🖥️ Single Server Installation Guide
Complete step-by-step guide for installing Ring2All PBX on a single server
🏛️ Architecture Diagram
Section titled “🏛️ Architecture Diagram”flowchart TB
subgraph External["External Network"]
Endpoints[SIP Phones & WebRTC Clients]
PSTN[Carrier SIP Trunk Provider]
end
subgraph SingleServer["Single Server Infrastructure (Debian 13)"]
Nginx["Reverse Proxy (Nginx 1.26+ SSL/TLS)"]
subgraph Apps["Web Applications"]
Admin["Ring2All Admin Web (:443)"]
Portal["User Portal (:443/portal)"]
Switch["Switchboard (:443/switchboard)"]
BSS["Ring2All BSS (:443/billing)"]
end
subgraph BackendServices["Backend Services (Node.js 22 & Fastify 5)"]
Api["Platform API (:3000)"]
MonitorApi["Monitoring API (:3001)"]
end
subgraph Telephony["Telephony Core (FreeSWITCH 1.11+)"]
Sofia["Sofia SIP Profile (UDP/TCP/TLS :5060)"]
RTP["RTP Audio Media (UDP 16384-32768)"]
Lua["Lua Routing Engine"]
end
subgraph Data["Database & Storage"]
PG[("PostgreSQL 17 DB Engine")]
Recordings[("Local Audio & Recordings (/var/lib/softswitch)")]
end
end
Endpoints -->|SIP / WebRTC| Sofia
Endpoints -->|HTTPS| Nginx
PSTN -->|SIP Inbound/Outbound| Sofia
PSTN -.->|Audio RTP| RTP
Endpoints -.->|Audio RTP| RTP
Nginx --> Admin
Nginx --> Portal
Nginx --> Switch
Nginx --> BSS
Nginx --> Api
Nginx --> MonitorApi
Admin --> Api
Portal --> Api
Switch --> MonitorApi
BSS --> Api
Api --> PG
MonitorApi --> PG
Telephony --> PG
Telephony --> Recordings
📋 Prerequisites
Section titled “📋 Prerequisites”Hardware Requirements
Section titled “Hardware Requirements”| Component | Minimum | Recommended | High Performance |
|---|---|---|---|
| CPU | 4 vCPU | 8 vCPU | 16+ vCPU |
| RAM | 8 GB | 16 GB | 32+ GB |
| Storage | 100 GB SSD | 250 GB SSD | 500+ GB NVMe |
| Network | 100 Mbps | 1 Gbps | 10 Gbps |
Software Requirements
Section titled “Software Requirements”- Operating System: Debian 13 (Trixie) - 64-bit
- Network: Static IP address configured
- Root Access: Required for installation
Capacity Reference
Section titled “Capacity Reference”| Configuration | Extensions | Concurrent Calls |
|---|---|---|
| Minimum (4 vCPU, 8GB) | ~500 | ~50 |
| Recommended (8 vCPU, 16GB) | ~2,500 | ~400 |
| High Performance (16+ vCPU, 32GB+) | ~10,000 | ~1,500 |
⚡ Option 1: Automated One-Command Installation (Recommended)
Section titled “⚡ Option 1: Automated One-Command Installation (Recommended)”For rapid all-in-one deployment on a clean Debian 13 (Trixie) server, run the official bootstrap installer as root:
wget -O- https://repo.softswitchone.com/apt/install-softswitch.sh | bashWhat this script performs automatically:
Section titled “What this script performs automatically:”- Configures Debian system prerequisites and DNS settings.
- Installs Node.js 22 LTS, PostgreSQL 17, and security packages (
fail2ban,nftables). - Registers the official Ring2All APT repository components (
base,core,devel,extras,audios). - Installs the
softswitch-allorchestrator meta-package, deploying all 10 core packages in correct dependency order. - Bootstraps databases, initializes system DSNs, and starts systemd services.
