# Asterisk pjsip_wizard.conf: Endpoints and Trunks in a Few Lines

Source: https://srvscripts.com/guides/asterisk-pjsip-wizard/
Updated: 2026-10-07
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** `pjsip_wizard.conf` (module `res_pjsip_config_wizard`) lets one `type = wizard` section create the endpoint, AOR, auth, identify and registration objects that plain `pjsip.conf` needs separately. Set `accepts_registrations` and `accepts_auth` for phones, `remote_hosts` with `sends_auth` and `sends_registrations` for a registering trunk, or `remote_hosts` alone for an IP-authenticated trunk, and pass any other option with prefixes such as `endpoint/` and `aor/`. It is for plain Asterisk: on FreePBX, define extensions and trunks in the GUI.

We ran the configuration and commands below on our lab server (Debian 12, Asterisk 22.11) on 7 October 2026, on a separate test Asterisk instance bound to 127.0.0.1 with documentation IP addresses for the trunks, so nothing registered to a real provider. We also checked the FreePBX 17.0.33 instance on the same server read-only.

## What the wizard generates

A normal PJSIP phone needs three sections in `pjsip.conf` (endpoint, aor, auth) and a registering trunk needs five or six. The wizard builds them from one section and names them predictably. From the Asterisk documentation, and as we saw on our test instance:

| Object | Name | Created when |
| --- | --- | --- |
| endpoint | same as the wizard section | always |
| aor | same as the wizard section | always; one contact per remote_hosts entry |
| inbound auth | -iauth | accepts_auth = yes |
| outbound auth | -oauth | sends_auth = yes |
| registration | -reg-0, -reg-1… | sends_registrations = yes, one per remote host |
| identify | -identify | remote_hosts is set (not with accepts_registrations) |
| phoneprov | -phoneprov | has_phoneprov = yes |

Every generated object carries an `@pjsip_wizard` attribute with the wizard name, visible in `pjsip show endpoint`, `pjsip show aor` and similar commands. That is how you tell wizard objects from hand-written ones.

Options that do not have a wizard keyword are passed through with a prefix: `endpoint/`, `aor/`, `inbound_auth/`, `outbound_auth/`, `registration/`, `identify/` and `phoneprov/`. So `endpoint/context = from-phones` becomes `context = from-phones` on the endpoint. `config show help res_pjsip_config_wizard wizard` on Asterisk 22.11 lists the wizard keywords:

- `type`, `transport`, `remote_hosts`, `outbound_proxy`

- `sends_auth`, `accepts_auth`, `sends_registrations`, `accepts_registrations`, `sends_line_with_registrations`

- `server_uri_pattern`, `client_uri_pattern`, `contact_pattern`

- `has_phoneprov`, `has_hint`, `hint_context`, `hint_exten`, `hint_application`

## Before you start: transport in pjsip.conf

The wizard does not create transports, `system` or `global` sections. Those stay in `pjsip.conf`, and the module must be loaded (`asterisk -rx "module show like wizard"` should list `res_pjsip_config_wizard.so` as Running).

```
; /etc/asterisk/pjsip.conf
[transport-udp]
type = transport
protocol = udp
bind = 0.0.0.0:5060
```

If the server is behind NAT, add `external_media_address`, `external_signaling_address` and `local_net` to the transport; our [PJSIP NAT generator](/tools/pjsip-nat-generator/) writes them for you.

## Phones: one template, three lines per extension

Templates (a section name followed by `(!)`) hold the shared settings; each phone inherits with `[name](template)`. This is the file we loaded on our test instance, with placeholder passwords:

```
; /etc/asterisk/pjsip_wizard.conf
[phone-defaults](!)
type = wizard
transport = transport-udp
accepts_registrations = yes
accepts_auth = yes
endpoint/context = from-phones
endpoint/disallow = all
endpoint/allow = ulaw,alaw
endpoint/direct_media = no
aor/max_contacts = 1
aor/remove_existing = yes
aor/qualify_frequency = 60

[1001](phone-defaults)
inbound_auth/username = 1001
inbound_auth/password = USE-A-LONG-RANDOM-PASSWORD
endpoint/callerid = "Bob"

[1002](phone-defaults)
inbound_auth/username = 1002
inbound_auth/password = USE-A-LONG-RANDOM-PASSWORD
endpoint/callerid = "Alice"
```

- `accepts_registrations = yes`: the phone registers to Asterisk, so the AOR gets its contact from the REGISTER. No identify object is created.

