How to run VICIdial on a cloud VPS
A practical walkthrough of running VICIdial on a cloud VPS: server size, public IPv4, the firewall rules for SIP and RTP, snapshots, and the audio caveats.

A cloud VPS works fine for a single VICIdial dialer, and the steps are much the same whichever provider you rent from. You rent a virtual private server, give it a real public IPv4, open the right ports, and install Ubuntu plus Asterisk and the dialer on top. The catch is in the network layer, not the hardware. Get the firewall and the audio path right and the rest is routine.
Pick the server size
Cloud servers come in two broad kinds. Shared vCPUs are the budget option. Dedicated vCPUs have no noisy-neighbor jitter, which matters once you carry a few dozen concurrent calls. For a small campaign a 4 vCPU / 8 GB server is a sane start; for 50-plus agents move to dedicated vCPUs. VICIdial wants real CPU for transcoding when your Codec mix forces conversion. If your Carrier hands you G.729 codec and your agents use a different codec, every leg gets transcoded and CPU climbs fast.
You need a public IPv4
VICIdial is a telephony server, not a web app behind a load balancer. It must be reachable by a routable address so your SIP trunk can register or send INVITEs to it, and so media flows back. At order time, make sure the server gets a public IPv4, and confirm it is attached before you build. Without a public address SIP (Session Initiation Protocol) signaling will not complete and you will chase one-way-audio ghosts that were never going to work. The public-IP requirement is the single most common reason a cloud dialer never makes a call.
Open SIP and the RTP range
Whatever firewall sits in front of the server - your provider's cloud firewall, the host firewall on the box, or both - has to let the call traffic in. You must allow your SIP signaling port (UDP 5060, or your TLS port) and the whole RTP media range. Asterisk uses UDP 10000-20000 for audio out of the box, and every one of those ports has to be open inbound, scoped to your carrier's IPs where you can. Lock SIP to known carrier and agent addresses; an open 5060 to the whole internet invites credential-stuffing within hours.
flowchart LR
Carrier[SIP carrier] -->|UDP 5060 SIP| FW[Cloud firewall]
FW -->|allow signaling| VD[VICIdial box]
Carrier -->|UDP 10000-20000 RTP| FW
FW -->|allow media| VD
VD -->|audio| Agent[Agent softphone]NAT and audio
Some providers put the public IP directly on the server's interface, so heavy NAT traversal gymnastics are usually unnecessary; others give the box a private address and map the public IP to it one-to-one. Either way, set externip and localnet in Asterisk so SDP advertises the public address as the media IP. Skip that and the SIP packets say connect here while pointing at a private address the carrier cannot reach. The symptom is the call connects, both sides answer, and nobody hears anything. That is the classic NAT audio fault, and we cover it in depth in our cloud NAT audio guide.
Backups with snapshots
Most cloud providers can take a Server snapshot of the whole disk on demand, which captures your config, dialplan, and database state in one image. Schedule one before any upgrade. A full snapshot takes minutes, not seconds, to create, and longer on a big disk, so do not treat it as instant rollback during a live shift. Recordings live on the same disk by default; move them off if retention matters.
The honest time cost
Doing this by hand is a real afternoon. Provision the VPS, harden SSH, build VICIdial from source or run an installer, set up the firewall, wire TLS, and test a call. None of it is hard, but it adds up, and the security hardening is the part people skip and regret. The cloud part of this is covered end to end in our VICIdial in the cloud guide. We automate this build ourselves, and Provisioning a fully secured, Single tenant box takes us under 40 seconds. You still get root SSH and bring your own carrier. See pricing if you would rather skip the afternoon.
Related from VICIfast
- The managed VICIdial firewallConsole access, recorded SSH sessions, and self-serve agent IP whitelisting.
- Add IPs and whitelist by sourcePin trunks per IP and whitelist agent home offices.
- Managed VICIdial backupsDaily snapshots at 03:00 local, 7-day retention, restore in a click.
- Dedicated-CPU plansAMD EPYC dedicated cores for steady volume or visible CPU steal.
About VICIfast
We run VICIdial servers for call centres, so you don’t have to. You get the dialer set up, secured and kept running — we handle the server, the updates and the backups. Bring your own phone carrier at no markup, or use VICIfast Voice, our own US calling and numbers, from $0.0085 a minute. From $49 a month per server.
Questions? Call +1 636 556 0022 and talk to someone who runs dialers.
Citing this article
VICIfast Engineering. “How to run VICIdial on a cloud VPS”. VICIfast LLC, June 29, 2026. Retrieved from https://vicifast.com/blog/vicidial-on-a-cloud-vps
Have questions?
Related posts
You might be interested in
VICIfast newsletter
Liked this? Get the next one in your inbox.
We ship the kind of stuff you just read - concrete, numbers-first, no drip. One email when a new post goes live. Unsubscribe in one click.
Comments
No comments yet - be the first.





