Changes for page SIP

Last modified by Aaron Blackburn on 2026/09/01 19:00

From version 1.2
edited by Aaron Blackburn
on 2026/09/01 18:31
Change comment: There is no comment for this version
To version 1.4
edited by Aaron Blackburn
on 2026/09/01 19:00
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -1,12 +1,13 @@
1 1  {{html clean="false"}}
2 2  <!--
3 - XWiki usage: paste everything in this file into an HTML macro.
3 + XWiki usage: Paste into an HTML macro on your page.
4 + Note: All FirstDigital public IPs have been sanitized for public wiki security.
4 4  -->
5 5  <style>
6 6   @import url('https://fonts.googleapis.com/css2?family=Host+Grotesk:wght@300;400;500;600;700;800&display=swap');
7 7  
8 - .fd-sip-diag, .fd-sip-diag * { box-sizing: border-box; }
9 - .fd-sip-diag {
9 + .fd-sip-doc, .fd-sip-doc * { box-sizing: border-box; }
10 + .fd-sip-doc {
10 10   --fd-navy: #003366;
11 11   --fd-dark-navy: #001a33;
12 12   --fd-blue: #307ab2;
... ... @@ -13,6 +13,7 @@
13 13   --fd-sky: #38b2e3;
14 14   --fd-bright-cyan: #5ed2ff;
15 15   --fd-red: #cf333d;
17 + --fd-green: #2e7d32;
16 16   --fd-slate: #2e404d;
17 17   --fd-grey: #8f9499;
18 18   --fd-lightgrey: #e2e8f0;
... ... @@ -27,8 +27,8 @@
27 27   padding: 24px 16px;
28 28   }
29 29  
30 - /* ---------- HEADER BANNER ---------- */
31 - .fd-sip-diag .diag-header {
32 + /* Header */
33 + .fd-sip-doc .doc-header {
32 32   background: radial-gradient(circle at 50% 35%, rgba(13, 71, 128, 0.78) 0%, rgba(0, 51, 102, 0.93) 60%, rgba(0, 26, 51, 0.98) 100%),
33 33   url('Fiber Optic Theme.JPG') center/cover no-repeat;
34 34   padding: 40px 32px;
... ... @@ -38,7 +38,7 @@
38 38   box-shadow: inset 0 0 60px rgba(0, 26, 51, 0.6), 0 12px 32px rgba(0, 51, 102, 0.12);
39 39   margin-bottom: 32px;
40 40   }
41 - .fd-sip-diag .diag-header p.kicker {
43 + .fd-sip-doc .doc-header p.kicker {
42 42   color: var(--fd-bright-cyan);
43 43   font-weight: 800;
44 44   font-size: .8rem;
... ... @@ -47,7 +47,7 @@
47 47   margin: 0 0 8px;
48 48   text-shadow: 0 2px 10px rgba(0, 26, 51, 0.8);
49 49   }
50 - .fd-sip-diag .diag-header h1 {
52 + .fd-sip-doc .doc-header h1 {
51 51   font-weight: 800;
52 52   font-size: 2.25rem;
53 53   margin: 0 0 10px;
... ... @@ -54,7 +54,7 @@
54 54   letter-spacing: -0.02em;
55 55   text-shadow: 0 3px 12px rgba(0, 26, 51, 0.9);
56 56   }
57 - .fd-sip-diag .diag-header p.sub {
59 + .fd-sip-doc .doc-header p.sub {
58 58   color: #f8fafc;
59 59   font-weight: 400;
60 60   font-size: 1rem;
... ... @@ -64,305 +64,373 @@
64 64   text-shadow: 0 2px 8px rgba(0, 26, 51, 0.95);
65 65   }
66 66  
67 - /* ---------- DIAGRAM ARCHITECTURE GRID ---------- */
68 - .fd-sip-diag .arch-grid {
69 - display: grid;
70 - grid-template-columns: 1fr 120px 1.2fr 120px 1fr;
71 - align-items: center;
72 - gap: 12px;
73 - margin-bottom: 36px;
69 + /* Disclaimer Banner */
70 + .fd-sip-doc .disclaimer-box {
71 + background: #f0f7fc;
72 + border-left: 5px solid var(--fd-blue);
73 + padding: 16px 20px;
74 + border-radius: 8px;
75 + margin-bottom: 28px;
76 + font-size: 0.9rem;
77 + line-height: 1.5;
74 74   }
75 75  
76 - .fd-sip-diag .node-box {
77 - background: rgba(255, 255, 255, 0.95);
78 - border: 2px solid var(--fd-lightgrey);
79 - border-radius: 16px;
80 - padding: 24px 20px;
81 - text-align: center;
82 - box-shadow: 0 8px 24px rgba(0, 30, 60, 0.06);
83 - position: relative;
84 - }
85 -
86 - .fd-sip-diag .node-box.fd-cloud {
87 - background: linear-gradient(180deg, #f0f7fc 0%, #ffffff 100%);
88 - border-color: var(--fd-blue);
89 - }
90 - .fd-sip-diag .node-box.firewall {
91 - background: linear-gradient(180deg, #fff5f5 0%, #ffffff 100%);
92 - border-color: var(--fd-red);
93 - }
94 - .fd-sip-diag .node-box.cust-pbx {