- `accepts_auth = yes`: creates `1001-iauth` from the `inbound_auth/` lines and sets it as the endpoint’s auth.

- `aor/max_contacts = 1` with `remove_existing = yes`: a new registration replaces the old one instead of being rejected.

- The context `from-phones` must exist in `extensions.conf`. Keep phones and trunks in different contexts so a call from a trunk can never reach your outbound routes.

If you want Asterisk to create hints too, add `has_hint = yes`, `hint_context` and `hint_exten`; the Asterisk documentation shows this pattern.

## ITSP trunks: registration and IP authentication

A trunk wizard uses `remote_hosts`. With registration and outbound authentication:

```
[trunk-defaults](!)
type = wizard
transport = transport-udp
endpoint/context = from-itsp
endpoint/disallow = all
endpoint/allow = ulaw,alaw
aor/qualify_frequency = 60

; provider that wants you to register with a user name and password
[itsp-reg](trunk-defaults)
remote_hosts = 203.0.113.10
sends_auth = yes
sends_registrations = yes
outbound_auth/username = 4420000000
outbound_auth/password = PROVIDER-PASSWORD
registration/expiration = 300
registration/retry_interval = 60

; provider that authenticates you by IP address only
[itsp-ip](trunk-defaults)
remote_hosts = 203.0.113.20
sends_auth = no
sends_registrations = no
```

- `sends_registrations = yes` builds `itsp-reg-reg-0` with `server_uri = sip:203.0.113.10` and `client_uri = sip:4420000000@203.0.113.10`, from the default patterns `sip:${REMOTE_HOST}` and `sip:${USERNAME}@${REMOTE_HOST}`. Change them with `server_uri_pattern` and `client_uri_pattern` if your provider wants a different domain.

- `sends_auth = yes` creates `itsp-reg-oauth` and uses it for both the registration and outbound calls.

- Both trunks get an identify object matching the remote host’s address (`203.0.113.10/32` and `203.0.113.20/32` on our test), so calls from the provider land on the right endpoint and context.

- `remote_hosts` takes a comma-separated list, and a host can include a port (`sip.example.com:5080`). With several hosts you get one contact, one registration and one identify match per host.

- If the provider sends calls from addresses you cannot list, `sends_line_with_registrations = yes` adds the `line` and `endpoint` parameters to the registration so inbound calls can be matched to it.

For the full trunk picture (routes, caller ID, NAT), see [FreePBX PJSIP trunk setup](/guides/freepbx-pjsip-trunk-setup/); the provider side is the same on plain Asterisk.

## Load and reload the wizard

```
asterisk -rx "module reload res_pjsip_config_wizard.so"
```

On our test instance, adding a phone section and running that command printed `Module 'res_pjsip_config_wizard.so' reloaded successfully`, and the new endpoint appeared without a restart. A full `core reload` also re-reads it. Note there is no `pjsip reload` command; Asterisk 22.11 answered “No such command”.

## Check that it worked

`pjsip show endpoints` lists everything the wizard built. From our test instance (no phones registered, trunks pointing at documentation addresses, so all show Unavailable):

```
 Endpoint:  1001/1001                                            Unavailable   0 of inf
     InAuth:  1001-iauth/1001
        Aor:  1001                                               1
  Transport:  transport-udp             udp      0      0  127.0.0.1:5099

 Endpoint:  itsp-ip                                              Unavailable   0 of inf
        Aor:  itsp-ip                                            0
      Contact:  itsp-ip/sip:203.0.113.20                   1e48d23f09 NonQual         nan
  Transport:  transport-udp             udp      0      0  127.0.0.1:5099
   Identify:  itsp-ip-identify/itsp-ip
        Match: 203.0.113.20/32

 Endpoint:  itsp-reg                                             Unavailable   0 of inf
    OutAuth:  itsp-reg-oauth/4420000000
        Aor:  itsp-reg                                           0
      Contact:  itsp-reg/sip:203.0.113.10                  aad5b6aade NonQual         nan
  Transport:  transport-udp             udp      0      0  127.0.0.1:5099
   Identify:  itsp-reg-identify/itsp-reg
        Match: 203.0.113.10/32
```

More checks:

- `pjsip show registrations`: on a real server the trunk should show `Registered`. Ours showed `Rejected`, as expected, because the test transport was bound to 127.0.0.1 and could not reach the documentation address.

- `pjsip show registration itsp-reg-reg-0`: confirms `server_uri`, `client_uri`, `expiration` and `outbound_auth`.

