Short answer: pjsip_wizard.conf (module res_pjsip_config_wizard) lets one type = wizard section create the endpoint, AOR, auth, identify and registration objects that plain pjsip.conf needs separately. Set accepts_registrations and accepts_auth for phones, remote_hosts with sends_auth and sends_registrations for a registering trunk, or remote_hosts alone for an IP-authenticated trunk, and pass any other option with prefixes such as endpoint/ and aor/. It is for plain Asterisk: on FreePBX, define extensions and trunks in the GUI.
Applies to Asterisk 22 on Debian 12 (FreePBX 17 notes included)
We ran the configuration and commands below on our lab server (Debian 12, Asterisk 22.11) on 7 October 2026, on a separate test Asterisk instance bound to 127.0.0.1 with documentation IP addresses for the trunks, so nothing registered to a real provider. We also checked the FreePBX 17.0.33 instance on the same server read-only.
Table of Contents
What the wizard generates
A normal PJSIP phone needs three sections in pjsip.conf (endpoint, aor, auth) and a registering trunk needs five or six. The wizard builds them from one section and names them predictably. From the Asterisk documentation, and as we saw on our test instance:
| Object | Name | Created when |
|---|---|---|
| endpoint | same as the wizard section | always |
| aor | same as the wizard section | always; one contact per remote_hosts entry |
| inbound auth | <name>-iauth | accepts_auth = yes |
| outbound auth | <name>-oauth | sends_auth = yes |
| registration | <name>-reg-0, -reg-1… | sends_registrations = yes, one per remote host |
| identify | <name>-identify | remote_hosts is set (not with accepts_registrations) |
| phoneprov | <name>-phoneprov | has_phoneprov = yes |
Every generated object carries an @pjsip_wizard attribute with the wizard name, visible in pjsip show endpoint, pjsip show aor and similar commands. That is how you tell wizard objects from hand-written ones.
Options that do not have a wizard keyword are passed through with a prefix: endpoint/, aor/, inbound_auth/, outbound_auth/, registration/, identify/ and phoneprov/. So endpoint/context = from-phones becomes context = from-phones on the endpoint. config show help res_pjsip_config_wizard wizard on Asterisk 22.11 lists the wizard keywords:
type,transport,remote_hosts,outbound_proxysends_auth,accepts_auth,sends_registrations,accepts_registrations,sends_line_with_registrationsserver_uri_pattern,client_uri_pattern,contact_patternhas_phoneprov,has_hint,hint_context,hint_exten,hint_application
Before you start: transport in pjsip.conf
The wizard does not create transports, system or global sections. Those stay in pjsip.conf, and the module must be loaded (asterisk -rx "module show like wizard" should list res_pjsip_config_wizard.so as Running).
; /etc/asterisk/pjsip.conf
[transport-udp]
type = transport
protocol = udp
bind = 0.0.0.0:5060
If the server is behind NAT, add external_media_address, external_signaling_address and local_net to the transport; our PJSIP NAT generator writes them for you.
Phones: one template, three lines per extension
Templates (a section name followed by (!)) hold the shared settings; each phone inherits with [name](template). This is the file we loaded on our test instance, with placeholder passwords:
; /etc/asterisk/pjsip_wizard.conf
[phone-defaults](!)
type = wizard
transport = transport-udp
accepts_registrations = yes
accepts_auth = yes
endpoint/context = from-phones
endpoint/disallow = all
endpoint/allow = ulaw,alaw
endpoint/direct_media = no
aor/max_contacts = 1
aor/remove_existing = yes
aor/qualify_frequency = 60
[1001](phone-defaults)
inbound_auth/username = 1001
inbound_auth/password = USE-A-LONG-RANDOM-PASSWORD
endpoint/callerid = "Bob" <1001>
[1002](phone-defaults)
inbound_auth/username = 1002
inbound_auth/password = USE-A-LONG-RANDOM-PASSWORD
endpoint/callerid = "Alice" <1002>
accepts_registrations = yes: the phone registers to Asterisk, so the AOR gets its contact from the REGISTER. No identify object is created.accepts_auth = yes: creates1001-iauthfrom theinbound_auth/lines and sets it as the endpoint’s auth.aor/max_contacts = 1withremove_existing = yes: a new registration replaces the old one instead of being rejected.- The context
from-phonesmust exist inextensions.conf. Keep phones and trunks in different contexts so a call from a trunk can never reach your outbound routes.
