Emergency server help: get in touch

Asterisk pjsip_wizard.conf: Endpoints and Trunks in a Few Lines

Use Asterisk pjsip_wizard.conf to define phones and ITSP trunks in a few lines: templates, registration and IP-auth trunks, reload and checks. Tested on Asterisk 22.

Published 8 min read

Short answer: pjsip_wizard.conf (module res_pjsip_config_wizard) lets one type = wizard section create the endpoint, AOR, auth, identify and registration objects that plain pjsip.conf needs separately. Set accepts_registrations and accepts_auth for phones, remote_hosts with sends_auth and sends_registrations for a registering trunk, or remote_hosts alone for an IP-authenticated trunk, and pass any other option with prefixes such as endpoint/ and aor/. It is for plain Asterisk: on FreePBX, define extensions and trunks in the GUI.

Applies to Asterisk 22 on Debian 12 (FreePBX 17 notes included)

We ran the configuration and commands below on our lab server (Debian 12, Asterisk 22.11) on 7 October 2026, on a separate test Asterisk instance bound to 127.0.0.1 with documentation IP addresses for the trunks, so nothing registered to a real provider. We also checked the FreePBX 17.0.33 instance on the same server read-only.

What the wizard generates

A normal PJSIP phone needs three sections in pjsip.conf (endpoint, aor, auth) and a registering trunk needs five or six. The wizard builds them from one section and names them predictably. From the Asterisk documentation, and as we saw on our test instance:

ObjectNameCreated when
endpointsame as the wizard sectionalways
aorsame as the wizard sectionalways; one contact per remote_hosts entry
inbound auth<name>-iauthaccepts_auth = yes
outbound auth<name>-oauthsends_auth = yes
registration<name>-reg-0, -reg-1…sends_registrations = yes, one per remote host
identify<name>-identifyremote_hosts is set (not with accepts_registrations)
phoneprov<name>-phoneprovhas_phoneprov = yes

Every generated object carries an @pjsip_wizard attribute with the wizard name, visible in pjsip show endpoint, pjsip show aor and similar commands. That is how you tell wizard objects from hand-written ones.

Options that do not have a wizard keyword are passed through with a prefix: endpoint/, aor/, inbound_auth/, outbound_auth/, registration/, identify/ and phoneprov/. So endpoint/context = from-phones becomes context = from-phones on the endpoint. config show help res_pjsip_config_wizard wizard on Asterisk 22.11 lists the wizard keywords:

  • type, transport, remote_hosts, outbound_proxy
  • sends_auth, accepts_auth, sends_registrations, accepts_registrations, sends_line_with_registrations
  • server_uri_pattern, client_uri_pattern, contact_pattern
  • has_phoneprov, has_hint, hint_context, hint_exten, hint_application

Before you start: transport in pjsip.conf

The wizard does not create transports, system or global sections. Those stay in pjsip.conf, and the module must be loaded (asterisk -rx "module show like wizard" should list res_pjsip_config_wizard.so as Running).

; /etc/asterisk/pjsip.conf
[transport-udp]
type = transport
protocol = udp
bind = 0.0.0.0:5060

If the server is behind NAT, add external_media_address, external_signaling_address and local_net to the transport; our PJSIP NAT generator writes them for you.

Phones: one template, three lines per extension

Templates (a section name followed by (!)) hold the shared settings; each phone inherits with [name](template). This is the file we loaded on our test instance, with placeholder passwords:

; /etc/asterisk/pjsip_wizard.conf
[phone-defaults](!)
type = wizard
transport = transport-udp
accepts_registrations = yes
accepts_auth = yes
endpoint/context = from-phones
endpoint/disallow = all
endpoint/allow = ulaw,alaw
endpoint/direct_media = no
aor/max_contacts = 1
aor/remove_existing = yes
aor/qualify_frequency = 60

[1001](phone-defaults)
inbound_auth/username = 1001
inbound_auth/password = USE-A-LONG-RANDOM-PASSWORD
endpoint/callerid = "Bob" <1001>