🛠️ Option 2: Step-by-Step Package Installation
Section titled “🛠️ Option 2: Step-by-Step Package Installation”If you prefer installing individual packages or customizing dependencies:
Step 1: Add Ring2All Repository
Section titled “Step 1: Add Ring2All Repository”# Install prerequisitesapt update && apt install -y curl gnupg2 lsb-release
# Add GPG keymkdir -p /etc/apt/keyringscurl -fsSL https://repo.softswitchone.com/gpg.key | gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg
# Add repositoryecho "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt trixie main" > /etc/apt/sources.list.d/ring2all.list
# Update package listapt update# Install prerequisitesapt update && apt install -y curl gnupg2 lsb-release
# Add GPG keymkdir -p /etc/apt/keyringscurl -fsSL https://repo.softswitchone.com/gpg.key | gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg
# Add repositoryecho "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt bookworm main" > /etc/apt/sources.list.d/ring2all.list
# Update package listapt update# Install prerequisitessudo apt update && sudo apt install -y curl gnupg2 lsb-release
# Add GPG keysudo mkdir -p /etc/apt/keyringscurl -fsSL https://repo.softswitchone.com/gpg.key | sudo gpg --dearmor -o /etc/apt/keyrings/ring2all.gpg
# Add repositoryecho "deb [signed-by=/etc/apt/keyrings/ring2all.gpg] https://repo.softswitchone.com/apt noble main" | sudo tee /etc/apt/sources.list.d/ring2all.list
# Update package listsudo apt updateStep 2: Install Packages
Section titled “Step 2: Install Packages”Quick Method (AIO Meta-Package):
Section titled “Quick Method (AIO Meta-Package):”apt install -y softswitch-allGranular Method (Individual Packages):
Section titled “Granular Method (Individual Packages):”# 1. Database (creates schemas, users, tables)apt install -y softswitch-db
# 2. API Backend & Telemetryapt install -y softswitch-api softswitch-monitoring-api
# 3. Web Frontends (Admin, Portal, Switchboard) & Authoritative Nginx configapt install -y softswitch-admin softswitch-portal softswitch-switchboard
# 4. Telephony Core (FreeSWITCH 1.11+ & Lua Routing)apt install -y softswitch-telephony
# 5. Audio Assets & Multilingual Voice Promptsapt install -y softswitch-music softswitch-voiceguide-emma softswitch-voiceguide-paloma
# 6. (Optional) Ring2All BSS Carrier Billing & Storefront on same nodeapt install -y softswitch-bss-allStep 3: Enable & Start Services
Section titled “Step 3: Enable & Start Services”# Databasesystemctl enable --now postgresql