95 - background: linear-gradient(180deg, var(--fd-offwhite) 0%, #ffffff 100%);
96 - border-color: var(--fd-navy);
97 - }
98 -
99 - .fd-sip-diag .node-badge {
100 - display: inline-block;
101 - padding: 4px 10px;
102 - font-size: 0.72rem;
80 + /* Section Titles */
81 + .fd-sip-doc .section-title {
82 + color: var(--fd-navy);
83 + font-size: 1.35rem;
103 103   font-weight: 700;
104 - text-transform: uppercase;
105 - letter-spacing: 0.08em;
106 - border-radius: 20px;
107 - margin-bottom: 12px;
85 + margin: 36px 0 16px;
86 + border-bottom: 2px solid var(--fd-lightgrey);
87 + padding-bottom: 8px;
108 108   }
109 - .fd-cloud .node-badge { background: var(--fd-blue); color: #ffffff; }
110 - .firewall .node-badge { background: var(--fd-red); color: #ffffff; }
111 - .cust-pbx .node-badge { background: var(--fd-navy); color: #ffffff; }
112 112  
113 - .fd-sip-diag .node-box h3 {
114 - margin: 0 0 6px;
115 - font-size: 1.2rem;
116 - color: var(--fd-navy);
117 - font-weight: 700;
90 + /* Embedded Diagram Containers */
91 + .fd-sip-doc .diagram-card {
92 + background: #ffffff;
93 + border: 1px solid var(--fd-lightgrey);
94 + border-radius: 16px;
95 + padding: 24px;
96 + margin-bottom: 28px;
97 + box-shadow: 0 6px 20px rgba(0, 30, 60, 0.05);
98 + text-align: center;
118 118   }
119 - .fd-sip-diag .node-box p.ip-addr {
120 - font-family: monospace;
100 + .fd-sip-doc .diagram-card svg {
101 + max-width: 100%;
102 + height: auto;
103 + }
104 + .fd-sip-doc .diagram-caption {
121 121   font-size: 0.85rem;
122 - font-weight: 700;
123 123   color: var(--fd-slate);
124 - background: #eef4f8;
125 - padding: 4px 8px;
126 - border-radius: 6px;
127 - display: inline-block;
128 - margin: 4px 0 10px;
107 + margin-top: 12px;
108 + font-weight: 500;
129 129   }
130 - .fd-sip-diag .node-box p.desc {
131 - font-size: 0.82rem;
132 - color: var(--fd-slate);
133 - margin: 0;
134 - line-height: 1.4;
135 - }
136 136  
137 - /* Connector Arrows */
138 - .fd-sip-diag .flow-connector {
139 - text-align: center;
140 - position: relative;
111 + /* Specifications Grid */
112 + .fd-sip-doc .specs-grid {
113 + display: grid;
114 + grid-template-columns: repeat(auto-fit, minmax(260px, 1fr));
115 + gap: 16px;
116 + margin-bottom: 32px;
141 141   }
142 - .fd-sip-diag .arrow-line {
143 - height: 3px;
144 - background: var(--fd-blue);
145 - position: relative;
146 - margin: 12px 0;
118 + .fd-sip-doc .spec-card {
119 + background: var(--fd-offwhite);
120 + border: 1px solid var(--fd-lightgrey);
121 + border-radius: 12px;
122 + padding: 16px 20px;
147 147   }
148 - .fd-sip-diag .arrow-line::before, .fd-sip-diag .arrow-line::after {
149 - content: '';
150 - position: absolute;
151 - top: -4px;
152 - width: 0; height: 0;
153 - border-style: solid;
124 + .fd-sip-doc .spec-card .label {
125 + font-size: 0.75rem;
126 + text-transform: uppercase;
127 + font-weight: 700;
128 + color: var(--fd-grey);
129 + letter-spacing: 0.05em;
130 + margin-bottom: 4px;
154 154   }
155 - /* Left Arrowhead */
156 - .fd-sip-diag .arrow-line::before {
157 - left: -2px;
158 - border-width: 5px 8px 5px 0;
159 - border-color: transparent var(--fd-blue) transparent transparent;
160 - }
161 - /* Right Arrowhead */
162 - .fd-sip-diag .arrow-line::after {
163 - right: -2px;
164 - border-width: 5px 0 5px 8px;
165 - border-color: transparent transparent transparent var(--fd-blue);
166 - }
167 - .fd-sip-diag .flow-label {
168 - font-size: 0.72rem;
132 + .fd-sip-doc .spec-card .val {
133 + font-size: 1rem;
169 169   font-weight: 700;
170 170   color: var(--fd-navy);
171 - text-transform: uppercase;
172 - letter-spacing: 0.05em;
173 - background: var(--fd-offwhite);
174 - padding: 2px 6px;
175 - border-radius: 4px;
176 - border: 1px solid var(--fd-lightgrey);
