
Overview
FreePBX gives IT administrators at small and mid-sized businesses a production-ready IP-PBX on AWS with streamlined one-click deployment. Built on Asterisk - the world's most widely deployed open source PBX - this AMI delivers a complete, pre-configured communications stack that is operational and monitorable from its first boot. Take full control of your business phone system without the recurring costs of hosted PBX services.
What Is Included?
This image delivers a complete FreePBX and Asterisk stack that is installed, permission-fixed, and tuned with AWS-native integrations already configured:
- FreePBX and Asterisk Pre-configured - Asterisk built and running as the dedicated asterisk user with correct ownership of all configuration, library, and log directories. FreePBX framework installed with core, voicemail, SIP settings, PM2, and UCP modules. Apache configured to run as asterisk with AllowOverride and mod_rewrite enabled. PHP upload_max_filesize and memory_limit raised for module installation.
- Amazon CloudWatch Integration - CloudWatch agent installed and enabled with a ready-made configuration that ships Asterisk, FreePBX, Apache, syslog, and auth logs to CloudWatch Logs (30-day retention). Publishes CPU, memory, disk, TCP connection, and process metrics under the SolveDevOps/FreePBX namespace with InstanceId, InstanceType, and AutoScalingGroupName dimensions.
- AWS Systems Manager Integration - SSM agent installed and enabled so the instance can be reached with Session Manager, patched with Patch Manager, and managed with Run Command without opening inbound SSH.
- Full Root Access - Complete control over FreePBX sources in /opt/freepbx and Asterisk configuration in /etc/asterisk.
Who Is This For?
This AMI is built for IT managers and system administrators at organizations with 10 to 200 extensions who need to:
- Replace expensive hosted PBX services with a self-managed solution
- Interconnect branch offices and remote workers onto a unified voice platform
- Deploy call center queues, IVR menus, conferencing, and voicemail
- Maintain full ownership of call data and recordings for compliance
- Monitor VoIP infrastructure using native AWS observability tools
Example Use Case: A 50-seat professional services firm connects three branch offices and remote workers using softphones. Inbound calls route through a multi-level IVR to department queues, with call recording enabled for compliance. CloudWatch dashboards provide real-time visibility into call server health, while Systems Manager handles patching without SSH access.
Key Capabilities
- Point-and-Click WebGUI - Manage extensions, ring groups, IVR trees, and call routing from any browser without command-line expertise.
- Broad Phone Compatibility - Works with Cisco, Avaya, Polycom, Yealink, and popular softphones including Zoiper and Linphone.
- Sangoma Commercial Plugin Support - Expand functionality with advanced modules for endpoint management, call center wallboards, and more.
- Simple Backup and Restore - Built-in backup module lets you schedule automated backups and restore configurations with a few clicks.
- Hassle-Free Upgrades - Stay current with the latest features and security patches through the integrated module update system.
Security and Hardening
This image ships with multiple layers of protection pre-configured:
- SSH Key-Only Authentication - Root login disabled, no pre-set admin or database passwords baked into the image. Build-time SSH keys and cloud-init state scrubbed so every launch starts clean.
- Pre-configured Firewall - Responsive firewall restricts access to SIP, HTTP, and SSH ports, blocking unauthorized traffic by default.
- Fail2ban Integration - Automatically bans IP addresses after repeated failed authentication attempts, protecting against SIP brute-force attacks.
- Debian Hardened Base - Built on Debian with unnecessary services disabled and the latest security patches applied at image build time.
- HTTPS for WebGUI - TLS encryption available for administrative access to prevent credential interception.
Note: This product contains the latest patched software from respective vendors. We do not claim that all vulnerabilities have been addressed.
Getting Started
- Subscribe - Click the subscribe button to begin deployment.
- Configure - Select your instance size and attach an IAM instance role that includes CloudWatchAgentServerPolicy and AmazonSSMManagedInstanceCore managed policies.
- Launch - Deploy your server. Initial provisioning completes in approximately five minutes. The agents start automatically and detect the Region at boot.
- Access - Navigate to http://your-instance-ip/admin in your browser. The login message of the day shows the admin URL, source locations, log paths, and CloudWatch namespace.
Highlights
- Easy to deploy (1-Click deploy)
- Latest versions of FreePBX and Asterisk included
- 1-Click Sangoma Commercial Plugin Activation and Broad Device Support: Activate Sangoma commercial modules directly from the FreePBX web GUI. The image supports SIP-compatible soft and hard phones from Cisco, Avaya, and other vendors. Core modules including voicemail, SIP settings, PM2, and UCP are pre-installed, and Apache is configured with mod_rewrite and raised PHP limits for seamless module installation.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.