If you want Asterisk to create hints too, add has_hint = yes, hint_context and hint_exten; the Asterisk documentation shows this pattern.
ITSP trunks: registration and IP authentication
A trunk wizard uses remote_hosts. With registration and outbound authentication:
[trunk-defaults](!)
type = wizard
transport = transport-udp
endpoint/context = from-itsp
endpoint/disallow = all
endpoint/allow = ulaw,alaw
aor/qualify_frequency = 60
; provider that wants you to register with a user name and password
[itsp-reg](trunk-defaults)
remote_hosts = 203.0.113.10
sends_auth = yes
sends_registrations = yes
outbound_auth/username = 4420000000
outbound_auth/password = PROVIDER-PASSWORD
registration/expiration = 300
registration/retry_interval = 60
; provider that authenticates you by IP address only
[itsp-ip](trunk-defaults)
remote_hosts = 203.0.113.20
sends_auth = no
sends_registrations = no
sends_registrations = yesbuildsitsp-reg-reg-0withserver_uri = sip:203.0.113.10andclient_uri = sip:4420000000@203.0.113.10, from the default patternssip:${REMOTE_HOST}andsip:${USERNAME}@${REMOTE_HOST}. Change them withserver_uri_patternandclient_uri_patternif your provider wants a different domain.sends_auth = yescreatesitsp-reg-oauthand uses it for both the registration and outbound calls.- Both trunks get an identify object matching the remote host’s address (
203.0.113.10/32and203.0.113.20/32on our test), so calls from the provider land on the right endpoint and context. remote_hoststakes a comma-separated list, and a host can include a port (sip.example.com:5080). With several hosts you get one contact, one registration and one identify match per host.- If the provider sends calls from addresses you cannot list,
sends_line_with_registrations = yesadds thelineandendpointparameters to the registration so inbound calls can be matched to it.
For the full trunk picture (routes, caller ID, NAT), see FreePBX PJSIP trunk setup; the provider side is the same on plain Asterisk.
Load and reload the wizard
asterisk -rx "module reload res_pjsip_config_wizard.so"
On our test instance, adding a phone section and running that command printed Module 'res_pjsip_config_wizard.so' reloaded successfully, and the new endpoint appeared without a restart. A full core reload also re-reads it. Note there is no pjsip reload command; Asterisk 22.11 answered “No such command”.
Check that it worked
pjsip show endpoints lists everything the wizard built. From our test instance (no phones registered, trunks pointing at documentation addresses, so all show Unavailable):
Endpoint: 1001/1001 Unavailable 0 of inf
InAuth: 1001-iauth/1001
Aor: 1001 1
Transport: transport-udp udp 0 0 127.0.0.1:5099
Endpoint: itsp-ip Unavailable 0 of inf
Aor: itsp-ip 0
Contact: itsp-ip/sip:203.0.113.20 1e48d23f09 NonQual nan
Transport: transport-udp udp 0 0 127.0.0.1:5099
Identify: itsp-ip-identify/itsp-ip
Match: 203.0.113.20/32
Endpoint: itsp-reg Unavailable 0 of inf
OutAuth: itsp-reg-oauth/4420000000
Aor: itsp-reg 0
Contact: itsp-reg/sip:203.0.113.10 aad5b6aade NonQual nan
Transport: transport-udp udp 0 0 127.0.0.1:5099
Identify: itsp-reg-identify/itsp-reg
Match: 203.0.113.10/32
More checks:
pjsip show registrations: on a real server the trunk should showRegistered. Ours showedRejected, as expected, because the test transport was bound to 127.0.0.1 and could not reach the documentation address.pjsip show registration itsp-reg-reg-0: confirmsserver_uri,client_uri,expirationandoutbound_auth.pjsip show endpoint 1001: the@pjsip_wizardline,context,allowandcalleridshould match what you set.pjsip show contacts: after a phone registers, its contact appears with a status and round-trip time.pjsip show identifies: one entry per trunk host.
