Release notes — Version 2.4
What changed in each version 2.4 release, newest first, as published with the release.
v2.4.9
Released 2026-10-08
- New: conference rooms. Staff create rooms under PBX > Conferences; a customer can create and run their own rooms in the portal once you switch on "Portal: conference rooms" in their user settings (off by default).
- A room has its own number, a PIN (6 to 12 digits), a maximum number of participants and a maximum duration per participant. Only the owner's own devices can dial the room number; any other customer who dials it is cut off and never routed out as an external call.
- Callers from outside reach a room through a DID of the room's owner (DID page > dial plan > the room). They must enter the PIN: after 3 wrong tries the call ends and that caller number is locked for 30 minutes; after 10 wrong tries from any numbers within 15 minutes the dial-in of that room is locked for 30 minutes.
- Live view per room: who is in the room and who is speaking; add one of the owner's devices (the phone rings and joins on answer), remove a participant, end the room. Every action is logged.
- New device switch "Conferences" (off by default): the device sees and controls the rooms of its owner in the device portal; it cannot create or change rooms.
- Calls between a device and a room cost nothing. A dial-in through a DID is handled like any DID call to a ring group or queue today (no new price).
- Fix: a busy lock on the telephony configuration was recognised only by a German word in the error text; it is now recognised by its error code.
v2.4.8
Released 2026-10-07
- Listen in from the browser: on Call tracing you can listen in, whisper or barge in directly in the browser, with a level meter and a "who is speaking" display. New switch "Listen in from the browser" on the Listen in (ChanSpy) settings page, off by default.
- Listening in, whispering and barging in are now three separate permissions. Every role and system user that could listen in before keeps all three.
- New Listen-in log (Monitoring, administrators only): every session with who, when, which call and which device. Entries cannot be changed or deleted.
- Spy device: choose your own WebRTC device under Personal details (customers: My data). Use a separate device; while you listen in, other calls to it are rejected.
- Customers can listen in on calls of their own devices in the portal, but only when you enable it for that customer and for each kind separately (user form, off by default). Every session is logged.
- Device portal: new per-device switch "Add participant" (off by default). It lets a device add another device of the same account into its running call; the added device hears both sides and speaks to both.
- Fixed: listening in always connects to exactly the selected call and side. Before, it could connect to a different call, and the spy device was dialled by its extension instead of its name, so it often did not ring.
- Fixed: staff accounts restricted to selected users now see, listen to and hang up only the calls of those users on Call tracing.
v2.4.7
Released 2026-10-06
- Devices: new section "Status per origin" next to "Change failed code to". Per device you choose which status the phone receives when a call to the outside fails - per provider result (busy, no answer, congestion, unavailable) or per own rejection code. A row takes precedence over "Change failed code to". Without rows nothing changes.
- The original result is kept: the call list, the hangup cause statistics and the daily totals keep the real cause and status. For staff, the call details show "original -> sent to the phone".
- The SIP response code of the provider is now recorded for every dial attempt and shown in the call details next to the Q.850 cause.
- Number pools: the reject rule can now count SIP classes (4xx except 404, 480, 486, 487; 5xx) and single codes (403, 503, 603). A caller hanging up (487) never counts. The default rule is unchanged.
- "Change failed code to": the labels now show the SIP response the phone really receives. Code 22 sends 410 Gone (was shown as 301), codes 23 and 26 send 603 Decline (were shown as 410 and 404).
v2.4.6
Released 2026-10-06
- Routing by country: each LCR has a new tab "Routing by country". For a destination country you can give the LCR its own list of providers; a call to that country tries them in the order of the LCR (price, priority or percent), each next one when the previous one fails, and the failover provider of the LCR still comes last. Only providers with a rate for the dialled number are used. Calls to other countries keep the normal provider list. A matching rule under "Routing by destinations" still comes first. Note: after going back to an older version, country rows no longer apply and the normal provider list is used again.
- Protection against loss calls: a provider whose price per minute or connection fee is higher than the customer's price is no longer used, unless the LCR has "Allow loss calls" switched on (off by default). The skipped call gets cause 224. The failover provider and emergency and service numbers are never skipped. The switch "Allow loss calls" can now be set on the LCR page; before, it could only be changed in the database and had no effect on calls.
- Start setting of this protection: "Only write it down" - calls still go through as before and each affected call is written to the log of the background service. Under LCR / routing the setting can be changed to "Skip such providers" once the numbers have been checked.
- New option per LCR "Only providers with a rate for the number": a provider without a rate for the dialled number is skipped (cause 274) instead of being tried. Off by default, so nothing changes until it is switched on.
- Fixed: when a provider rule changed the tariff and that provider failed or was skipped, the next provider could be billed with the tariff of the first provider's rule. Now each call is billed with the tariff of the provider that was really dialled.
- "Routing by destinations" rules are no longer read from the database on every call; a change takes effect within 60 seconds.
- Monitoring: a warning is sent when SIP over TLS (port 5061) still uses the old certificate after a renewal - Asterisk only loads the new one on a restart, and the renewal does not restart it while calls are running.
