📘 Reflector Setup Guide
You are in the right place if you want to add your own reflector to the DVPX network. This page walks through the whole path: what you need, which steps are yours, and which belong to the dashboard administrator.
A reflector is the server where DVPX users meet. Apps connect to it over TCP, announce their identity and pick a talkgroup; while someone talks, voice packets travel to the reflector over UDP and it forwards them to everyone on that talkgroup.
Reflectors also link to each other: a talkgroup is shared across the whole network, so which reflector you are on never splits a conversation. A reflector NEVER connects to the database — it talks to the dashboard only through the API token issued to it. That is why no database credentials ever live on your server.
- Sign up. Your callsign becomes your username. Your account waits for administrator approval.
-
File a reflector request.
Give your server address, ports and justification. You do not have to rent the server before this step, but you do need to know its address. The form also asks for SSH details, but they are OPTIONAL — you may leave them empty. If you provide them, an administrator can look at your server during an outage and help with the setup; the password is stored encrypted and only an administrator can read it.
-
Approval and token.
The administrator approves the request and creates the reflector record. The moment they generate a token it waits for you HERE ON THIS PANEL: press ⚿ Show Token in the My Reflectors list on "My Panel" and it appears together with a ready-made config.json. The token does NOT need to be sent over WhatsApp or e-mail — and it should not be. While waiting on the panel the token is stored encrypted, with the key kept outside the database. Once installed, clear it with "Got it, clear from my panel".
- Prepare the server. Install Node.js, place the files, write config.json, open the ports, start the service. The sections below cover this.
- Verify. Once your reflector starts reporting to the dashboard it shows as LIVE in the "My Reflectors" list on your panel. If it does not, the same row tells you why.
A talkgroup number BEGINS WITH THE COUNTRY CODE. The country you pick when signing up determines that code, and you may only request numbers starting with your own. This splits the number space by country so operators from two countries never ask for the same number.
| Number | Meaning | Who creates it? |
|---|---|---|
| 90 | Türkiye, country-wide | Administrator |
| 9034 | Türkiye / Istanbul (34 = plate code) | You request it |
| 9006 | Türkiye / Ankara | You request it |
| 1 | United States, country-wide | Administrator |
| Minimum | Comfortable | |
|---|---|---|
| CPU | 1 core | 4 cores |
| RAM | 1 GB | 4 GB |
| Disk | 5 GB | 30 GB |
| Operating system | Ubuntu 22.04 / Debian 12 | Ubuntu 24.04 |
| Public address | Static IP (required) | Domain name + static IP |
| Node.js | 18 | 20 |
Open ports
TCP 62070 (signalling), UDP 62071 (audio). The UDP port must be open both inbound and outbound — the reflector-to-reflector link uses it too.
API token
The administrator generates it; it lands encrypted on your panel. Without it the reflector gets no policy and is never published to the apps.
Stable address
A static public IP is required; pointing a domain at it is better. Users keep their settings even if the server changes.
SSH access
The IP, username (usually root) and password or SSH key from your provider. You will do the install over that connection.
1) Node.js
Check first: if the version is 18 or newer, skip this step.
💡 You do NOT need to run npm install. The DVPX reflector has no external dependencies; it uses Node's built-in modules only.
2) Get the files from the repository
The files live in a public GitHub repository. Using Git is recommended: updating later becomes a single command.
Do not leave out the /opt/dvpx-reflector path at the end of the command: giving the target directory explicitly puts the files exactly there (no mkdir needed, git creates the directory itself). We pick that path on purpose — the dvpx-reflector.service file shipped in the repository uses the same path, so you can copy it without editing. The repository is the reflector only; the dashboard runs at the centre of the network and is never installed on your server.
3) config.json
Save the template below as /opt/dvpx-reflector/config.json. The dashboard URL is pre-filled for this installation; replace the token with the value the administrator gave you. The ports must MATCH what you wrote in your request.
4) Firewall
Your provider may run a SECOND firewall in front of the server (Hetzner, AWS, Oracle Cloud, Azure, Google Cloud…). This is the most commonly missed step: add the same rules there too.
5) Trial run
If the log looks clean (registered with the dashboard, TCP/UDP listening), stop it with Ctrl+C and move on to the service.
6) Install as a service
This keeps it running after you close the SSH window, starts it on boot and restarts it after a crash. Do NOT run the reflector as root.
If your install path is not /opt/dvpx-reflector, fix the WorkingDirectory, Documentation and ReadWritePaths lines in the service file. If node lives elsewhere (which node), fix ExecStart too.
Is the log clean?
Are the ports listening?
Does the dashboard see it?
Look at "My Reflectors" on your panel. Four conditions must hold TOGETHER for the reflector to count as LIVE:
- An API token must have been issued
- The record must be approved by an administrator
- Status must be "online" (not maintenance)
- It must have reported to the dashboard within 2 minutes
If any one is missing, the row says NOT LIVE and names the condition that is missing.
1) Back up first
config.json is your own file and is not kept in the repository, so git pull never overwrites it. Still, a backup costs a minute and saves you from having to ask for a new token.
2) Download and install the update
If you installed with Git (the recommended path) it is five commands in total. The first line installs git if it is missing.
If you did not install with Git (one-off migration)
If the directory is not a git repository (you installed from a zip), re-clone it once; your config.json is preserved. Every later update becomes the five commands above.
3) How do you know it worked?
You will see the new version number in the log. The moment the reflector checks in with the dashboard (a few minutes at most) the red warning on your panel clears ITSELF — there is no “I read it” button and you need not notify anyone. If the warning stays, the update did not actually take effect.
| Symptom | Cause | Fix |
|---|---|---|
| Service runs, log is clean, nobody can connect | Ports closed — usually at the provider firewall | Open 62070/tcp and 62071/udp in ufw AND the provider panel |
| Signalling works but no audio | The UDP port is closed (TCP opened, UDP forgotten) | Open UDP 62071; a TCP rule does not cover UDP |
| Dashboard says "never connected" | The url or token in config.json is wrong | Check the URL and token, then: systemctl restart dvpx-reflector |
After every config.json change you must RESTART the service; the file is read only at startup.
- Keep your reflector up. Announce planned maintenance in advance.
- Keep the software current; move to a new version when the administrator announces one.
- Keep the API token secret. If you suspect it leaked, use "Request New Token" on your panel IMMEDIATELY.
- When something goes wrong, write from 💬 Chat on your panel; the conversation updates live and every dashboard administrator sees it.
- Do not run the reflector as root; use an unprivileged user.
- Keep your instant-messaging details current — that is how you are reached in an emergency.
- Do not record user traffic or pass it to third parties.
A reflector-operator account is DELIBERATELY very limited. Nothing you do touches the network directly; everything passes through administrator approval.
You can
- File a reflector request
- File a talkgroup request
- Withdraw your own pending request
- Watch your own reflector status
- See your own talkgroups and the stations connected to them
- Watch last heard for your own reflectors and talkgroups
- Read the API token issued to you from your panel
- Request a new token, with a justification
- Chat with an administrator from your panel
- Change your own contact details and password
You cannot
- Create, disable or delete talkgroups
- Approve reflectors or generate API tokens
- See the user list or block users
- View last heard or statistics for the WHOLE network (you only see your own scope)
- View person-to-person private calls or private talkgroup traffic
- See another operator's request or details