BeePanel opens no firewall port and installs no reverse proxy. Allow the connections below in your firewall yourself. Exposing BeePanel to the internet, and any proxy in front of it, is your responsibility.
Connections to BeePanel
| From | Port | Purpose |
|---|---|---|
| Users' browsers | TCP 18080 by default | The panel, over HTTP or HTTPS |
BeePanel listens on every network interface by default. Change the address, the port, or the protocol in the panel address setting: HTTP, HTTPS with a self-signed certificate BeePanel generates, or HTTPS with your own certificate. A self-signed certificate makes browsers show a warning that users must accept once.
Warning
Until setup is complete, anyone who can reach the setup address can complete setup and become BeePanel's administrator. Keep the port closed to untrusted networks until then.
Connections to the PBX
| To | Port | Purpose |
|---|---|---|
| Asterisk AMI | TCP 5038 by default | Live calls, queues, and call actions |
| CEL database | The database's port | Call history, with Pro |
On the PBX server both stay on the server itself. On a separate server, the BeePanel server must reach the AMI port and the database across the network; see Installing on a server separate from the PBX.
Over a network, keep AMI traffic on a private network, a VPN, or a tunnel.
When the AMI address is not a loopback address such as
127.0.0.1, the AMI editor asks you to accept this risk before it accepts
the connection.
Connections to BeePanel services
All are outbound HTTPS on TCP 443.
| To | When |
|---|---|
licensing.beepanel.io |
Starting a trial, activating or moving a license, and checking a license's status when the service starts and before an update |
| The BeePanel download address | Installing, and updating when an administrator runs the update command |
beestt.beepanel.io |
Call transcription, with Pro: when a permitted user asks for a transcript, and when an administrator opens the call transcription setting, to show the credit balance |
The download address is published with the first release.
If licensing.beepanel.io cannot be reached, an activated license keeps
working and nothing is blocked; only starting a trial and activating or
moving a license need it. The licensing service receives the license key
or the trial email address, an installation key, hashed machine identifiers,
and installation details such as the BeePanel version, the PBX distribution,
the Asterisk version, and the operating system. No call data, recordings,
settings, or logs are sent. Transcription sends only the recording a user
asked to transcribe.