177 177   }
137 + .fd-sip-doc .spec-card .subtext {
138 + font-size: 0.8rem;
139 + color: var(--fd-slate);
140 + margin-top: 4px;
141 + }
178 178  
179 - /* ---------- RULES & SPECS CARDS ---------- */
180 - .fd-sip-diag .rules-grid {
143 + /* Rules Grid */
144 + .fd-sip-doc .rules-grid {
181 181   display: grid;
182 182   grid-template-columns: 1fr 1fr;
183 183   gap: 20px;
184 184   margin-bottom: 32px;
185 185   }
186 - .fd-sip-diag .rule-card {
187 - background: rgba(255, 255, 255, 0.95);
150 + .fd-sip-doc .rule-box {
188 188   border: 1px solid var(--fd-lightgrey);
189 - border-left: 5px solid var(--fd-sky);
190 190   border-radius: 12px;
191 - padding: 20px 24px;
192 - box-shadow: 0 4px 16px rgba(0, 30, 60, 0.04);
153 + padding: 20px;
154 + background: #ffffff;
155 + box-shadow: 0 4px 12px rgba(0, 0, 0, 0.03);
193 193   }
194 - .fd-sip-diag .rule-card.outbound {
195 - border-left-color: var(--fd-blue);
196 - }
197 - .fd-sip-diag .rule-card h4 {
198 - margin: 0 0 10px;
199 - font-size: 1.05rem;
157 + .fd-sip-doc .rule-box h4 {
158 + margin: 0 0 12px;
200 200   color: var(--fd-navy);
201 - display: flex;
202 - align-items: center;
203 - gap: 8px;
160 + font-size: 1.05rem;
204 204   }
205 - .fd-sip-diag .rule-card ul {
162 + .fd-sip-doc .rule-box ul {
206 206   margin: 0;
207 - padding-left: 18px;
208 - font-size: 0.9rem;
209 - line-height: 1.5;
164 + padding-left: 20px;
165 + font-size: 0.88rem;
166 + line-height: 1.6;
210 210   }
211 - .fd-sip-diag .rule-card li { margin-bottom: 6px; }
212 212  
213 - /* ---------- TROUBLESHOOTING / PITFALLS SECTION ---------- */
214 - .fd-sip-diag .pitfalls-container {
215 - background: #fff8f8;
216 - border: 1px solid #fecaca;
217 - border-radius: 16px;
218 - padding: 28px;
219 - box-shadow: 0 8px 24px rgba(207, 51, 61, 0.05);
169 + /* Troubleshooting Table */
170 + .fd-sip-doc .tb-table {
171 + width: 100%;
172 + border-collapse: collapse;
173 + margin-bottom: 32px;
174 + font-size: 0.9rem;
220 220   }
221 - .fd-sip-diag .pitfalls-header {
222 - display: flex;
223 - align-items: center;
224 - gap: 12px;
225 - margin-bottom: 16px;
226 - }
227 - .fd-sip-diag .pitfalls-header h3 {
228 - margin: 0;
229 - color: var(--fd-red);
230 - font-size: 1.2rem;
231 - font-weight: 800;
232 - }
233 - .fd-sip-diag .pitfalls-grid {
234 - display: grid;
235 - grid-template-columns: 1fr 1fr;
236 - gap: 20px;
237 - }
238 - .fd-sip-diag .pitfall-item {
239 - background: #ffffff;
240 - border: 1px solid #fca5a5;
241 - border-radius: 10px;
242 - padding: 16px 20px;
243 - }
244 - .fd-sip-diag .pitfall-item h5 {
245 - margin: 0 0 6px;
246 - color: var(--fd-navy);
247 - font-size: 0.95rem;
176 + .fd-sip-doc .tb-table th {
177 + background: var(--fd-navy);
178 + color: #ffffff;
179 + text-align: left;
180 + padding: 12px 16px;
248 248   font-weight: 700;
249 249   }
250 - .fd-sip-diag .pitfall-item p {
251 - margin: 0;
252 - font-size: 0.88rem;
253 - color: var(--fd-slate);
254 - line-height: 1.45;
183 + .fd-sip-doc .tb-table th:first-child { border-top-left-radius: 8px; }
184 + .fd-sip-doc .tb-table th:last-child { border-top-right-radius: 8px; }
185 + .fd-sip-doc .tb-table td {
186 + padding: 14px 16px;
187 + border-bottom: 1px solid var(--fd-lightgrey);
188 + line-height: 1.5;
255 255   }
190 + .fd-sip-doc .tb-table tr:nth-child(even) { background: var(--fd-offwhite); }
191 + .fd-sip-doc .symptom { font-weight: 700; color: var(--fd-red); width: 28%; }
256 256  
257 - @media (max-width: 900px) {
258 - .fd-sip-diag .arch-grid { grid-template-columns: 1fr; gap: 20px; }
259 - .fd-sip-diag .flow-connector { display: none; }
260 - .fd-sip-diag .rules-grid, .fd-sip-diag .pitfalls-grid { grid-template-columns: 1fr; }
193 + @media (max-width: 768px) {