- The routing probe shows the country rule, providers skipped for a missing rate and providers that are more expensive than the customer.
v2.4.5
Released 2026-10-06
- Devices now record when they were last used (any call from or to the device, including ring groups and queues). Registrations and SIP messages do not count. Nothing changes on your system after the update: the new setting "inactive after X days" starts at 0 (off) on every device.
- New optional daily job for unused devices: when a device has been unused for more than X local calendar days, it can release its numbers (DIDs, caller IDs, pool links, country rules) and is marked "inactive". The system starts in "Preview" mode, which only lists the devices that would be affected; numbers are released only after you switch the mode to "Release" under Settings > Default device. Use the "Preview" button on the device list first.
- Safety brake for the daily job: it stops without changing anything and notifies you when more than 10 devices or more than 10 % of devices would be released at once, or when usage tracking was interrupted (service or Asterisk connection down for more than 10 minutes) during the period.
- Released DIDs show the badge "automatically released (recycling)" with date, reason and previous device in the DID list and DID details, and the DID list has a filter for them. The badge disappears once the DID is assigned again.
- Inactive devices show "inactive since <date>" in the device list and device header, with the buttons "Reactivate" and "Undo release" (operator only). Undo restores every number and link that is still free and allowed, and reports anything that was given to someone else in the meantime.
- Before rolling back to an older version, undo any open automatic releases first - the older version does not have the "Undo release" button.
- An inactive device that calls an outside number now hears a short announcement ("This number is no longer active. Please contact your provider.") and the call ends with hangup cause 904 and no charge. Emergency numbers still go through, internal calls are not affected. Announcements in German, English, French and Italian (generated voices); other languages hear English.
- Number pool mode: the first provider now uses the caller ID that was already drawn from the pool instead of drawing a second one. Before, every call counted twice in the pool statistics, so the distribution was less even than configured.
- New provider option "Override all other settings": when enabled, calls through this provider always show the provider's own caller ID (number and name), overriding the device's number, hidden caller ID, P-Asserted-Identity/RPID and privacy settings. If the provider's number pool has no usable number, this provider is skipped (cause 900) and the next one is tried. Emergency caller ID rules still take priority. Without the option, behaviour is unchanged.
- Moving a device to another customer now clears the caller ID chosen by the previous customer and switches "customer may choose caller ID" off; you can switch it on again on the device.
- Moving a device whose caller ID pool was deleted now says "pool deleted" instead of showing an unclear pool reference.
- Restricting a number pool to one customer and attaching the pool to a device at the same moment can no longer create a link the customer is not allowed to use.
- Customer portal "Choose caller ID": a note now explains when the provider sets the number for some destination countries.
v2.4.4
Released 2026-10-06
- Caller ID by country: each device has a new tab "Caller ID by country". For every destination country you can name a DID or a number pool; calls to that country go out with a number from this rule, calls to other countries keep the device's caller ID setting. A country rule comes before the number a customer chose in the portal; if none of its numbers is usable (pool used up, DID blocked or no longer the customer's), the device's normal setting is used. A pool that is used in a country rule cannot be deleted. Note: after going back to an older version, country rules no longer apply and devices send their normal caller ID again.
- Destination countries are now recognised from a table kept in memory, without a database query per call; live calls and the globe show the same countries as before.
- Devices that have calls, are the forwarding or fax target of another device, are a queue agent or were reassigned can no longer be deleted (before, only devices with DIDs were refused).
- Caller ID taken from the device's DIDs now only uses active DIDs that belong to the device's user. Reserving a DID for another user now detaches it from the old user's device, so that device no longer sends the reserved number.
- DID import: a DID whose device belongs to a different user is now created without a device and listed in the import result, instead of being linked to a device that could never receive its calls.
- The limit "block caller ID after N simultaneous calls" now counts the caller ID that is really sent. Before, it compared with the number the phone sent and never triggered once the system replaced the number (number pool, DIDs, CLI, by destination). Devices that use this setting may now block numbers that were never blocked before.
- Update button: with automatic restart switched on, the update window now stays open until the server is back after the restart, instead of reloading into a "This site can't be reached" page.
v2.4.3
Released 2026-10-05
- Number pools can now be reserved for one user ("Available for" in the pool form). Only that user's devices can use the pool's numbers as CallerID. New and existing pools stay "All users" - nothing changes until you reserve a pool.
- The reservation is checked when a pool is assigned (device CallerID, fake CallerID pool, CID pools page, provider, moving a device to another user) and again on every call, including fallback pools and pool rotation. A call never uses a number from another user's pool: if a device has no allowed pool for a provider, that provider is skipped with cause 900 instead of sending a different CallerID.
- Reserving a pool is refused while devices or pools of other users still use it; the message lists them. Providers can only use pools available for all users.
- The pool list shows and filters "Available for", the user page lists the pools reserved for that user, and the device CID pools page marks pools that are skipped in calls.
- Switching a device from a pool CallerID mode to a fixed CallerID now removes its CID pool links when you save, so calls use the CallerID shown in the form. The form warns before you save.
