Problem: Calls via FQDN work "sometimes" because STUN-only mode fails behind strict NAT (cellular, Proton VPN, hotel WiFi, corporate firewalls). STUN tells clients their public IP, but can't relay media when direct UDP paths are blocked. TURN relays media as a fallback. Changes: coturn (docker-compose.yml): - Upgraded from STUN-only to full STUN+TURN relay - Uses long-term credential mechanism (--lt-cred-mech) - Credentials shared between coturn and Asterisk automatically - Relay port range 49152-49252 (configurable, ~50 concurrent relayed calls) - Always-on (removed --profile stun gate) - Conditional --external-ip (only set when PUBLIC_IP is provided) Entrypoint (docker/entrypoint.sh): - Auto-detects public IP (ifconfig.me → icanhazip.com → api.ipify.org) - Auto-generates TURN password on first startup (saved to config) - Configures rtp.conf with icesupport + stunaddr + turnaddr + credentials - Updates pjsip.conf external_*_address if public IP changes - Always enables ICE, STUN, and TURN for Docker deployments Main script (easy-asterisk-v0.10.0.sh): - Added TURN_ENABLED, TURN_SERVER, TURN_USERNAME, TURN_PASSWORD to load_config/save_config - repair_core_configs: rtp.conf now includes turnaddr/turnusername/turnpassword when TURN is enabled - Bash device creation: Docker mode defaults to FQDN (TLS) for all new devices - Python device creation: reads TURN_ENABLED, auto-selects FQDN in Docker - Main menu shows TURN status .env.example: - Comprehensive documentation for every setting - DOMAIN_NAME is the only required setting - Port forwarding requirements clearly listed - TURN credentials and relay port range documented The result: `docker compose up -d` gives you a fully working PBX where any SIP client on any network can connect reliably via FQDN:5061. https://claude.ai/code/session_01Vm6NLaQuzM4VosAotqS1q8
93 lines
4.3 KiB
Bash
93 lines
4.3 KiB
Bash
# ================================================================
|
|
# Easy Asterisk - Environment Configuration
|
|
#
|
|
# Setup:
|
|
# 1. cp .env.example .env
|
|
# 2. Set DOMAIN_NAME (the only required setting)
|
|
# 3. docker compose up -d
|
|
# 4. docker exec -it easy-asterisk easy-asterisk
|
|
#
|
|
# Port forwarding required on your router:
|
|
# 5061/tcp → SIP TLS signaling
|
|
# 3478/udp → STUN/TURN (NAT traversal + media relay)
|
|
# 3478/tcp → TURN TCP fallback (for restrictive networks)
|
|
# 10000-20000/udp → RTP media (or your custom range below)
|
|
#
|
|
# How it works:
|
|
# - All SIP clients connect to DOMAIN_NAME:5061 (TLS)
|
|
# - coturn handles NAT traversal (STUN) and media relay (TURN)
|
|
# - Works from any network: LAN, cellular, Proton VPN, hotel WiFi
|
|
# - TURN credentials are auto-generated if TURN_PASSWORD is empty
|
|
# ================================================================
|
|
|
|
# ── Domain Name (REQUIRED) ────────────────────────────────────
|
|
# The FQDN that points to this server's public IP.
|
|
# This is what SIP clients use to connect.
|
|
# Example: asterisk.yourdomain.com
|
|
DOMAIN_NAME=
|
|
|
|
# ── Public IP ─────────────────────────────────────────────────
|
|
# Your server's public IP address.
|
|
# Leave empty to auto-detect (uses ifconfig.me).
|
|
# Set manually if auto-detection fails (e.g., behind double NAT).
|
|
PUBLIC_IP=
|
|
|
|
# ── TLS ───────────────────────────────────────────────────────
|
|
# Always "y" for remote access. Self-signed certs are auto-generated.
|
|
# For trusted certs (no client warnings), mount your Let's Encrypt
|
|
# certs into /etc/asterisk/certs/ via docker compose volumes.
|
|
ENABLE_TLS=y
|
|
|
|
# ── Local Network ─────────────────────────────────────────────
|
|
# Your LAN CIDR. Auto-detected if empty.
|
|
# Example: 192.168.1.0/24
|
|
LOCAL_CIDR=
|
|
|
|
# ── Additional Subnets (optional) ─────────────────────────────
|
|
# Only needed for site-to-site VPNs or VLANs where the server
|
|
# has a direct route to client IPs (e.g., WireGuard, Tailscale).
|
|
#
|
|
# NOT needed for client-side VPNs (Proton, NordVPN, etc.)
|
|
# - Those clients appear with random public IPs
|
|
# - TURN handles media relay for them automatically
|
|
#
|
|
# Examples:
|
|
# WireGuard: VLAN_SUBNETS=10.8.0.0/24
|
|
# Tailscale: VLAN_SUBNETS=100.64.0.0/10
|
|
# Multiple: VLAN_SUBNETS=10.8.0.0/24 10.10.0.0/24
|
|
HAS_VLANS=n
|
|
VLAN_SUBNETS=
|
|
|
|
# ── TURN/STUN Credentials ────────────────────────────────────
|
|
# Used by coturn for TURN relay authentication.
|
|
# If TURN_PASSWORD is empty, a random password is generated on
|
|
# first startup and saved to /etc/easy-asterisk/config.
|
|
#
|
|
# These credentials are shared between coturn and Asterisk.
|
|
# SIP clients do NOT need these - only the server uses them.
|
|
TURN_USERNAME=easyasterisk
|
|
TURN_PASSWORD=
|
|
|
|
# ── TURN Relay Port Range ─────────────────────────────────────
|
|
# Ports coturn uses for media relay. Forward this range on your router.
|
|
# Default is 100 ports (enough for ~50 simultaneous relayed calls).
|
|
# Most calls use direct paths; TURN relay is the fallback.
|
|
TURN_RELAY_MIN=49152
|
|
TURN_RELAY_MAX=49252
|
|
|
|
# ── RTP Port Range ────────────────────────────────────────────
|
|
# Asterisk's own RTP media ports. Forward this range on your router.
|
|
# Default: 10000-20000 (10,000 ports)
|
|
# For constrained environments: 10000-10200
|
|
RTP_START=10000
|
|
RTP_END=20000
|
|
|
|
# ── Web Admin ─────────────────────────────────────────────────
|
|
# HTTP management interface. Access via browser at:
|
|
# http://your-server:8080/clients
|
|
#
|
|
# For HTTPS: put this behind Caddy or nginx reverse proxy,
|
|
# then set WEB_ADMIN_AUTH_DISABLED=true (let the proxy handle auth).
|
|
WEB_ADMIN_PORT=8080
|
|
WEB_ADMIN_AUTH_DISABLED=false
|