FreePBX and the wizard
FreePBX writes its own PJSIP files (pjsip.endpoint.conf, pjsip.aor.conf, pjsip.auth.conf, pjsip.registration.conf and so on, included from pjsip.conf) from the database every time you apply configuration. On our FreePBX 17.0.33 lab, res_pjsip_config_wizard.so is loaded and /etc/asterisk/pjsip_wizard.conf exists, but it contains only comments.
Do not add extensions or trunks there on a FreePBX system. FreePBX does not know about them: they do not show in the GUI, FreePBX’s dialplan does not treat them as extensions or trunks, and the documentation does not allow a wizard name to collide with an existing object, such as one FreePBX generated. Use Applications > Extensions and Connectivity > Trunks instead. The wizard is the right tool for plain Asterisk builds, such as one installed with our Asterisk 22 on Debian guide.
Common problems
- Endpoint missing after reload: generated objects must pass the same checks as hand-written ones, so an invalid option value can stop one from loading. Look in the Asterisk log for errors naming the wizard section.
accepts_registrationstogether withremote_hosts: the documentation says they are mutually exclusive. Use one or the other.- Name collision: a wizard section and a hand-written endpoint, AOR or auth with the same name cannot coexist.
- Inbound trunk calls rejected as unknown: the provider sends from an address not in
remote_hosts. Add the address, or pass extraidentify/matchvalues. - Registration stays Rejected or Unregistered: check credentials, the provider’s expected client URI and firewall rules; see SIP error codes and sngrep.
Official documentation: Asterisk: PJSIP Configuration Wizard · Asterisk: res_pjsip_config_wizard reference
Related: chan_sip to PJSIP Migration: sip_to_pjsip.py, Option Mapping, Tests · FreePBX PJSIP Trunk Setup: Registration, IP Auth, Routes, NAT · Install Asterisk 22 LTS on Debian 13: Step-by-Step Guide · PJSIP Endpoint Unreachable or Unavailable: Fix Qualify and NAT · PJSIP NAT Settings Generator: Asterisk, FreePBX, Issabel, VitalPBX, 3CX
See also: FreePBX PJSIP Trunk Setup: Registration, IP Auth, Routes, NAT · Provision Yealink Phones on FreePBX 17 (Without Commercial EPM) · Asterisk AMI Originate a Call with Python
Frequently asked questions
What is pjsip_wizard.conf in Asterisk?
A configuration file read by res_pjsip_config_wizard. Each type = wizard section generates the endpoint, AOR, auth, identify and registration objects you would otherwise write in pjsip.conf.
How do I reload pjsip_wizard.conf?
Run asterisk -rx “module reload res_pjsip_config_wizard.so”, or core reload. There is no pjsip reload command.
Can I use pjsip_wizard.conf on FreePBX?
The module is loaded on FreePBX 17, but you should not. FreePBX generates its own PJSIP files and will not know about wizard objects. Use the GUI.
How do I set endpoint options that the wizard does not have?
Prefix them: endpoint/context, endpoint/allow, aor/max_contacts, registration/expiration and so on are passed straight to the generated object.
What is the difference between sends_auth and accepts_auth?
sends_auth creates outbound credentials that Asterisk uses towards a provider. accepts_auth creates inbound credentials that phones must use towards Asterisk.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- Asterisk 22 on Debian 12 (FreePBX 17 notes included)
- Last full review
- Next review