22 are unidentified_request_count=5 within unidentified_request_period=5 seconds (global settings), which fail2ban can act on through the security log.

9-10: Alerts and updates

9. Get told when an international call goes out

FreePBX 17 outbound routes have a Notifications tab with Email To and a Notification when choice: “Call successful” (after answer) or “Dial pattern matched” (as soon as the pattern matches). Turn it on for the international route; the GUI itself warns not to enable it on high-traffic routes.

Independently of the GUI, a short cron job can watch the CDR database. This query ran on our lab (FreePBX keeps CDRs in asteriskcdrdb.cdr):

mysql asteriskcdrdb -e "SELECT calldate, src, dst, disposition, billsec FROM cdr
  WHERE calldate > NOW() - INTERVAL 1 HOUR AND (dst LIKE '011%' OR dst LIKE '00%')
  ORDER BY calldate DESC"

Mail the result when it is not empty, and alert on unusual volume at night or weekends. Also alert on provider-side spend if your provider offers it.

10. Keep it patched and check module signatures

Update FreePBX modules and Asterisk regularly. fwconsole ma list shows a Signature column for each module; on our lab every Sangoma module showed Sangoma. A module that suddenly shows as unsigned or tampered needs investigating.

If you think you are being defrauded

  1. Disable the trunk now: fwconsole trunks --list, then fwconsole trunks --disable=<id>, or block outbound at the provider.
  2. Hang up active calls: asterisk -rx "core show channels", then channel request hangup <channel> for each fraudulent one.
  3. Call your provider and ask them to block international calling on the account.
  4. Find the source: CDR src field and channel names show which extension or trunk carried the calls; /var/log/asterisk/full shows registrations.
  5. Change every SIP password and voicemail PIN, remove unknown extensions, review the GUI admin users, then re-enable the trunk.

Official documentation: Asterisk: Dialplan Security · Asterisk best practices (README-SERIOUSLY) · FreePBX: A Secure FreePBX is a Happy FreePBX

Related: fail2ban for Asterisk and FreePBX: Block SIP Password Guessing · SIP Firewall Rules Generator: iptables, nftables, UFW, firewalld, CSF and pfSense · SIP Ports Firewall Rules: 4 Setups for CSF, firewalld and pfSense · Erlang Calculator: How Many SIP Channels (Erlang B) or Call Centre Agents (Erlang C) · AI fail2ban Regex Generator: Filters and Jails from Log Lines

See also: Upgrade FreePBX 16 to 17: Backup, Restore and Migration Checklist · Install FreePBX 17 on Debian 12 (Open-Source Only, Tested) · FreePBX Responsive Firewall vs Intrusion Detection (FreePBX 17) · 3CX vs FreePBX: Licensing, Hosting, Features and Lock-in (2026)

Frequently asked questions

What is VoIP toll fraud?

Someone uses your PBX or SIP trunk to place calls you pay for, usually to international or premium-rate numbers. It often starts with a guessed SIP password or an open dialplan.

Is fail2ban enough to stop toll fraud?

No. It slows password guessing, but restricting SIP to known IPs, strong passwords, tight outbound routes and provider spend limits matter more.

How do I block international calls in FreePBX?

Remove or password-protect the outbound route with 011 or 00 patterns, and make sure no catch-all route sends other numbers to the trunk. Ask your provider to block international calling too.

Should I disable DISA?

Yes, unless you need it. If you keep it, use a long PIN, restrict its context and record its use, because DISA gives dial tone to outside callers.

What should I do first if fraud is happening now?

Disable the trunk or block calls at the provider, hang up active calls, then find the source and change credentials.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.