Atlas Knowledge Base
Dashboard
SIP Server

SIP Server

The SIP Server - connects SBN Media to SIP trunks and PBX systems so calls and alarms arrive over SIP.

configuration
registrars
sbn-media
sip
sip-server
sipserver
telephony

SIP Server

The SIP Server connects SBN Media to SIP trunks and PBX systems, so calls and alarms can arrive over SIP.

Overview

The SIP Server is the telephony entry point for SBN Media. It receives SIP calls and signals from a SIP trunk or PBX, handles the SIP signaling, and passes the call into SBN Media for processing - for example to recognize alarm tones or to set up two-way voice. How each incoming number or trunk is handled - which alarm protocols to expect, the caller ID, and similar settings - is set in the line configuration, not on this page.

Like the API Proxy and TURN server, the SIP Server is reached from outside networks, so it should sit in the DMZ. It applies the SBN Media firewall to the connections it receives.

  1. Runs: When configured; at most one per host. A host that handles telephony needs one.
  2. Required: Required for SIP telephony and SIP-delivered alarms. Not needed on a host that only handles video.
  3. Depends on: NATS, and a SIP trunk or PBX to connect to.

Configuration

The SIP Server is configured under the sipserver namespace. View the defaults with ./sbn-media config eject and set host-specific overrides in sbn-media.local.yaml.


Setting

Default

Description

sipserver.ports.sip

5060

SIP over UDP and TCP (unencrypted).

sipserver.ports.sips

5061

SIP over TLS (encrypted).

sipserver.ports.ws

5080

SIP over WebSocket (unencrypted).

sipserver.ports.wss

5081

SIP over WebSocket with TLS (encrypted).

sipserver.minPort

10000

The lowest port used for call media (RTP).

sipserver.maxPort

65000

The highest port used for call media (RTP).

sipserver.address

empty

The network address to listen on. Listens on all addresses when empty.

sipserver.publicIP

empty

The public address to advertise to callers. Looked up automatically when empty.

sipserver.maxConcurrentCalls

100

The most calls allowed at the same time across the whole server. Per-line and per-extension limits are set separately (see Concurrent calls below).

sipserver.minExpires

60

The shortest registration period, in seconds, the server will accept.

sipserver.useProxy

false

Whether to route through a SIP proxy.

sipserver.registrars

empty

How external SIP services and trunks authenticate their calls, per realm (see Authenticating callers below).

Example:

sipserver:
ports:
sip: 5060
sips: 5061

# The public address to advertise, if it is not detected correctly.
publicIP: "203.0.113.10"

# The most calls allowed at once.
maxConcurrentCalls: 100

After changing these settings in sbn-media.local.yaml, reload the configuration for them to take effect. Changing a listen port requires restarting the service.

The SIP Server has further advanced settings - SIP message tracing, rport handling, and how the host address is used in requests - that most installations leave at their defaults. View them with ./sbn-media config eject.

Concurrent calls

The number of calls is limited at three levels, and a call must be within all of the limits that apply to it:

  1. Across the server - sipserver.maxConcurrentCalls caps the total number of calls on the host.
  2. Per line - a line can set its own maxConcurrentCalls in the line configuration.
  3. Per extension - a line can also cap calls for individual extensions with maxExtensionCalls in the line configuration.

Raise the limits where you need more, and make sure the host is sized for the load.

Authenticating callers (registrars)

sipserver.registrars is how external SIP services and trunks authenticate their calls to the SIP Server. Each entry is a realm; the realm of an incoming call is matched against its FROM address, then its TO address, then its recipient.

  1. A realm given an algorithm, a secret, and a nonceWindow must pass digest authentication before its calls are accepted.
  2. A realm listed without those settings is permitted without authentication.
  3. When no registrars are configured (the default), calls are accepted without this check.
sipserver:
registrars:
# Callers in this realm must authenticate.
sl6.example.com:
algorithm: SHA-256
secret: a-shared-secret
nonceWindow: 30
# Callers in this realm are allowed without authentication.
trusted.example.com:

FAQ

Calls are not arriving from my SIP trunk. What should I check?

Confirm the SIP port the trunk uses (5060 by default, or 5061 for TLS) is open and reachable from the trunk, and that the firewall - if it is on - allows the trunk's address. If you authenticate the trunk with sipserver.registrars, confirm its realm and secret match what the trunk uses. If the service will not start, run it in the foreground with sbn-media service exec sipserver -ld to see the error.

How do I handle different phone numbers differently?

The per-number and per-trunk settings - which alarm protocols to expect, the caller ID, the language, call limits, and so on - are set in the line configuration, not on the SIP Server. The SIP Server provides the connection; the line configuration decides what happens on each line.

Do I need encrypted SIP?

Use the sips port (5061) or the wss port (5081) for encrypted SIP, and the sip port (5060) or ws port (5080) for unencrypted SIP. Which you use depends on what your trunk or PBX supports. The encrypted ports use a TLS certificate - see the Certificates page for obtaining and renewing one.

How many calls can the SIP Server handle?

Up to sipserver.maxConcurrentCalls (100 by default) across the whole server, and within any per-line and per-extension limits set in the line configuration (see Concurrent calls above). Raise the limits if you need more, and make sure the host is sized for the load.

Related pages

  1. SBN Media Overview (SBN-Media/overview)
  2. Installing and Configuring SBN Media (SBN-Media/installation)
  3. Firewall (SBN-Media/Configuration/firewall)
  4. Certificates (SBN-Media/Configuration/certificates)
  5. Line Configuration (SBN-Media/Configuration/line-configuration)




Was this helpful?