Enable ARI connection
If there is a Partner that wants to have the ability to connect the server using API to get real-time call statistics or they wish to use the ARI connection for other purposes, you would find the instructions here.
NOTE – Very important!
This can not be enabled until the Partner signs the contract that they understand the risks and potential security issues.
Details and potential risks
To perform the requested action, the Support team has 2 possibilities:
1. To create a rule that enables external ARI connection, and modify allowed_origins in the ARI conf file.
2. To open access via nginx and add an ACL rule, which would limit connections to only allowed IPs, so access to an asterisk HTTP server won’t be exposed to the public. Developers are to decide which action will be taken.
the After Partner signs the contract, we may provide them with the instructions:
1. Create an ARI user
cd /opt/pbxware/pw/etc/asterisk/ari.d
nano/vim file_name.cfg
In this file, you would need to put the credentials for the user that would be connecting to ARI.
[user_name]
type = user
read_only = no
password = enter_your_password
2. Save the file and reload PBXware with /opt/pbxware/sh/pbxware reload
3. cd /opt/pbxware/pw/etc/nginx/custom
nano/vim nginx-ari.conf
Add:
location /ari {
proxy_pass http://127.0.0.1:8088;
proxy_buffering off;
access_log off;
limit_req zone=prov burst=10 nodelay;
allow x.x.x.x;
deny all;
}
Please note that here above with allow/deny you can define for what IP addresses this access will be
allowed, so please make sure to use it carefully.
4. Reload/restart Asterisk & nginx
asterisk -rx 'reload'
Stop nginx using command:
/opt/pbxware/sh/nginx -s stop
Start nginx with:
/opt/pbxware/sh/nginx
Restart PBXware
/opt/pbxware/sh/pbxware restart
5. Add ACL
After that, the connection would be established.
• Test
• Before opening ARI connection, enter this into your browser:
http://PBX_IP/ari/endpoints
Result:

• Open ARI connection as describe above, but do not put your public IP address under the ‘allow’ section:
Result:

• Open ARI connection with your public IP under the ‘allow’ section:
You would be prompt to enter the username/password defined above in file_name.cfg and after entering it, you would get the following:
Result:
