Help, I’ve been blocked from my PBX!

[HOW TO] Help, I’ve been blocked from my PBX!

Note: This post assumes you’re running FreePBX Distro 13 or higher

If your FreePBX instance has suddenly become unreachable, chances are you’ve been blocked by one of the included network security mechanisms in FreePBX. The good news is that it’s working! The bad news is now you have to somehow work out a way to get yourself unblocked, figure out how you got blocked, and stop it from happening again.

What Blocked Me?

Intrusion Detection (fail2ban)

If you’ve suddenly lost access to the server, this is the most likely culprit. Intrusion Detection scans log files and looks for failed login attempts and other types of unauthorized access, and then temporarily bans the IP of the “attacker”. Continue reading

Virtualmin Server Configuration on Vultr VS

Initial Configuration

In your Vultr Control Panel, set up a Ubuntu or Debian Server instance and SSH into it. Then add a repository that will provide your server with multiple PHP versions and update.

For Ubuntu Install
# add-apt-repository ppa:ondrej/php
# apt-get update && apt-get -y upgrade && apt-get -y dist-upgrade
# apt install php5.6-cgi php5.6-mysql php5.6-curl php5.6-gd php5.6-imap php5.6-mcrypt php5.6-tidy php5.6-xmlrpc php5.6-xsl php5.6-mbstring php5.6-zip php5.6-cli
# apt install php7.1-cgi php7.1-mysql php7.1-curl php7.1-gd php7.1-imap php7.1-mcrypt php7.1-tidy php7.1-xmlrpc php7.1-xsl php7.1-mbstring php7.1-zip php7.1-cli
# apt install php7.2-cgi php7.2-mysql php7.2-curl php7.2-gd php7.2-imap php7.2-tidy php7.2-xmlrpc php7.2-xsl php7.2-mbstring php7.2-zip php7.2-cli

For Debian Install
# apt-get update
# apt-get -y install curl wget gnupg2 ca-certificates lsb-release apt-transport-https
# wget && apt-key add apt.gpg
# echo "deb $(lsb_release -sc) main" | tee /etc/apt/sources.list.d/php7.list
# apt-get update && apt-get -y upgrade && apt-get -y dist-upgrade
# apt-get -y install php7.1 php7.1-cgi php7.1-mysql php7.1-curl php7.1-gd php7.1-imap php7.1-mcrypt php7.1-tidy php7.1-xmlrpc php7.1-xsl php7.1-mbstring php7.1-zip php7.1-cli php7.1-common php7.2 php7.2-cgi php7.2-mysql php7.2-curl php7.2-gd php7.2-imap php7.2-tidy php7.2-xmlrpc php7.2-xsl php7.2-mbstring php7.2-zip php7.2-cli php7.2-common php7.3 php7.3-cgi php7.3-mysql php7.3-curl php7.3-gd php7.3-imap php7.3-tidy php7.3-xmlrpc php7.3-xsl php7.3-mbstring php7.3-zip php7.3-cli php7.3-common php7.4 php7.4-cgi php7.4-mysql php7.4-curl php7.4-gd php7.4-imap php7.4-tidy php7.4-xmlrpc php7.4-xsl php7.4-mbstring php7.4-zip php7.4-cli php7.4-common
# update-alternatives --set php /usr/bin/php7.3
# php -v

Now download the Virtualmin install script and run the install.

# wget
# sh

When you first log in to Virtualmin, it will run the Install Wizard. make sure to use Vultr’s DNS servers when it asks for a primary and secondary DNS. Also, under System Settings > Virtualmin Configuration click on SSL Settings and choose yes for “Request Let’s Encrypt certificate at domain creation time?” and “Redirect HTTP to HTTPS by default?” and save the changes. Now go back to your Vultr Control Panel and click on “Server Details” for your Server instance. Then click on “Settings” and change the Reverse DNS to your servers full host name (i.e.

Creating a Virtual Server

Within Virtualmin, click on “Create Virtual Server”. Enter the domain name and a user password and then click on “Enabled Features” and make sure that the box next to “Setup SSL website too?” is checked, then click on the “Create Server” button. Before the server will work, you need to add the domain to your DNS settings in your Vultr Control Panel. A sub-server can be created by clicking on “Create Virtual Server” and then selecting the sub-server button at the top of the page next to “New virtual server type”. Also a redirect can be created by going to Server Configuration > Website Redirects and clicking on the “Add a new website redirect” button, then adding “/” for the source URL path and the redirect URL for the destination. After creating a new Virtual server for your primary domain, go to Server Configuration > SSL Certificate and click the “Copy” buttons to copy it to all the services that it will be used for. Now go to Virtualmin > Email Settings > DomainKeys Identified Mail. You probably won’t have DKIM filter installed on your server. Virtualmin will give you an option to install it. Do it and then enable ‘Signing of outgoing mail’. Enter the current year for the selector and click on save. Add your primary domain with the “mail” prefix to the “additional domains to sign for” section (i.e. You will also need to make sure that both ‘Signing of outgoing mail enabled?‘ and ‘Reject incoming email with invalid DKIM signature?‘ are set to yes. Next, go to Server Configuration > DNS Options under your domain name and make sure that the IP address isn’t repeated in ‘Allowed sender IPv4 addresses‘. Change “Action for other senders” to “Discourage”, “DMARC record enabled?” to “Yes”, and “DMARC policy for emails that fail SPF or DKIM” to “Quarantine email”. Last, go to Virtualmin > Email Settings > Mail Client Configuration and enable mail client autoconfiguration. You might also have to edit a line in the “/etc/opendkim.conf” file. The line beginning with ‘Socket’ should read ‘Socket   inet:8891@localhost‘. You can set a default domain by logging into Virtualmin, choosing your desired domain from the drop-down on the left, then clicking Server Configuration -> Website Options, and setting “Default website for IP address” to “Yes”.

Configure Baikal CalDAV/CardDav Server used for Calander/Addressbook Syncing

In Virtualmin, create a new virtual server using the steps above which will be used to host the Baikal CalDAV/CardDAV server. Download the latest release here. Copy all of the files in the “html” folder of the zip file into the “public_html” folder of your virtual server. The rest of the files get copied into the parent folder. Make sure that the “Specific” folder is writable by your webserver process. Now you should be able to run the server installer by accessing this virtual server from a browser.

Configure Roundcube

In Virtualmin, click on “Install Scripts” and choose “Roundcube”. After it installs, add the CardDAV plugin manually by uncompressing it in the plugins folder and adding ‘carddav’ to the file. Until an official CalDAV Calendar plugin is developed, we will just have to go without a calendar for a while…. Set up the CardDAV plugin by having it connect to your Baikal CardDav server at Now you can test out your mail server configuration by going to If DKIM is failing then try editing /etc/opendkim.conf and make sure that the line beginning with ‘Socket’ has ‘inet:8891@localhost’ after it.

Configure Scheduled Backups

In Virtualmin, click on “Scheduled Backups” and click on the “Add a New Backup Schedule” button. Select the virtual servers and features that you want to backup. Next select your destination server and path. You can use “%Y-%m-%d” in the path to show the date. Last, you will need to select when the backup will run and then click on the “Save Schedule” button.