194 + .fd-sip-doc .rules-grid { grid-template-columns: 1fr; }
261 261   }
262 262  </style>
263 263  
264 -<div class="fd-sip-diag">
198 +<div class="fd-sip-doc">
265 265  
266 266   <!-- Header Banner -->
267 - <div class="diag-header">
268 - <p class="kicker">FirstDigital Technical Architecture</p>
269 - <h1>SIP Trunking Architecture & Traffic Flow</h1>
270 - <p class="sub">Reference guide for signaling (UDP 5060), media routing (RTP), and required customer firewall policies.</p>
201 + <div class="doc-header">
202 + <p class="kicker">FirstDigital Voice Operations</p>
203 + <h1>SIP Trunking Technical Reference</h1>
204 + <p class="sub">Network architecture, firewall requirements, and troubleshooting standards for customer SIP trunks.</p>
271 271   </div>
272 272  
273 - <!-- Architecture Flow Diagram -->
274 - <div class="arch-grid">
275 -
276 - <!-- FirstDigital SBC -->
277 - <div class="node-box fd-cloud">
278 - <span class="node-badge">FirstDigital Cloud</span>
279 - <h3>Cloud SBC</h3>
280 - <span class="ip-addr">FirstDigital SBC IP</span>
281 - <p class="desc">Central Session Border Controller managing inbound/outbound signaling & media.</p>
282 - </div>
207 + <!-- Disclaimer Notice -->
208 + <div class="disclaimer-box">
209 + <strong>Customer Responsibility Notice:</strong> Customers are responsible for the configuration and maintenance of their own routers, firewalls, and PBX equipment. FirstDigital provides these specifications to assist engineers during trunk integration.
210 + </div>
283 283  
284 - <!-- Flow Connector 1 -->
285 - <div class="flow-connector">
286 - <span class="flow-label">WAN SIP / RTP</span>
287 - <div class="arrow-line"></div>
288 - <span class="flow-label">UDP 5060</span>
289 - </div>
212 + <!-- DIAGRAM 1: Network Topology -->
213 + <div class="section-title">1. SIP Trunk Topology & Traffic Routing</div>
214 + <div class="diagram-card">
215 + <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 800 300" style="font-family:'Host Grotesk', system-ui, sans-serif;">
216 + <!-- Cloud Node -->
217 + <rect x="30" y="50" width="200" height="200" rx="12" fill="#f0f7fc" stroke="#307ab2" stroke-width="2"/>
218 + <rect x="45" y="35" width="170" height="26" rx="13" fill="#003366"/>
219 + <text x="130" y="52" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">FIRSTDIGITAL CLOUD</text>
220 + <text x="130" y="115" fill="#003366" font-size="14" font-weight="bold" text-anchor="middle">FirstDigital SBC</text>
221 + <rect x="55" y="130" width="150" height="24" rx="4" fill="#e2e8f0"/>
222 + <text x="130" y="146" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[FirstDigital_SBC_IP]</text>
223 + <text x="130" y="180" fill="#2e404d" font-size="10" text-anchor="middle">Signaling &amp; Audio Target</text>
290 290  
291 - <!-- Customer Firewall -->
292 - <div class="node-box firewall">
293 - <span class="node-badge">Boundary</span>
294 - <h3>Customer Firewall</h3>
295 - <span class="ip-addr">Public IP (Provided)</span>
296 - <p class="desc">Network perimeter executing NAT and inspecting incoming/outgoing UDP 5060 & RTP streams.</p>
297 - </div>
225 + <!-- Flow Connectors -->
226 + <path d="M 230 110 L 370 110" stroke="#307ab2" stroke-width="3" stroke-dasharray="6,4"/>
227 + <path d="M 370 160 L 230 160" stroke="#38b2e3" stroke-width="3"/>
228 + <polygon points="230,160 238,155 238,165" fill="#38b2e3"/>
229 + <polygon points="370,110 362,105 362,115" fill="#307ab2"/>
230 + <text x="300" y="100" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">UDP 5060 (SIP)</text>
231 + <text x="300" y="180" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">UDP 5k-65k (RTP)</text>
298 298  
299 - <!-- Flow Connector 2 -->
300 - <div class="flow-connector">
