SIP Server
The SIP Server - connects SBN Media to SIP trunks and PBX systems so calls and alarms arrive over SIP.
SIP Server
The SIP Server connects SBN Media to SIP trunks and PBX systems, so calls and alarms can arrive over SIP.
Overview
The SIP Server is the telephony entry point for SBN Media. It receives SIP calls and signals from a SIP trunk or PBX, handles the SIP signaling, and passes the call into SBN Media for processing - for example to recognize alarm tones or to set up two-way voice. How each incoming number or trunk is handled - which alarm protocols to expect, the caller ID, and similar settings - is set in the line configuration, not on this page.
Like the API Proxy and TURN server, the SIP Server is reached from outside networks, so it should sit in the DMZ. It applies the SBN Media firewall to the connections it receives.
- Runs: When configured; at most one per host. A host that handles telephony needs one.
- Required: Required for SIP telephony and SIP-delivered alarms. Not needed on a host that only handles video.
- Depends on: NATS, and a SIP trunk or PBX to connect to.
Configuration
The SIP Server is configured under the sipserver namespace. View the defaults with ./sbn-media config eject and set host-specific overrides in sbn-media.local.yaml.
Setting | Default | Description |
|---|---|---|
| 5060 | SIP over UDP and TCP (unencrypted). |
| 5061 | SIP over TLS (encrypted). |
| 5080 | SIP over WebSocket (unencrypted). |
| 5081 | SIP over WebSocket with TLS (encrypted). |
| 10000 | The lowest port used for call media (RTP). |
| 65000 | The highest port used for call media (RTP). |
| empty | The network address to listen on. Listens on all addresses when empty. |
| empty | The public address to advertise to callers. Looked up automatically when empty. |
| 100 | The most calls allowed at the same time across the whole server. Per-line and per-extension limits are set separately (see Concurrent calls below). |
| 60 | The shortest registration period, in seconds, the server will accept. |
| false | Whether to route through a SIP proxy. |
| empty | How external SIP services and trunks authenticate their calls, per realm (see Authenticating callers below). |
Example:
After changing these settings in sbn-media.local.yaml, reload the configuration for them to take effect. Changing a listen port requires restarting the service.
The SIP Server has further advanced settings - SIP message tracing, rport handling, and how the host address is used in requests - that most installations leave at their defaults. View them with ./sbn-media config eject.
Concurrent calls
The number of calls is limited at three levels, and a call must be within all of the limits that apply to it:
- Across the server -
sipserver.maxConcurrentCallscaps the total number of calls on the host. - Per line - a line can set its own
maxConcurrentCallsin the line configuration. - Per extension - a line can also cap calls for individual extensions with
maxExtensionCallsin the line configuration.
Raise the limits where you need more, and make sure the host is sized for the load.
Authenticating callers (registrars)
sipserver.registrars is how external SIP services and trunks authenticate their calls to the SIP Server. Each entry is a realm; the realm of an incoming call is matched against its FROM address, then its TO address, then its recipient.
- A realm given an
algorithm, asecret, and anonceWindowmust pass digest authentication before its calls are accepted. - A realm listed without those settings is permitted without authentication.
- When no registrars are configured (the default), calls are accepted without this check.
FAQ
Calls are not arriving from my SIP trunk. What should I check?
Confirm the SIP port the trunk uses (5060 by default, or 5061 for TLS) is open and reachable from the trunk, and that the firewall - if it is on - allows the trunk's address. If you authenticate the trunk with sipserver.registrars, confirm its realm and secret match what the trunk uses. If the service will not start, run it in the foreground with sbn-media service exec sipserver -ld to see the error.
How do I handle different phone numbers differently?
The per-number and per-trunk settings - which alarm protocols to expect, the caller ID, the language, call limits, and so on - are set in the line configuration, not on the SIP Server. The SIP Server provides the connection; the line configuration decides what happens on each line.
Do I need encrypted SIP?
Use the sips port (5061) or the wss port (5081) for encrypted SIP, and the sip port (5060) or ws port (5080) for unencrypted SIP. Which you use depends on what your trunk or PBX supports. The encrypted ports use a TLS certificate - see the Certificates page for obtaining and renewing one.
How many calls can the SIP Server handle?
Up to sipserver.maxConcurrentCalls (100 by default) across the whole server, and within any per-line and per-extension limits set in the line configuration (see Concurrent calls above). Raise the limits if you need more, and make sure the host is sized for the load.
Related pages
- SBN Media Overview (
SBN-Media/overview) - Installing and Configuring SBN Media (
SBN-Media/installation) - Firewall (
SBN-Media/Configuration/firewall) - Certificates (
SBN-Media/Configuration/certificates) - Line Configuration (
SBN-Media/Configuration/line-configuration)