Emergency server help: get in touch

Install FusionPBX on Debian 12 with the Official Installer

Install FusionPBX on Debian 12 with the official script: review config.sh, what the installer changes, saving the admin login, first hardening steps and checks.

Published 7 min read

Short answer: On a fresh, minimal Debian 12 (or 13) server, as root, run wget -O - https://raw.githubusercontent.com/fusionpbx/fusionpbx-install.sh/master/debian/pre-install.sh | sh, then cd /usr/src/fusionpbx-install.sh/debian && ./install.sh. The script installs FreeSWITCH, PostgreSQL, PHP, nginx, fail2ban and iptables rules, and prints the admin username and a random password at the end. Save that output, reboot, and log in at https://your-server-ip.

Commands checked against the official FusionPBX download page and the installer source on GitHub (linked below) on 6 October 2026; not yet run on our lab servers. Installer defaults change between releases, so re-check resources/config.sh before you run it.

Before you start

  • Fresh server only. The installer removes UFW, flushes iptables and sets its own rules, overwrites /etc/snmp/snmpd.conf and installs a web server. Do not run it on a box that already hosts something.
  • OS: the FusionPBX download page says “Debian 12 or 13 is the recommended operating system. Start with a minimal install.” The installer checks for a 64-bit x86 or ARM system and stops on unsupported CPUs.
  • Size: FreeSWITCH is compiled from source by default, so leave room for the build and expect it to take a while; more CPU cores shorten it.
  • Network: a static IP or a DNS name. SSH access as root (or sudo -i).
  • Console access (hypervisor or provider console) in case the firewall rules cut your SSH session.

Update the base system first:

apt update && apt upgrade -y

Review the installer settings

The one-line command on the download page clones the installer and starts it straight away. If you want to change defaults, split it in two. pre-install.sh only updates packages, installs git and lsb-release and clones the repository into /usr/src/fusionpbx-install.sh:

wget -O - https://raw.githubusercontent.com/fusionpbx/fusionpbx-install.sh/master/debian/pre-install.sh | sh
cd /usr/src/fusionpbx-install.sh/debian
nano resources/config.sh

Settings worth knowing (values from the master branch on 6 October 2026):

SettingDefaultMeaning
domain_nameip_addressFirst FusionPBX domain: the server IP, the hostname, or a custom value
system_username / system_passwordadmin / randomSuperadmin login; random is printed at the end
system_branch5.6FusionPBX version branch (or master)
switch_source / switch_packagetrue / falseCompile FreeSWITCH from source rather than install packages
switch_version1.11FreeSWITCH source version
switch_tokenemptySignalWire personal token, only needed for package installs
database_repo / database_versionofficial / 18PostgreSQL from the official PostgreSQL repository
php_version8.4PHP version
database_backupfalseInstaller database backup option (true or false)

Leave the defaults on a first install unless you have a reason. Then start it:

./install.sh

What the installer does

Reading install.sh tells you what to expect on the server afterwards. In order, it:

  1. Removes any cdrom: lines from /etc/apt/sources.list and upgrades packages.
  2. Installs base tools and snmpd, writing rocommunity public to /etc/snmp/snmpd.conf.
  3. Runs resources/iptables.sh: removes UFW, flushes iptables, and sets a default DROP policy with these inbound allows: TCP 22, 80, 443, 7443; TCP and UDP 5060-5091; UDP 16384-32768 (RTP); UDP 1194; ICMP echo. It also drops SIP packets containing known scanner user agents such as friendly-scanner and sipcli/, and saves the rules with iptables-persistent.
  4. Installs sngrep, PHP, nginx and FusionPBX itself, optional applications, fail2ban with FreeSWITCH and FusionPBX filters, and PostgreSQL.
  5. Builds and installs FreeSWITCH (from source by default).
  6. Runs resources/finish.sh: sets random database passwords, installs daily backup and maintenance cron jobs, creates the domain and superadmin user, and prints the login details.

SNMP: the config line allows read access with the community “public”, but the installer’s firewall does not open UDP 161, so it is not reachable from outside unless you open it. Keep it that way, or remove snmpd if you do not use it.