301 - <span class="flow-label">LAN Routing</span>
302 - <div class="arrow-line"></div>
303 - <span class="flow-label">Private Net</span>
304 - </div>
233 + <!-- Firewall Node -->
234 + <rect x="370" y="50" width="180" height="200" rx="12" fill="#fff5f5" stroke="#cf333d" stroke-width="2"/>
235 + <rect x="385" y="35" width="150" height="26" rx="13" fill="#cf333d"/>
236 + <text x="460" y="52" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">CUSTOMER FIREWALL</text>
237 + <text x="460" y="105" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">Public Edge Router</text>
238 + <rect x="385" y="120" width="150" height="24" rx="4" fill="#e2e8f0"/>
239 + <text x="460" y="136" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[Customer_Public_IP]</text>
240 + <text x="460" y="175" fill="#cf333d" font-size="10" font-weight="bold" text-anchor="middle">SIP ALG: DISABLED</text>
241 + <text x="460" y="195" fill="#2e404d" font-size="10" text-anchor="middle">Source NAT Active</text>
305 305  
306 - <!-- Customer PBX -->
307 - <div class="node-box cust-pbx">
308 - <span class="node-badge">Customer Premises</span>
309 - <h3>Customer PBX</h3>
310 - <span class="ip-addr">192.168.x.x (Private)</span>
311 - <p class="desc">Internal phone system handling extensions, call logic, and audio endpoints.</p>
243 + <!-- Internal LAN Path -->
244 + <path d="M 550 135 L 610 135" stroke="#2e404d" stroke-width="2"/>
245 +
246 + <!-- PBX Node -->
247 + <rect x="610" y="50" width="160" height="200" rx="12" fill="#f8fafc" stroke="#003366" stroke-width="2"/>
248 + <rect x="625" y="35" width="130" height="26" rx="13" fill="#003366"/>
249 + <text x="690" y="52" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">CUSTOMER PBX</text>
250 + <text x="690" y="115" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">Internal PBX / SBC</text>
251 + <rect x="625" y="130" width="130" height="24" rx="4" fill="#e2e8f0"/>
252 + <text x="690" y="146" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">192.168.x.x (LAN)</text>
253 + </svg>
254 + <div class="diagram-caption">Figure 1: Standard end-to-end SIP signaling and RTP media pathing via customer firewall.</div>
255 + </div>
256 +
257 + <!-- Specifications Grid -->
258 + <div class="section-title">2. Core Trunk Parameters</div>
259 + <div class="specs-grid">
260 + <div class="spec-card">
261 + <div class="label">Signaling Protocol</div>
262 + <div class="val">UDP 5060</div>
263 + <div class="subtext">Standard SIP port</div>
312 312   </div>
265 + <div class="spec-card">
266 + <div class="label">Primary Codec</div>
267 + <div class="val">G.711u</div>
268 + <div class="subtext">20ms packetization</div>
269 + </div>
270 + <div class="spec-card">
271 + <div class="label">DTMF Mode</div>
272 + <div class="val">RFC 2833</div>
273 + <div class="subtext">Out-of-band touch tones</div>
274 + </div>
275 + <div class="spec-card">
276 + <div class="label">DNIS Delivery</div>
277 + <div class="val">10 Digits</div>
278 + <div class="subtext">+1 stripped; Intl disabled by default</div>
279 + </div>
280 + <div class="spec-card">
281 + <div class="label">Authentication</div>
282 + <div class="val">IP Registration-less</div>
283 + <div class="subtext">No user/password required</div>
284 + </div>
285 + <div class="spec-card">
286 + <div class="label">SIP Advanced</div>
287 + <div class="val">Peer Path / Re-invite</div>
288 + <div class="subtext">Disabled / No re-invites permitted</div>
289 + </div>
290 + </div>
313 313  
292 + <!-- DIAGRAM 2: REWORKED FIREWALL PACKET FILTER & PORT MAP ILLUSTRATION -->
293 + <div class="section-title">3. Firewall Policy Rules & Packet Filter Action</div>
294 + <div class="diagram-card">
