Short answer: On a fresh, minimal Debian 12 (or 13) server, as root, run wget -O - https://raw.githubusercontent.com/fusionpbx/fusionpbx-install.sh/master/debian/pre-install.sh | sh, then cd /usr/src/fusionpbx-install.sh/debian && ./install.sh. The script installs FreeSWITCH, PostgreSQL, PHP, nginx, fail2ban and iptables rules, and prints the admin username and a random password at the end. Save that output, reboot, and log in at https://your-server-ip.
Commands checked against the official FusionPBX download page and the installer source on GitHub (linked below) on 6 October 2026; not yet run on our lab servers. Installer defaults change between releases, so re-check resources/config.sh before you run it.
Table of Contents
Before you start
- Fresh server only. The installer removes UFW, flushes iptables and sets its own rules, overwrites
/etc/snmp/snmpd.confand installs a web server. Do not run it on a box that already hosts something. - OS: the FusionPBX download page says “Debian 12 or 13 is the recommended operating system. Start with a minimal install.” The installer checks for a 64-bit x86 or ARM system and stops on unsupported CPUs.
- Size: FreeSWITCH is compiled from source by default, so leave room for the build and expect it to take a while; more CPU cores shorten it.
- Network: a static IP or a DNS name. SSH access as root (or
sudo -i). - Console access (hypervisor or provider console) in case the firewall rules cut your SSH session.
Update the base system first:
apt update && apt upgrade -y
Review the installer settings
The one-line command on the download page clones the installer and starts it straight away. If you want to change defaults, split it in two. pre-install.sh only updates packages, installs git and lsb-release and clones the repository into /usr/src/fusionpbx-install.sh:
wget -O - https://raw.githubusercontent.com/fusionpbx/fusionpbx-install.sh/master/debian/pre-install.sh | sh
cd /usr/src/fusionpbx-install.sh/debian
nano resources/config.sh
Settings worth knowing (values from the master branch on 6 October 2026):
| Setting | Default | Meaning |
|---|---|---|
domain_name | ip_address | First FusionPBX domain: the server IP, the hostname, or a custom value |
system_username / system_password | admin / random | Superadmin login; random is printed at the end |
system_branch | 5.6 | FusionPBX version branch (or master) |
switch_source / switch_package | true / false | Compile FreeSWITCH from source rather than install packages |
switch_version | 1.11 | FreeSWITCH source version |
switch_token | empty | SignalWire personal token, only needed for package installs |
database_repo / database_version | official / 18 | PostgreSQL from the official PostgreSQL repository |
php_version | 8.4 | PHP version |
database_backup | false | Installer database backup option (true or false) |
Leave the defaults on a first install unless you have a reason. Then start it:
./install.sh
What the installer does
Reading install.sh tells you what to expect on the server afterwards. In order, it:
- Removes any
cdrom:lines from/etc/apt/sources.listand upgrades packages. - Installs base tools and
snmpd, writingrocommunity publicto/etc/snmp/snmpd.conf. - Runs
resources/iptables.sh: removes UFW, flushes iptables, and sets a default DROP policy with these inbound allows: TCP 22, 80, 443, 7443; TCP and UDP 5060-5091; UDP 16384-32768 (RTP); UDP 1194; ICMP echo. It also drops SIP packets containing known scanner user agents such asfriendly-scannerandsipcli/, and saves the rules withiptables-persistent. - Installs sngrep, PHP, nginx and FusionPBX itself, optional applications, fail2ban with FreeSWITCH and FusionPBX filters, and PostgreSQL.
- Builds and installs FreeSWITCH (from source by default).
- Runs
resources/finish.sh: sets random database passwords, installs daily backup and maintenance cron jobs, creates the domain and superadmin user, and prints the login details.
SNMP: the config line allows read access with the community “public”, but the installer’s firewall does not open UDP 161, so it is not reachable from outside unless you open it. Keep it that way, or remove snmpd if you do not use it.
Expect the FreeSWITCH compile to be the longest step. If the script stops with an error, scroll up to the first failure; community threads on the FusionPBX forum have reported Debian-specific build breaks in the past, and they usually come with a fix.
