Emergency server help: get in touch

Upgrade FreePBX 16 to 17: Backup, Restore and Migration Checklist

Move from FreePBX 16 (SNG7) to FreePBX 17 (Debian 12) with backup and restore: CLI restore options, chan_sip conversion, licences and a cut-over checklist.

Published Updated 8 min read

Short answer: There is no in-place upgrade from FreePBX 16 to 17. FreePBX 16 runs on CentOS 7/SNG7, FreePBX 17 on Debian 12, so you build a new Debian 12 server, take a full backup with the Backup & Restore module on 16, copy it across and restore it with fwconsole backup --restore=/path/to/backup.tar.gz. Plan for what does not carry over cleanly: chan_sip (Asterisk 22 has none), custom Macro() dialplan, commercial module licences (move the Deployment ID) and anything you set up at OS level.

Applies to FreePBX 16 (SNG7) to FreePBX 17 on Debian 12; tested on FreePBX 17.0.33 with Asterisk 22.11

We ran the fwconsole commands below on our lab server (Debian 12, FreePBX 17.0.33, Asterisk 22.11) on 6 October 2026 to confirm their options. The full 16-to-17 restore follows Sangoma’s documentation (linked below); we have not yet run it end to end on our lab.

Why FreePBX 16 to 17 is a migration, not an upgrade

Sangoma’s upgrade page is direct about it: the supported path is backup on FreePBX 15 or 16, a fresh FreePBX 17 install, then restore. Three things change at once:

  • Operating system: CentOS 7 based SNG7 to Debian 12. Packages, paths for system services, and the firewall stack all differ.
  • Asterisk: FreePBX 17 installs Asterisk 22 by default. Asterisk 22 has no chan_sip driver and no Macro() application.
  • Hardware fingerprint: a new server means commercial licences tied to the old one must be moved.

Because the old server keeps running until you cut over, this is also your rollback plan: if the new box misbehaves, point phones and trunks back at the old one.

Before you start: inventory the FreePBX 16 server

Collect this while the old system is still live. Most migration surprises come from items nobody wrote down.

  1. Versions: FreePBX and Asterisk version (fwconsole -V, asterisk -rx "core show version"). Update all modules on 16 first (fwconsole ma upgradeall) so the backup format is current.
  2. chan_sip use: list chan_sip extensions and trunks in the GUI (Applications > Extensions and Connectivity > Trunks show the technology).
  3. Custom dialplan: grep -n "Macro(" /etc/asterisk/extensions_custom.conf and any AGI scripts. These must be rewritten to Gosub().
  4. Commercial modules: note each one (System Admin Pro, EndPoint Manager, Call Recording Reports and so on) and confirm each has a FreePBX 17 release before you commit to a date.
  5. Network facts: public IP, hostname, NAT settings, provider IP allow-lists that include your current IP, and the IPs phones are provisioned with.
  6. Things outside FreePBX: crontabs, custom scripts, SSH keys, mail relay settings, VPNs, monitoring agents, TLS certificates obtained outside Certificate Manager.

Inventory the old PBX’s NAT settings with our PJSIP NAT generator in mind: if the public IP changes, external address and provider allow-lists must change too.

Take the backup on FreePBX 16

In the FreePBX 16 GUI, go to Admin > Backup & Restore and create a backup job that includes all modules. Run it, then download the resulting .tar.gz or copy it from the backup storage location. From the shell you can run an existing job by ID:

fwconsole backup --list
fwconsole backup --backup=<backup-job-id>

Copy the file to the new server with scp or rsync. Check its size and keep a second copy off both servers. Do not change the old system after this point, or take a fresh backup just before cut-over.

Call recordings and voicemail can make the backup very large. If you include them, plan disk space on the new server for the backup file plus the restored data, and expect the restore to take a long time.

Build the FreePBX 17 server

Install Debian 12 and FreePBX 17 using Sangoma’s install script; our draft guide Install FreePBX 17 on Debian 12 walks through it. Two choices matter for a migration:

  • Commercial modules or open source only. The install script has an --opensourceonly option. With it, the script removes commercial modules and also removes the Firewall module, because Firewall depends on the commercial System Admin module. If you relied on the FreePBX Firewall or System Admin on 16, install without that option.
  • Same version line for Asterisk. If you cannot convert chan_sip or Macro dialplan in time, Sangoma documents switching Asterisk to a version below 21 before restoring. Treat that as temporary: Asterisk 20 goes security-fix-only on 19 October 2026.

Update all modules on the new server before restoring (fwconsole ma upgradeall, then fwconsole reload).

Restore the backup on FreePBX 17

The GUI restore works for small backups. Sangoma recommends the CLI for large ones, because the browser can time out. Run it as the asterisk user:

sudo -u asterisk fwconsole backup --restore=/var/spool/asterisk/backup/restore-xxxxxx.tar.gz

If /tmp is small, point temporary files somewhere with space, as Sangoma’s documentation shows:

sudo -u asterisk TMPDIR=/var/spool/asterisk/tmp fwconsole backup --restore=/var/spool/asterisk/backup/restore-xxxxxx.tar.gz

fwconsole backup --help on our FreePBX 17.0.33 lab lists options that are useful in a migration:

OptionUse it when
--convertchansipexts2pjsipConvert chan_sip extensions to PJSIP during the restore
--convertchansiptrunks2pjsipConvert chan_sip trunks to PJSIP during the restore
--skipchansipexts / --skipchansiptrunksLeave chan_sip extensions or trunks out and rebuild them by hand
--skipbindportKeep the new server’s SIP bind ports instead of the old ones
--skipremotenatDo not restore the old NAT (external IP, local networks) settings
--skipdnsDo not restore DNS settings
--skiptrunksandroutesRestore everything except trunks and routes (useful for a staged test)
--ignoremodules=Skip named modules
--restorelegacycdrAlso restore CDR data from a legacy backup