# Telephony Coresystemctl enable --now freeswitch
# Backend APIssystemctl enable --now softswitch-apisystemctl enable --now softswitch-monitoring-api
# Web Server (Nginx)systemctl enable --now nginxThat’s it! 🎉 Your Ring2All PBX is now running.
✅ Post-Installation Verification
Section titled “✅ Post-Installation Verification”Check Services Status
Section titled “Check Services Status”# All services should show "active (running)"systemctl status postgresqlsystemctl status freeswitchsystemctl status softswitch-apisystemctl status softswitch-monitoring-apisystemctl status nginxCheck Database Connection
Section titled “Check Database Connection”# Read generated credentialscat /etc/softswitch/db-credentials
# Test connection (should show 6 databases)sudo -u postgres psql -c "\l"# Expected: ss_admin, ss_telephony, ss_cdr, ss_cc, ss_logs, freeswitchCheck Telephony Server
Section titled “Check Telephony Server”# Enter Telephony Server CLIfs_cli
# Check status (should show internal and external profiles)sofia status
# Exit/exitAccess Web Interfaces
Section titled “Access Web Interfaces”| Interface | URL | Description |
|---|---|---|
| Admin Dashboard | https://your-server/admin |
System administration |
| User Portal | https://your-server/portal |
End-user self-service |
| Switchboard | https://your-server/switchboard |
Operator console |
Default login: admin / (check setup wizard or database)
🔒 Firewall Configuration
Section titled “🔒 Firewall Configuration”# Allow essential portsufw allow 22/tcp # SSHufw allow 80/tcp # HTTP (redirect to HTTPS)ufw allow 443/tcp # HTTPSufw allow 5060/udp # SIPufw allow 5060/tcp # SIP over TCPufw allow 5061/tcp # SIP TLSufw allow 16384:32768/udp # RTP media
# Enable firewallufw enable🔐 SSL Certificate (Let’s Encrypt)
Section titled “🔐 SSL Certificate (Let’s Encrypt)”# Install certbotapt install certbot python3-certbot-nginx
# Obtain certificate (replace with your domain)certbot --nginx -d pbx.example.com
# Auto-renewal is configured automaticallysystemctl status certbot.timer⚙️ Nginx Configuration
Section titled “⚙️ Nginx Configuration”The softswitch-admin package includes a default Nginx configuration. For customization:
nano /etc/nginx/sites-available/softswitchserver { listen 80; server_name _;
# Redirect all HTTP to HTTPS return 301 https://$host$request_uri;}
server { listen 443 ssl http2; server_name _;
# SSL Certificates ssl_certificate /etc/ssl/certs/softswitch.crt; ssl_certificate_key /etc/ssl/private/softswitch.key;
# Security headers add_header X-Frame-Options "SAMEORIGIN" always; add_header X-Content-Type-Options "nosniff" always;
# API Backend (Node.js) location /api { proxy_pass http://127.0.0.1:3000; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection 'upgrade'; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; }
# WebSocket (Monitoring API) location /ws { proxy_pass http://127.0.0.1:3001; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_read_timeout 86400; }
# Admin Dashboard location /admin { alias /var/www/softswitch/web; try_files $uri $uri/ /admin/index.html; }
# User Portal location /portal { alias /var/www/softswitch/portal; try_files $uri $uri/ /portal/index.html; }
# Switchboard Console location /switchboard { alias /var/www/softswitch/switchboard; try_files $uri $uri/ /switchboard/index.html; }
# Root redirect to Admin location = / { return 302 /admin; }}Apply changes:
ln -sf /etc/nginx/sites-available/softswitch /etc/nginx/sites-enabled/nginx -t && systemctl reload nginx📁 Credentials & Configuration Files
Section titled “📁 Credentials & Configuration Files”| File | Description |
|---|---|
/etc/softswitch/db-credentials |
Database username and password |
/etc/softswitch/api.env |
API environment variables |
/etc/odbc.ini |
ODBC connections for Telephony Server |
/etc/freeswitch/ |
Telephony Server configuration |
View Credentials
Section titled “View Credentials”cat /etc/softswitch/db-credentials# Softswitch Database Credentials# Generated: 2026-01-27 15:00:00DB_USER=ss_db_userDB_PASSWORD=Xk9mN2pQ4rT7DB_HOST=127.0.0.1DB_PORT=5432🔧 Resource Optimization