295 + <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 800 290" style="font-family:'Host Grotesk', system-ui, sans-serif;">
296 + <!-- Outer Frame -->
297 + <rect x="10" y="10" width="780" height="270" rx="12" fill="#f8fafc" stroke="#e2e8f0" stroke-width="2"/>
298 +
299 + <!-- FirstDigital WAN Side -->
300 + <text x="110" y="40" fill="#003366" font-size="12" font-weight="bold" text-anchor="middle">WAN SOURCE</text>
301 + <text x="110" y="58" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[FirstDigital_Subnet]</text>
302 +
303 + <!-- Firewall Barrier (Middle) -->
304 + <rect x="360" y="30" width="80" height="230" rx="8" fill="#fff5f5" stroke="#cf333d" stroke-width="2"/>
305 + <text x="400" y="135" fill="#cf333d" font-size="12" font-weight="bold" text-anchor="middle" transform="rotate(-90,400,135)">FIREWALL BOUNDARY</text>
306 +
307 + <!-- Customer LAN Side -->
308 + <text x="690" y="40" fill="#003366" font-size="12" font-weight="bold" text-anchor="middle">LAN DESTINATION</text>
309 + <text x="690" y="58" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[Customer_PBX_IP]</text>
310 +
311 + <!-- ROW 1: SIP SIGNALING (PASS) -->
312 + <path d="M 200 90 L 360 90" stroke="#2e7d32" stroke-width="2.5"/>
313 + <circle cx="380" cy="90" r="10" fill="#2e7d32"/>
314 + <text x="380" y="94" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">✓</text>
315 + <path d="M 400 90 L 580 90" stroke="#2e7d32" stroke-width="2.5"/>
316 + <polygon points="580,90 572,85 572,95" fill="#2e7d32"/>
317 +
318 + <rect x="220" y="72" width="120" height="22" rx="4" fill="#e8f5e9" stroke="#2e7d32"/>
319 + <text x="280" y="87" fill="#2e7d32" font-size="10" font-weight="bold" text-anchor="middle">SIP: UDP 5060</text>
320 + <text x="480" y="82" fill="#2e7d32" font-size="10" font-weight="bold" text-anchor="middle">FORWARD TO PBX</text>
321 +
322 + <!-- ROW 2: RTP AUDIO STREAM (PASS) -->
323 + <path d="M 200 150 L 360 150" stroke="#307ab2" stroke-width="2.5"/>
324 + <circle cx="380" cy="150" r="10" fill="#2e7d32"/>
325 + <text x="380" y="154" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">✓</text>
326 + <path d="M 400 150 L 580 150" stroke="#307ab2" stroke-width="2.5"/>
327 + <polygon points="580,150 572,145 572,155" fill="#307ab2"/>
328 +
329 + <rect x="210" y="132" width="140" height="22" rx="4" fill="#f0f7fc" stroke="#307ab2"/>
330 + <text x="280" y="147" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">RTP: UDP 5k - 65k</text>
331 + <text x="480" y="142" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">ALLOW MEDIA STREAM</text>
332 +
333 + <!-- ROW 3: SIP ALG / INSPECTION (BLOCKED) -->
334 + <path d="M 200 215 L 360 215" stroke="#cf333d" stroke-width="2.5" stroke-dasharray="4,4"/>
335 + <circle cx="380" cy="215" r="10" fill="#cf333d"/>
336 + <text x="380" y="219" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">✕</text>
337 +
338 + <rect x="220" y="197" width="120" height="22" rx="4" fill="#fff5f5" stroke="#cf333d"/>
339 + <text x="280" y="212" fill="#cf333d" font-size="10" font-weight="bold" text-anchor="middle">SIP ALG / STUN</text>
340 + <text x="485" y="212" fill="#cf333d" font-size="11" font-weight="bold">DISABLED (Prevents Header Modification)</text>
341 +
342 + <!-- Bottom Note -->
343 + <rect x="180" y="250" width="440" height="20" rx="4" fill="#e2e8f0"/>
344 + <text x="400" y="264" fill="#2e404d" font-size="10" font-weight="bold" text-anchor="middle">OUTBOUND EGRESS NAT: All traffic MUST egress sourcing from [Customer_Public_IP]</text>
345 + </svg>
346 + <div class="diagram-caption">Figure 2: Firewall packet-filtering policy—explicitly allowing signaling/media while disabling SIP ALG.</div>
314 314   </div>
315 315  
316 - <!-- Inbound & Outbound Traffic Rules -->