In the GUI, if the backup contains chan_sip devices, Sangoma’s documentation says the restore pauses and offers to convert them to PJSIP or cancel. A typical migration command, converting both and keeping the new server’s NAT settings, looks like this:

sudo -u asterisk fwconsole backup --restore=/var/spool/asterisk/backup/restore-xxxxxx.tar.gz \
  --convertchansipexts2pjsip --convertchansiptrunks2pjsip --skipremotenat
fwconsole reload

Review the converted trunks in Connectivity > Trunks afterwards. Converted settings are a starting point; see our chan_sip to PJSIP migration guide for what to check.

What does not carry over

ItemWhat happensWhat to do
chan_sip extensions and trunksNo chan_sip in Asterisk 22Convert during restore, or with fwconsole convert2pjsip and fwconsole trunks --convert2pjsip
Macro() in custom dialplan or AGIAsterisk 22 has no app_macroRewrite to Gosub() before or right after the restore
Commercial module licencesLicences are locked to the old hardwareReset the hardware lock on the Deployment ID in the Sangoma portal, then register the new server
System Admin and Firewall settingsAbsent on an open-source-only installInstall with commercial modules, or replace with your own firewall and fail2ban
OS-level setupNot part of a FreePBX backupRecreate crontabs, scripts, SSH keys, monitoring by hand
Phones registered by IPStill point at the old serverRe-provision, or move the old IP or DNS name to the new server
Provider IP allow-listsOld public IP onlyAsk providers to add the new IP before cut-over

For licences, Sangoma’s “How to Move a Deployment ID to a new PBX” page describes the steps: in portal.sangoma.com open the deployment, use Reset Hardware Lock on the License tab, then register the Deployment ID on the new server. The portal allows two resets per deployment; after that you have to ask Sangoma support. Do the reset only when you are ready to move.

Cut-over checklist and verification

  1. Restore finished without errors; run fwconsole reload and fwconsole ma list to confirm modules are enabled.
  2. asterisk -rx "pjsip show registrations" shows each provider Registered (IP-authenticated trunks will not appear here; test them with a call).
  3. Set NAT in Settings > Asterisk SIP Settings: External Address and Local Networks for the new server.
  4. Move phones: pjsip show contacts should list each phone as Avail.
  5. Test inbound to an IVR, ring group and queue; outbound local, long distance and emergency route (if your provider supports test calls).
  6. Check voicemail to email, call recording and CDR Reports playback.
  7. Check fail2ban-client status and your firewall rules; see our fail2ban for Asterisk and FreePBX guide.
  8. Take a first FreePBX 17 backup and confirm it completes.
  9. Keep the FreePBX 16 server powered but disconnected from trunks for a week as a fallback.

Common problems after the restore:

  • Trunk registers but calls fail with 403: the provider still allow-lists only the old IP.
  • No audio on external calls: NAT settings restored from the old server, or not set at all. Use --skipremotenat and set them fresh.
  • Custom feature stops working: look for Macro( in /etc/asterisk/extensions_custom.conf and Asterisk log lines about an unknown application.
  • Commercial module shows unlicensed: the Deployment ID still holds the old hardware lock.

Official documentation: Sangoma: Upgrading to FreePBX 17 · Sangoma: Move a Deployment ID to a new PBX · Asterisk versions and EOL dates

Related: Migrate PBX to Cloud: 8-Step Plan From 3CX or Asterisk · PJSIP Behind NAT: Asterisk and FreePBX Settings for Two-Way Audio · fail2ban for Asterisk and FreePBX: Block SIP Password Guessing · PJSIP NAT Settings Generator: Asterisk, FreePBX, Issabel, VitalPBX, 3CX · SIP Ports Firewall Rules: 4 Setups for CSF, firewalld and pfSense

See also: Install FreePBX 17 on Debian 12 (Open-Source Only, Tested) · FreePBX Responsive Firewall vs Intrusion Detection (FreePBX 17) · Asterisk and FreePBX Toll Fraud Prevention: 10-Point Checklist · 3CX vs FreePBX: Licensing, Hosting, Features and Lock-in (2026)

See also: FreePBX Backup and Restore from the Command Line (fwconsole)

Frequently asked questions

Can I upgrade FreePBX 16 to 17 in place?

No. FreePBX 16 runs on CentOS 7/SNG7 and FreePBX 17 on Debian 12, so Sangoma documents backup on 16, fresh install of 17, then restore.

What happens to chan_sip extensions when I restore on FreePBX 17?

Asterisk 22 has no chan_sip. Convert them during the restore with –convertchansipexts2pjsip and –convertchansiptrunks2pjsip, or skip them and rebuild them as PJSIP.

Do commercial module licences move automatically?

No. Reset the hardware lock on the Deployment ID in the Sangoma portal and register the new server. The portal allows two resets per deployment.

Why is the Firewall module missing after I installed FreePBX 17?

The install script’s –opensourceonly option removes commercial modules and also the Firewall module, because Firewall depends on the commercial System Admin module.

Should I restore from the GUI or the CLI?

The CLI, for anything large. Sangoma recommends sudo -u asterisk fwconsole backup –restore=/path/file.tar.gz because the GUI can time out.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
FreePBX 16 (SNG7) to FreePBX 17 on Debian 12; tested on FreePBX 17.0.33 with Asterisk 22.11
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.