- Fixed: "is currently not used as a CallerID" was shown for numbers in cooldown even when the pool does not skip cooldown numbers.
- Fixed: moving the mouse on the login page caused an endless error loop in the browser.
- Fixed: DID bulk management with selected DIDs described a number range instead of the selection.
- Fixed: number pools stored without an owner value could not be opened or saved.
- Note: if you go back to v2.4.2, pool reservations are no longer enforced. Write down your reserved pools before going back.
v2.4.2
Released 2026-10-05
- Devices: new per-device switch "Customer chooses caller ID" (off by default, only staff can set it). When it is on, the end customer in the customer portal and the device's own portal login can choose the outgoing caller ID among the active DIDs assigned to that device.
- Calls: the chosen DID is used as caller ID in the caller ID modes "number", "number from DID" and "control by DIDs", without reloading Asterisk. It is checked on every call (still on this device, active, not blocked); otherwise the caller ID rule configured on the device applies. Forwarded calls ignore the choice.
- Device form: the switch is greyed out in modes where a choice would have no effect (pools, rotation, by destination, by CIDs, unknown, name to number) and can always be switched off; the device page shows the customer's current choice and whether it is in effect.
- DID bulk management: after an action on DIDs selected in the list, the page now stays open (previously it jumped back to the DID list), so you can continue with the same selection.
v2.4.1.2
Released 2026-10-05
- No manual step after an update any more: when you press Update, the server part (system scripts, watchdog, sudo rules) is now renewed automatically from the signed release package.
- If renewing the server part fails (for example a network outage during a night update), it is retried automatically up to three times, only while no call is active; you are notified only if all attempts fail.
- The system helper now renews itself from the signed package as well; its revision is shown in the server-part status.
- Fixed: the watchdog's direct notifications ("Pulse", "Watchdog active") were never delivered.
- The firewall and GeoIP scripts are now renewed by every update (before, an installed copy was never updated), and their settings file is read as plain values only.
- The pjsip reload helper is now renewed on every update and may only be run without arguments.
- The installation log is now readable by root only on existing servers as well.
- Fixed: a freshly installed server showed "1 warning" for the server part although nothing was missing (no fail2ban ban had happened yet).
- Hints from the health check now point to the system helper instead of a manual command.
v2.4.1.1
Released 2026-10-04
- One-time step after this update, done by support on each system: the server part is set up for automatic renewal. Until then the system keeps working as before.
- Releases are now digitally signed. An update installs a version only if its signature is valid; otherwise nothing is changed.
- From the next update on, the server part of the system (telephony and protection settings) renews itself automatically from the signed release - no manual step after an update anymore.
- The update page shows a new line "Server part" with its state: set up, being renewed, failed, not set up or switched off.
- If the server part cannot be renewed, the update itself stays installed and working; you get one notification "update failed" with the reason.
- New installations check the release signature before anything is changed (new option --version); the system packages rsync and dnsutils are now installed automatically.
- Installer hardening: during a reinstallation, application files are no longer written or run with administrator rights.
- Fixed: the progress on the update page stood still during the build step.
- Fixed: a beta version was treated as newer than its own stable release.
v2.4.1
Released 2026-10-04
- DID list: the Reputation column now shows the real state of each number - cooldown with its end time, quarantine, blocked, warnings and the reject count. Before, it read an outdated field and showed "Active" for every DID. Resellers no longer see this column, the same as on the DID page.
- DID list and DID page: a new Pool column and a Pool filter show which number pool a DID belongs to. Only pools you may see are shown. The filter also applies to the CSV/XLSX export and to "all results" in bulk management.
- Number pool, list of numbers: a new DID column marks which numbers are DIDs in this system (with a link) and which are not.
- Number pools: what counts as a reject is now adjustable - for the whole system (box on the Number pools page, operator only) and per pool (pool settings). The default is unchanged: Q.850 cause 21, CONGESTION, CHANUNAVAIL. BUSY and NOANSWER can be added deliberately; a warning explains that a pool can otherwise run empty. After a change, counting starts anew for the affected numbers.
- If you go back to v2.4.0, rules set per pool are ignored and the fixed default applies again.
v2.4.0
Released 2026-10-04
- System status has a new tab "Certificates": expiry date, issuer and names of the TLS certificates of the web interface (443), the web phone (WSS, 8089) and SIP over TLS (5061), read as the server serves them right now, with a traffic light that turns yellow from 21 days left - the same threshold as the server watch.
- The tab shows when SIP over TLS still presents the previous certificate after a renewal; Asterisk takes the new one at its next restart.
- Administrators can show the certbot status, run a local precheck (DNS, port 80, firewall rule), a test renewal and a renewal, and read the helper log - through a fixed helper on the server that accepts no input from the browser. Every run is written to the action log; the last 20 runs are listed on the tab.
- A renewal is never forced: before 30 days left certbot reports "not due yet" and changes nothing. If nginx is left with an invalid configuration after a run, the previous configuration is restored automatically.
- New rights ssl.view and ssl.manage (administrators only).
- The certificate helper is installed by the server maintenance step after the update; until then the tab shows the certificates and a note instead of the buttons.