349 + <!-- Rules Text -->
317 317   <div class="rules-grid">
318 -
319 - <div class="rule-card">
320 - <h4>
321 - <svg width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="#38b2e3" stroke-width="2.5"><path d="M12 5v14M5 12l7 7 7-7"/></svg>
322 - Inbound Call Rules (FirstDigital → Customer)
323 - </h4>
351 + <div class="rule-box">
352 + <h4>Outbound Traffic Requirements</h4>
324 324   <ul>
325 - <li>FirstDigital SBC directs calls toward the <strong>Public IP</strong> provided by the customer.</li>
326 - <li>The customer's firewall must <strong>permit inbound UDP 5060</strong> sourced strictly from FirstDigital's SBC IP.</li>
327 - <li>Dynamic RTP audio port ranges must be allowed through the firewall once the SIP handshake completes.</li>
354 + <li>Outbound calls to FirstDigital must source directly from the registered Customer Public IP.</li>
355 + <li>Outbound calls must send Caller ID matching a phone number assigned to the trunk instance.</li>
356 + <li>FirstDigital will automatically reject calls sourcing from unknown or unauthorized IPs.</li>
328 328   </ul>
329 329   </div>
330 -
331 - <div class="rule-card outbound">
332 - <h4>
333 - <svg width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="#307ab2" stroke-width="2.5"><path d="M12 19V5M5 12l7-7 7 7"/></svg>
334 - Outbound Call Rules (Customer → FirstDigital)
335 - </h4>
359 + <div class="rule-box">
360 + <h4>Firewall & NAT Settings</h4>
336 336   <ul>
337 - <li>All signaling and audio streams <strong>must source from the registered Public IP</strong> provided to FirstDigital.</li>
338 - <li>FirstDigital enforces strict security and will <strong>automatically reject calls</strong> sourcing from unknown or unverified IPs.</li>
339 - <li>Firewall must perform proper Source NAT (SNAT) to map outgoing PBX packets to the designated public IP.</li>
362 + <li><strong>SIP ALG:</strong> Must be completely <u>DISABLED</u> on customer edge firewalls and routers.</li>
363 + <li><strong>RTP Media:</strong> Ensure UDP ports 5000-65000 are permitted for full audio stream delivery.</li>
364 + <li><strong>NAT Routing:</strong> Confirm outbound NAT egress explicitly maps internal PBX traffic to the registered public IP.</li>
340 340   </ul>
341 341   </div>
342 -
343 343   </div>
344 344  
345 - <!-- Common Troubleshooting Pitfalls -->
346 - <div class="pitfalls-container">
347 - <div class="pitfalls-header">
348 - <svg width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="#cf333d" stroke-width="2.5"><path d="M10.29 3.86L1.82 18a2 2 0 001.71 3h16.94a2 2 0 001.71-3L13.71 3.86a2 2 0 00-3.42 0zM12 9v4M12 17h.01"/></svg>
349 - <h3>Most Common SIP & Audio Issues</h3>
350 - </div>
369 + <!-- DIAGRAM 3: One-Way Audio Problem -->
370 + <div class="section-title">4. Common Audio Defect: Private IP Header Leakage</div>
371 + <div class="diagram-card">
372 + <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 800 240" style="font-family:'Host Grotesk', system-ui, sans-serif;">
373 + <!-- SBC Box -->
374 + <rect x="40" y="40" width="180" height="160" rx="10" fill="#f0f7fc" stroke="#307ab2" stroke-width="2"/>
375 + <text x="130" y="80" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">FirstDigital SBC</text>
376 + <text x="130" y="100" fill="#2e404d" font-size="10" text-anchor="middle">Public Media Gateway</text>
351 351  
352 - <div class="pitfalls-grid">
353 -
354 - <div class="pitfall-item">
355 - <h5>1. One-Way or No Audio (Dropped RTP Packets)</h5>
356 - <p>Occurs when the customer firewall allows SIP signaling (UDP 5060) to connect the call, but blocks or drops the dynamic RTP audio stream ports. Ensure RTP port ranges are open between the SBC and PBX.</p>
357 - </div>
378 + <!-- Broken Return Audio Path -->