[1002](phone-defaults)
inbound_auth/username = 1002
inbound_auth/password = USE-A-LONG-RANDOM-PASSWORD
endpoint/callerid = "Alice" <1002>
  • accepts_registrations = yes: the phone registers to Asterisk, so the AOR gets its contact from the REGISTER. No identify object is created.
  • accepts_auth = yes: creates 1001-iauth from the inbound_auth/ lines and sets it as the endpoint’s auth.
  • aor/max_contacts = 1 with remove_existing = yes: a new registration replaces the old one instead of being rejected.
  • The context from-phones must exist in extensions.conf. Keep phones and trunks in different contexts so a call from a trunk can never reach your outbound routes.

If you want Asterisk to create hints too, add has_hint = yes, hint_context and hint_exten; the Asterisk documentation shows this pattern.

ITSP trunks: registration and IP authentication

A trunk wizard uses remote_hosts. With registration and outbound authentication:

[trunk-defaults](!)
type = wizard
transport = transport-udp
endpoint/context = from-itsp
endpoint/disallow = all
endpoint/allow = ulaw,alaw
aor/qualify_frequency = 60

; provider that wants you to register with a user name and password
[itsp-reg](trunk-defaults)
remote_hosts = 203.0.113.10
sends_auth = yes
sends_registrations = yes
outbound_auth/username = 4420000000
outbound_auth/password = PROVIDER-PASSWORD
registration/expiration = 300
registration/retry_interval = 60

; provider that authenticates you by IP address only
[itsp-ip](trunk-defaults)
remote_hosts = 203.0.113.20
sends_auth = no
sends_registrations = no
  • sends_registrations = yes builds itsp-reg-reg-0 with server_uri = sip:203.0.113.10 and client_uri = sip:4420000000@203.0.113.10, from the default patterns sip:${REMOTE_HOST} and sip:${USERNAME}@${REMOTE_HOST}. Change them with server_uri_pattern and client_uri_pattern if your provider wants a different domain.
  • sends_auth = yes creates itsp-reg-oauth and uses it for both the registration and outbound calls.
  • Both trunks get an identify object matching the remote host’s address (203.0.113.10/32 and 203.0.113.20/32 on our test), so calls from the provider land on the right endpoint and context.
  • remote_hosts takes a comma-separated list, and a host can include a port (sip.example.com:5080). With several hosts you get one contact, one registration and one identify match per host.
  • If the provider sends calls from addresses you cannot list, sends_line_with_registrations = yes adds the line and endpoint parameters to the registration so inbound calls can be matched to it.

For the full trunk picture (routes, caller ID, NAT), see FreePBX PJSIP trunk setup; the provider side is the same on plain Asterisk.

Load and reload the wizard

asterisk -rx "module reload res_pjsip_config_wizard.so"

On our test instance, adding a phone section and running that command printed Module 'res_pjsip_config_wizard.so' reloaded successfully, and the new endpoint appeared without a restart. A full core reload also re-reads it. Note there is no pjsip reload command; Asterisk 22.11 answered “No such command”.

Check that it worked

pjsip show endpoints lists everything the wizard built. From our test instance (no phones registered, trunks pointing at documentation addresses, so all show Unavailable):

 Endpoint:  1001/1001                                            Unavailable   0 of inf
     InAuth:  1001-iauth/1001
        Aor:  1001                                               1
  Transport:  transport-udp             udp      0      0  127.0.0.1:5099

 Endpoint:  itsp-ip                                              Unavailable   0 of inf
        Aor:  itsp-ip                                            0
      Contact:  itsp-ip/sip:203.0.113.20                   1e48d23f09 NonQual         nan
  Transport:  transport-udp             udp      0      0  127.0.0.1:5099
   Identify:  itsp-ip-identify/itsp-ip
        Match: 203.0.113.20/32

 Endpoint:  itsp-reg                                             Unavailable   0 of inf
    OutAuth:  itsp-reg-oauth/4420000000
        Aor:  itsp-reg                                           0
      Contact:  itsp-reg/sip:203.0.113.10                  aad5b6aade NonQual         nan
  Transport:  transport-udp             udp      0      0  127.0.0.1:5099
   Identify:  itsp-reg-identify/itsp-reg
        Match: 203.0.113.10/32