Save the login details and log in
At the end, finish.sh prints a block like this (your values will differ):
Use a web browser to login.
domain name: https://203.0.113.10
username: admin
password: <random>
Copy it somewhere safe; the random password is not shown again. Then reboot as the installer asks:
reboot
Browse to https://203.0.113.10 (your IP or domain). The certificate is self-signed at this stage, so accept the browser warning. Log in with the printed username and password. The domain in the browser address is part of the login; to log in to another domain use username@domain.
First configuration and hardening
- Change the admin password to one you store in your password manager, and enable two-factor authentication if your FusionPBX version offers it.
- Use a real hostname and certificate. Point DNS at the server, then run the bundled Let’s Encrypt helper, which uses dehydrated:
/usr/src/fusionpbx-install.sh/debian/resources/letsencrypt.sh. It asks for the domain name and email address. - Tighten the firewall. The default rules accept SIP (5060-5091) from anywhere and SSH from anywhere. Limit SIP to your providers and offices if you can, and limit SSH to admin IPs. Our SIP firewall rules generator writes iptables or nftables rules.
- Check fail2ban:
fail2ban-client statusshould list the FreeSWITCH and FusionPBX jails. - Remove UDP 1194 from the rules if you do not run OpenVPN on this server.
- Add extensions and a gateway. In FusionPBX, SIP trunks are “Gateways” (Accounts > Gateways), and you create inbound and outbound routes under Dialplan.
Check that it worked
systemctl status freeswitch --no-pager
systemctl status nginx postgresql php*-fpm --no-pager
fs_cli -x "sofia status"
iptables -S | head -30
freeswitch,nginx,postgresqland PHP-FPM are active.fs_cli -x "sofia status"lists the SIP profiles (internal and external) as RUNNING.iptables -Sshows-P INPUT DROPand the allowed ports above.- You can register a softphone to an extension and call between two extensions with audio both ways.
Common problems
- SSH dropped during install: the firewall step changed rules. Use the provider console; port 22 is allowed by the script, so reconnecting usually works once it finishes.
- Install stops during the FreeSWITCH build: check disk space (
df -h) and memory; small VPS plans can run out while compiling. Re-run after fixing. - Web page loads but login fails: wrong domain in the URL. Use the exact domain printed by the installer, or
admin@that-domain. - One-way audio: NAT. Set the external IP in the SIP profile settings and open UDP 16384-32768. See our one-way audio guide and SIP ALG guide.
- Port conflicts: the server already ran Apache or another web server; start from a clean install.
Official documentation: FusionPBX download and install · fusionpbx-install.sh (GitHub) · FusionPBX documentation
Related: Install Asterisk 22 LTS on Debian 13: Step-by-Step Guide · Install Issabel 5 on Rocky Linux 8: Simple Step-by-Step PBX Setup · SIP Firewall Rules Generator: iptables, nftables, UFW, firewalld, CSF and pfSense · SIP Ports Firewall Rules: 4 Setups for CSF, firewalld and pfSense · VoIP One-Way Audio Fix: 6 Checks for NAT and RTP
See also: 3CX vs FreePBX: Licensing, Hosting, Features and Lock-in (2026)
Frequently asked questions
Which Debian version does FusionPBX support?
The official download page recommends Debian 12 or 13, starting from a minimal install.
Where do I find the FusionPBX admin password after install?
The installer prints the domain, username and a random password at the end. Save it before rebooting; it is not shown again.
Does the FusionPBX installer configure a firewall?
Yes. It removes UFW, flushes iptables and sets a default DROP policy with SSH, web, SIP 5060-5091 and RTP 16384-32768 allowed, then saves the rules.
Does FusionPBX compile FreeSWITCH from source?
By default, yes: switch_source is true in resources/config.sh. Package installs need a SignalWire token in switch_token.
How do I add a Let’s Encrypt certificate to FusionPBX?
Point DNS at the server and run resources/letsencrypt.sh from the installer folder. It uses dehydrated and asks for the domain and email.