- `pjsip show endpoint 1001`: the `@pjsip_wizard` line, `context`, `allow` and `callerid` should match what you set.

- `pjsip show contacts`: after a phone registers, its contact appears with a status and round-trip time.

- `pjsip show identifies`: one entry per trunk host.

## FreePBX and the wizard

FreePBX writes its own PJSIP files (`pjsip.endpoint.conf`, `pjsip.aor.conf`, `pjsip.auth.conf`, `pjsip.registration.conf` and so on, included from `pjsip.conf`) from the database every time you apply configuration. On our FreePBX 17.0.33 lab, `res_pjsip_config_wizard.so` is loaded and `/etc/asterisk/pjsip_wizard.conf` exists, but it contains only comments.

Do not add extensions or trunks there on a FreePBX system. FreePBX does not know about them: they do not show in the GUI, FreePBX’s dialplan does not treat them as extensions or trunks, and the documentation does not allow a wizard name to collide with an existing object, such as one FreePBX generated. Use Applications > Extensions and Connectivity > Trunks instead. The wizard is the right tool for plain Asterisk builds, such as one installed with our [Asterisk 22 on Debian guide](/guides/install-asterisk-22-debian/).

## Common problems

- **Endpoint missing after reload:** generated objects must pass the same checks as hand-written ones, so an invalid option value can stop one from loading. Look in the Asterisk log for errors naming the wizard section.

- **`accepts_registrations` together with `remote_hosts`:** the documentation says they are mutually exclusive. Use one or the other.

- **Name collision:** a wizard section and a hand-written endpoint, AOR or auth with the same name cannot coexist.

- **Inbound trunk calls rejected as unknown:** the provider sends from an address not in `remote_hosts`. Add the address, or pass extra `identify/match` values.

- **Registration stays Rejected or Unregistered:** check credentials, the provider’s expected client URI and firewall rules; see [SIP error codes](/guides/sip-response-codes/) and [sngrep](/guides/troubleshoot-sip-sngrep/).

**Official documentation:** [Asterisk: PJSIP Configuration Wizard](https://docs.asterisk.org/Configuration/Channel-Drivers/SIP/Configuring-res_pjsip/PJSIP-Configuration-Wizard/) · [Asterisk: res_pjsip_config_wizard reference](https://docs.asterisk.org/Latest_API/API_Documentation/Module_Configuration/res_pjsip_config_wizard/)

**Related:** [chan_sip to PJSIP Migration: sip_to_pjsip.py, Option Mapping, Tests](/guides/chan-sip-to-pjsip-migration/) · [FreePBX PJSIP Trunk Setup: Registration, IP Auth, Routes, NAT](/guides/freepbx-pjsip-trunk-setup/) · [Install Asterisk 22 LTS on Debian 13: Step-by-Step Guide](/guides/install-asterisk-22-debian/) · [PJSIP Endpoint Unreachable or Unavailable: Fix Qualify and NAT](/guides/pjsip-endpoint-unreachable-qualify/) · [PJSIP NAT Settings Generator: Asterisk, FreePBX, Issabel, VitalPBX, 3CX](/tools/pjsip-nat-generator/)

**See also:** [FreePBX PJSIP Trunk Setup: Registration, IP Auth, Routes, NAT](/guides/freepbx-pjsip-trunk-setup/) · [Provision Yealink Phones on FreePBX 17 (Without Commercial EPM)](/guides/yealink-provisioning-freepbx/) · [Asterisk AMI Originate a Call with Python](/guides/asterisk-ami-originate-call-python/)

## Frequently asked questions

### What is pjsip_wizard.conf in Asterisk?

A configuration file read by res_pjsip_config_wizard. Each type = wizard section generates the endpoint, AOR, auth, identify and registration objects you would otherwise write in pjsip.conf.

### How do I reload pjsip_wizard.conf?

Run asterisk -rx “module reload res_pjsip_config_wizard.so”, or core reload. There is no pjsip reload command.

### Can I use pjsip_wizard.conf on FreePBX?

The module is loaded on FreePBX 17, but you should not. FreePBX generates its own PJSIP files and will not know about wizard objects. Use the GUI.

### How do I set endpoint options that the wizard does not have?

Prefix them: endpoint/context, endpoint/allow, aor/max_contacts, registration/expiration and so on are passed straight to the generated object.

### What is the difference between sends_auth and accepts_auth?

sends_auth creates outbound credentials that Asterisk uses towards a provider. accepts_auth creates inbound credentials that phones must use towards Asterisk.