More checks:

  • pjsip show registrations: on a real server the trunk should show Registered. Ours showed Rejected, as expected, because the test transport was bound to 127.0.0.1 and could not reach the documentation address.
  • pjsip show registration itsp-reg-reg-0: confirms server_uri, client_uri, expiration and outbound_auth.
  • pjsip show endpoint 1001: the @pjsip_wizard line, context, allow and callerid should match what you set.
  • pjsip show contacts: after a phone registers, its contact appears with a status and round-trip time.
  • pjsip show identifies: one entry per trunk host.

FreePBX and the wizard

FreePBX writes its own PJSIP files (pjsip.endpoint.conf, pjsip.aor.conf, pjsip.auth.conf, pjsip.registration.conf and so on, included from pjsip.conf) from the database every time you apply configuration. On our FreePBX 17.0.33 lab, res_pjsip_config_wizard.so is loaded and /etc/asterisk/pjsip_wizard.conf exists, but it contains only comments.

Do not add extensions or trunks there on a FreePBX system. FreePBX does not know about them: they do not show in the GUI, FreePBX’s dialplan does not treat them as extensions or trunks, and the documentation does not allow a wizard name to collide with an existing object, such as one FreePBX generated. Use Applications > Extensions and Connectivity > Trunks instead. The wizard is the right tool for plain Asterisk builds, such as one installed with our Asterisk 22 on Debian guide.

Common problems

  • Endpoint missing after reload: generated objects must pass the same checks as hand-written ones, so an invalid option value can stop one from loading. Look in the Asterisk log for errors naming the wizard section.
  • accepts_registrations together with remote_hosts: the documentation says they are mutually exclusive. Use one or the other.
  • Name collision: a wizard section and a hand-written endpoint, AOR or auth with the same name cannot coexist.
  • Inbound trunk calls rejected as unknown: the provider sends from an address not in remote_hosts. Add the address, or pass extra identify/match values.
  • Registration stays Rejected or Unregistered: check credentials, the provider’s expected client URI and firewall rules; see SIP error codes and sngrep.

Official documentation: Asterisk: PJSIP Configuration Wizard · Asterisk: res_pjsip_config_wizard reference

Related: chan_sip to PJSIP Migration: sip_to_pjsip.py, Option Mapping, Tests · FreePBX PJSIP Trunk Setup: Registration, IP Auth, Routes, NAT · Install Asterisk 22 LTS on Debian 13: Step-by-Step Guide · PJSIP Endpoint Unreachable or Unavailable: Fix Qualify and NAT · PJSIP NAT Settings Generator: Asterisk, FreePBX, Issabel, VitalPBX, 3CX

See also: FreePBX PJSIP Trunk Setup: Registration, IP Auth, Routes, NAT · Provision Yealink Phones on FreePBX 17 (Without Commercial EPM) · Asterisk AMI Originate a Call with Python

Frequently asked questions

What is pjsip_wizard.conf in Asterisk?

A configuration file read by res_pjsip_config_wizard. Each type = wizard section generates the endpoint, AOR, auth, identify and registration objects you would otherwise write in pjsip.conf.

How do I reload pjsip_wizard.conf?

Run asterisk -rx “module reload res_pjsip_config_wizard.so”, or core reload. There is no pjsip reload command.

Can I use pjsip_wizard.conf on FreePBX?

The module is loaded on FreePBX 17, but you should not. FreePBX generates its own PJSIP files and will not know about wizard objects. Use the GUI.

How do I set endpoint options that the wizard does not have?

Prefix them: endpoint/context, endpoint/allow, aor/max_contacts, registration/expiration and so on are passed straight to the generated object.

What is the difference between sends_auth and accepts_auth?

sends_auth creates outbound credentials that Asterisk uses towards a provider. accepts_auth creates inbound credentials that phones must use towards Asterisk.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
Asterisk 22 on Debian 12 (FreePBX 17 notes included)
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.