Section titled “🔧 Resource Optimization”Since all services share the same server, optimize resource allocation:
PostgreSQL Tuning
Section titled “PostgreSQL Tuning”nano /etc/postgresql/17/main/postgresql.conf# Memory (adjust based on available RAM)shared_buffers = 2GB # 25% of RAMeffective_cache_size = 6GB # 75% of RAMwork_mem = 32MBmaintenance_work_mem = 512MB
# Connectionsmax_connections = 200
# WALwal_buffers = 64MBcheckpoint_completion_target = 0.9Telephony Server Tuning
Section titled “Telephony Server Tuning”nano /etc/freeswitch/autoload_configs/switch.conf.xml<configuration name="switch.conf"> <settings> <!-- Limit concurrent sessions based on server capacity --> <param name="max-sessions" value="200"/> <param name="sessions-per-second" value="30"/>
<!-- RTP port range --> <param name="rtp-start-port" value="16384"/> <param name="rtp-end-port" value="32768"/> </settings></configuration>💾 Backup Strategy
Section titled “💾 Backup Strategy”Automated Daily Backup Script
Section titled “Automated Daily Backup Script”Create /opt/softswitch-backup.sh:
#!/bin/bash# Softswitch Single Server Backup Script
BACKUP_DIR="/var/backups/softswitch"DATE=$(date +%Y%m%d_%H%M%S)RETENTION_DAYS=7
mkdir -p $BACKUP_DIR
# Backup all databasesfor db in ss_admin ss_telephony ss_cdr ss_cc ss_logs ss_switchboard; do sudo -u postgres pg_dump $db | gzip > "$BACKUP_DIR/${db}_${DATE}.sql.gz"done
# Backup Telephony Server configstar -czf "$BACKUP_DIR/freeswitch_config_${DATE}.tar.gz" /etc/freeswitch
# Backup recordings (if any)if [ -d "/var/lib/freeswitch/recordings" ]; then tar -czf "$BACKUP_DIR/recordings_${DATE}.tar.gz" /var/lib/freeswitch/recordingsfi
# Backup credentialscp /etc/softswitch/db-credentials "$BACKUP_DIR/db-credentials_${DATE}"
# Remove old backupsfind $BACKUP_DIR -type f -mtime +$RETENTION_DAYS -delete
echo "Backup completed: $BACKUP_DIR"Enable and schedule:
chmod +x /opt/softswitch-backup.sh
# Add to cron (daily at 2 AM)echo "0 2 * * * root /opt/softswitch-backup.sh" >> /etc/crontab🔍 Troubleshooting
Section titled “🔍 Troubleshooting”Service Not Starting
Section titled “Service Not Starting”# Check logsjournalctl -u softswitch-api -fjournalctl -u freeswitch -f
# Check portsss -tlnp | grep -E '3000|3001|5060|5432'Database Connection Issues
Section titled “Database Connection Issues”# Test PostgreSQLsudo -u postgres psql -c "SELECT 1"
# Check ODBCisql -v ss_telephony ss_db_user YOUR_PASSWORDTelephony Server SIP Issues
Section titled “Telephony Server SIP Issues”# Check SIP profilesfs_cli -x "sofia status"
# Check registrationsfs_cli -x "sofia status profile internal reg"
# Debug SIP trafficfs_cli -x "sofia profile internal siptrace on"Nginx 502 Bad Gateway
Section titled “Nginx 502 Bad Gateway”# Check if API is runningcurl http://127.0.0.1:3000/api/health
# Check API logsjournalctl -u softswitch-api --since "5 minutes ago"📈 Scaling Up
Section titled “📈 Scaling Up”When your single server reaches capacity, consider:
- Vertical Scaling: Upgrade CPU/RAM
- Database Separation: Move PostgreSQL to dedicated server
- Distributed Deployment: See Distributed Installation Guide
Capacity Indicators (Time to Scale)
Section titled “Capacity Indicators (Time to Scale)”| Metric | Warning | Critical |
|---|---|---|
| CPU Usage | > 70% sustained | > 85% |
| RAM Usage | > 80% | > 90% |
| Concurrent Calls | > 100 | > 150 |
| Database Connections | > 150 | > 180 |
📊 Installation Summary
Section titled “📊 Installation Summary”| Component | Location | Port |
|---|---|---|
| Admin Dashboard | /var/www/softswitch/web |
443 (/admin) |
| User Portal | /var/www/softswitch/portal |
443 (/portal) |
| Switchboard | /var/www/softswitch/switchboard |
443 (/switchboard) |
| API | /var/www/softswitch/api |
3000 |
| Monitoring WS | /var/www/softswitch/monitoring-api |
3001 |
| PostgreSQL | System service | 5432 |
| Telephony Server | /etc/freeswitch |
5060/5061 |
| Credentials | /etc/softswitch/db-credentials |
- |