Expect the FreeSWITCH compile to be the longest step. If the script stops with an error, scroll up to the first failure; community threads on the FusionPBX forum have reported Debian-specific build breaks in the past, and they usually come with a fix.

Save the login details and log in

At the end, finish.sh prints a block like this (your values will differ):

   Use a web browser to login.
      domain name: https://203.0.113.10
      username: admin
      password: <random>

Copy it somewhere safe; the random password is not shown again. Then reboot as the installer asks:

reboot

Browse to https://203.0.113.10 (your IP or domain). The certificate is self-signed at this stage, so accept the browser warning. Log in with the printed username and password. The domain in the browser address is part of the login; to log in to another domain use username@domain.

First configuration and hardening

  1. Change the admin password to one you store in your password manager, and enable two-factor authentication if your FusionPBX version offers it.
  2. Use a real hostname and certificate. Point DNS at the server, then run the bundled Let’s Encrypt helper, which uses dehydrated: /usr/src/fusionpbx-install.sh/debian/resources/letsencrypt.sh. It asks for the domain name and email address.
  3. Tighten the firewall. The default rules accept SIP (5060-5091) from anywhere and SSH from anywhere. Limit SIP to your providers and offices if you can, and limit SSH to admin IPs. Our SIP firewall rules generator writes iptables or nftables rules.
  4. Check fail2ban: fail2ban-client status should list the FreeSWITCH and FusionPBX jails.
  5. Remove UDP 1194 from the rules if you do not run OpenVPN on this server.
  6. Add extensions and a gateway. In FusionPBX, SIP trunks are “Gateways” (Accounts > Gateways), and you create inbound and outbound routes under Dialplan.

Check that it worked

systemctl status freeswitch --no-pager
systemctl status nginx postgresql php*-fpm --no-pager
fs_cli -x "sofia status"
iptables -S | head -30
  • freeswitch, nginx, postgresql and PHP-FPM are active.
  • fs_cli -x "sofia status" lists the SIP profiles (internal and external) as RUNNING.
  • iptables -S shows -P INPUT DROP and the allowed ports above.
  • You can register a softphone to an extension and call between two extensions with audio both ways.

Common problems

  • SSH dropped during install: the firewall step changed rules. Use the provider console; port 22 is allowed by the script, so reconnecting usually works once it finishes.
  • Install stops during the FreeSWITCH build: check disk space (df -h) and memory; small VPS plans can run out while compiling. Re-run after fixing.
  • Web page loads but login fails: wrong domain in the URL. Use the exact domain printed by the installer, or admin@that-domain.
  • One-way audio: NAT. Set the external IP in the SIP profile settings and open UDP 16384-32768. See our one-way audio guide and SIP ALG guide.
  • Port conflicts: the server already ran Apache or another web server; start from a clean install.

Official documentation: FusionPBX download and install · fusionpbx-install.sh (GitHub) · FusionPBX documentation

Related: Install Asterisk 22 LTS on Debian 13: Step-by-Step Guide · Install Issabel 5 on Rocky Linux 8: Simple Step-by-Step PBX Setup · SIP Firewall Rules Generator: iptables, nftables, UFW, firewalld, CSF and pfSense · SIP Ports Firewall Rules: 4 Setups for CSF, firewalld and pfSense · VoIP One-Way Audio Fix: 6 Checks for NAT and RTP

See also: 3CX vs FreePBX: Licensing, Hosting, Features and Lock-in (2026)

Frequently asked questions

Which Debian version does FusionPBX support?

The official download page recommends Debian 12 or 13, starting from a minimal install.

Where do I find the FusionPBX admin password after install?

The installer prints the domain, username and a random password at the end. Save it before rebooting; it is not shown again.

Does the FusionPBX installer configure a firewall?

Yes. It removes UFW, flushes iptables and sets a default DROP policy with SSH, web, SIP 5060-5091 and RTP 16384-32768 allowed, then saves the rules.

Does FusionPBX compile FreeSWITCH from source?

By default, yes: switch_source is true in resources/config.sh. Package installs need a SignalWire token in switch_token.

How do I add a Let’s Encrypt certificate to FusionPBX?

Point DNS at the server and run resources/letsencrypt.sh from the installer folder. It uses dehydrated and asks for the domain and email.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.