379 + <path d="M 220 160 L 410 160" stroke="#cf333d" stroke-width="3" stroke-dasharray="4,4"/>
380 + <circle cx="420" cy="160" r="12" fill="#cf333d"/>
381 + <text x="420" y="165" fill="#ffffff" font-size="13" font-weight="bold" text-anchor="middle">X</text>
382 + <text x="315" y="150" fill="#cf333d" font-size="10" font-weight="bold" text-anchor="middle">Audio Fails: 192.168.x.x Unreachable</text>
358 358  
359 - <div class="pitfall-item">
360 - <h5>2. Private IP Leakage in SIP SDP Headers</h5>
361 - <p>The firewall fails to rewrite the SDP payload, causing the audio stream to request packet delivery to the PBX's <em>private IP</em> (e.g. <code>10.x.x.x</code> or <code>192.168.x.x</code>) rather than its external public IP address.</p>
362 - </div>
384 + <!-- Firewall Box -->
385 + <rect x="450" y="40" width="120" height="160" rx="10" fill="#fff5f5" stroke="#cf333d" stroke-width="2"/>
386 + <text x="510" y="120" fill="#cf333d" font-size="12" font-weight="bold" text-anchor="middle">Firewall</text>
363 363  
364 - </div>
388 + <!-- PBX Box -->
389 + <rect x="620" y="40" width="140" height="160" rx="10" fill="#f8fafc" stroke="#003366" stroke-width="2"/>
390 + <text x="690" y="75" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">Customer PBX</text>
391 +
392 + <!-- Problem Header Packet -->
393 + <path d="M 620 85 L 230 85" stroke="#307ab2" stroke-width="2"/>
394 + <rect x="310" y="60" width="240" height="24" rx="4" fill="#fffbe0" stroke="#d97706"/>
395 + <text x="430" y="76" fill="#b45309" font-size="10" font-weight="bold" text-anchor="middle">SDP Header: Audio IP = 192.168.1.50 (Private IP Leak!)</text>
396 + </svg>
397 + <div class="diagram-caption">Figure 3: Why one-way audio occurs—the PBX requests return audio to an unreachable internal private IP address.</div>
365 365   </div>
366 366  
400 + <!-- Troubleshooting Matrix -->
401 + <div class="section-title">5. Troubleshooting Matrix</div>
402 + <table class="tb-table">
403 + <thead>
404 + <tr>
405 + <th>Symptom</th>
406 + <th>Root Cause & Resolution Step</th>
407 + </tr>
408 + </thead>
409 + <tbody>
410 + <tr>
411 + <td class="symptom">No Inbound Calls</td>
412 + <td>Verify firewall allows <code>UDP 5060</code> from FirstDigital's subnet. Confirm <strong>SIP ALG is disabled</strong> on edge devices.</td>
413 + </tr>
414 + <tr>
415 + <td class="symptom">No Outbound Calls</td>
416 + <td>Confirm outbound SIP traffic is directed to FirstDigital's SBC IP on <code>UDP 5060</code>. Verify traffic sources from your registered Public IP and uses an assigned Caller ID.</td>
417 + </tr>
418 + <tr>
419 + <td class="symptom">One-Way or No Audio</td>
420 + <td><strong>Common Issue:</strong> PBX is leaking private IP addresses (e.g., <code>10.x.x.x</code> or <code>192.168.x.x</code>) in the SIP SDP header. Fix PBX NAT settings, SBC Media Address Override, or STUN configuration. Disable SIP ALG.</td>
421 + </tr>
422 + <tr>
423 + <td class="symptom">Touch Tones Not Working</td>
424 + <td>Configure PBX and endpoints to send DTMF out-of-band using <strong>RFC 2833</strong> (telephony-event).</td>
425 + </tr>
426 + <tr>
427 + <td class="symptom">Calls Routing Incorrectly</td>
428 + <td>Inspect received <strong>DNIS digit delivery</strong>. FirstDigital defaults to 10-digit delivery. Update PBX inbound routing rules to match.</td>
429 + </tr>
430 + <tr>
431 + <td class="symptom">Forwarded Calls Have One-Way Audio</td>
432 + <td>Occurs if FirstDigital enabled "NAT Media" as a temporary workaround for private IP header leaks. Resolving the PBX private IP leak allows FirstDigital to disable NAT Media settings, resolving transfer audio.</td>
433 + </tr>
434 + </tbody>
435 + </table>
436 +
367 367  </div>
368 368  {{/html}}