By NJ2RQ | Luffy Ham Vault
IAX2 (Inter-Asterisk eXchange version 2) carries signaling and audio over a single UDP port, normally 4569. For amateur radio operators, it can connect an authenticated software client directly to an AllStarLink node or carry links between properly configured nodes. The details matter: connecting an IAXRpt client to your own node is different from configuring two private nodes to find each other without the public AllStarLink directory.
1. Choose which type of direct connection you need
- Software client to your own node: Use the IAXRpt-compatible account and dialplan in your ASL3 installation. You provide the client with a hostname/IP, port, username, password and node number.
- Private node to private node: Give each node a reachable network address and add the other node under
[nodes]inrpt.conf. For this case, use the AllStarLink private-node instructions rather than copying the IAXRpt client example.
Current ASL3 installations use HTTP registration and DNS-based lookup for public node discovery. A directly addressed private connection can avoid that discovery step, but it still needs a functioning network path between the two endpoints.
2. Check your equipment and network
You need a working AllStarLink/Asterisk node, a compatible IAX2 client or another properly configured node, and a local IP address that will not change unexpectedly. Start by testing on the same LAN, or across a trusted VPN, before attempting access over the public internet.
Check the IAX2 listening port in the [general] section of /etc/asterisk/iax.conf. The normal default is UDP 4569. If you are connecting from outside your network without a VPN, you may need a tightly restricted router/firewall rule forwarding that UDP port to your node. Dynamic DNS can help a client find a residential connection with a changing public IP. Neither port forwarding nor Dynamic DNS is required for every local or VPN-based setup. Do not expose a node unnecessarily.
3. Create a dedicated IAXRpt-compatible client account
Back up your configuration before editing. Examine your installed ASL3 iax.conf first: recent ASL3 versions may place per-user definitions in custom/iax/iaxrpt-users.conf through an included template. Use your installation’s existing mechanism rather than creating a duplicate section. For an installation that expects a direct user stanza, the following illustrates the required settings; replace the secret with a unique, strong password:
[direct-client]
type = user
context = iaxrpt
auth = md5
secret = REPLACE_WITH_A_LONG_UNIQUE_SECRET
host = dynamic
disallow = all
allow = ulaw
allow = adpcm
allow = gsm
transfer = no
The section name (direct-client) becomes the client’s username. The context directs the authenticated call to the corresponding dialplan. Use the codecs actually supported by both ends; they need at least one in common. ASL3/Asterisk 20+ uses IAX call tokens, and older clients may need a documented compatibility setting. Review its security implications before disabling call-token checks.
4. Check the dialplan and node number
Look in /etc/asterisk/extensions.conf for the existing [iaxrpt] context. A standard ASL3 IAXRpt dialplan has the following form:
[iaxrpt]
exten => ${NODE},1,rpt(${EXTEN},X)
NODE must resolve to the actual node you wish to access. If you have more than one node on the server, verify the dialplan explicitly supports the intended node number. The X option bypasses the usual app_rpt node security checks after the IAX account is authenticated. Give access only to trusted users and protect each account with a unique strong password. Do not substitute P for automatic PTT: P is Phone Control Mode and requires an appropriately configured phone_functions context and PTT control function. Avoid making changes to a working radio dialplan until you understand how its contexts and permissions are organized.
5. Configure your software client
Important: The Windows IAXRpt client is orphaned and its original download servers have been offline for years. AllStarLink discourages new installations because older downloads may be unsafe or incompatible with future updates. A currently maintained compatible client, such as DVSwitch Mobile in IAXRpt mode, may be preferable. Only install software from sources you trust, and confirm its support for your version of ASL3.
In IAXRpt, create an account for your node, then enter its reachable hostname or IP address, IAX port (normally 4569), the account username and the password you created. Set the node number/account name to the actual node you are connecting to; use the duplex/default options described for your IAXRpt version. A client on your LAN can usually use the server’s LAN IP; a remote client needs an accessible VPN address or a securely exposed public endpoint.
6. Reload, connect and test safely
After backing up the original files and checking syntax, load the changed configuration using the Asterisk console:
sudo asterisk -rvvv
iax2 reload
dialplan reload
Reloading can affect live connections depending on the change and software version; perform significant changes during a maintenance window. Start the client and check the console for an authenticated IAX connection and correct dialplan routing. If it fails, verify the address and UDP port, firewall/VPN path, account name, password, allowed codecs, call-token compatibility and node number.
Do your first audio test without keying a public repeater unexpectedly. Coordinate with the node operator, listen before transmitting, and identify with your callsign as required. A separate, appropriately restricted Asterisk echo test can help troubleshoot audio without sending it to RF. If you can log in but cannot access the radio, check the dialplan permissions and your node’s radio/audio interface separately.
7. Linking two private nodes directly
For node-to-node connections that do not depend on public node-number lookup, define reachable endpoints in the [nodes] section of rpt.conf. For example, the official private-node documentation illustrates static entries using a remote host and IAX port:
[nodes]
1999 = radio@192.168.0.2:4569/1999,NONE
This is an example only: change the node number, host and port to match your own system. Private nodes use a reserved numbering range and require the corresponding configuration on both ends. A static entry only replaces the discovery step; the path, authentication/authorization, codecs and radio configuration still need to work. For production setups, follow the current AllStarLink private-node manual, especially if a private node bridges to a public node.
8. Security and resilience
- Use a unique, strong credential for every direct client and remove accounts that are no longer needed.
- Prefer a trusted LAN or VPN. Where public UDP access is necessary, restrict source IPs where practical and configure firewall rules deliberately.
- Keep ASL3, Asterisk and your network equipment patched. Review authentication logs and consider appropriate automated blocking for repeated failures.
- Do not rely on changing the default port as a substitute for real access controls.
- For emergency communications, test the complete link under realistic conditions. A direct connection can continue without external node discovery only while the underlying network, power and endpoints remain available.
Official references and further reading
For a look at an amateur-radio app that includes IAX Direct among its connection choices, read our QSO One feature guide. This is separate from configuring a private AllStar node-to-node connection.
These instructions distinguish authenticated software-client access from private node-to-node routing; neither mode guarantees service if the connecting network or either node fails.
Check the current AllStarLink iax.conf guide, extensions.conf guide, external-app setup, and private-node guide before applying examples to a live node. Configuration details can differ by version.

Leave a Reply