Changes for page SIP
Last modified by Aaron Blackburn on 2026/09/01 19:00
From version 1.3
edited by Aaron Blackburn
on 2026/09/01 18:33
on 2026/09/01 18:33
Change comment:
There is no comment for this version
To version 1.4
edited by Aaron Blackburn
on 2026/09/01 19:00
on 2026/09/01 19:00
Change comment:
There is no comment for this version
Summary
-
Page properties (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -1,7 +1,7 @@ 1 1 {{html clean="false"}} 2 2 <!-- 3 3 XWiki usage: Paste into an HTML macro on your page. 4 - Note: All FirstDigital IPs have been sanitized for public s afety.4 + Note: All FirstDigital public IPs have been sanitized for public wiki security. 5 5 --> 6 6 <style> 7 7 @import url('https://fonts.googleapis.com/css2?family=Host+Grotesk:wght@300;400;500;600;700;800&display=swap'); ... ... @@ -14,6 +14,7 @@ 14 14 --fd-sky: #38b2e3; 15 15 --fd-bright-cyan: #5ed2ff; 16 16 --fd-red: #cf333d; 17 + --fd-green: #2e7d32; 17 17 --fd-slate: #2e404d; 18 18 --fd-grey: #8f9499; 19 19 --fd-lightgrey: #e2e8f0; ... ... @@ -65,7 +65,7 @@ 65 65 text-shadow: 0 2px 8px rgba(0, 26, 51, 0.95); 66 66 } 67 67 68 - /* Notice Banner */69 + /* Disclaimer Banner */ 69 69 .fd-sip-doc .disclaimer-box { 70 70 background: #f0f7fc; 71 71 border-left: 5px solid var(--fd-blue); ... ... @@ -76,16 +76,38 @@ 76 76 line-height: 1.5; 77 77 } 78 78 79 - /* S pecificationsGrid*/80 + /* Section Titles */ 80 80 .fd-sip-doc .section-title { 81 81 color: var(--fd-navy); 82 82 font-size: 1.35rem; 83 83 font-weight: 700; 84 - margin: 3 2px 0 16px;85 + margin: 36px 0 16px; 85 85 border-bottom: 2px solid var(--fd-lightgrey); 86 86 padding-bottom: 8px; 87 87 } 88 88 90 + /* Embedded Diagram Containers */ 91 + .fd-sip-doc .diagram-card { 92 + background: #ffffff; 93 + border: 1px solid var(--fd-lightgrey); 94 + border-radius: 16px; 95 + padding: 24px; 96 + margin-bottom: 28px; 97 + box-shadow: 0 6px 20px rgba(0, 30, 60, 0.05); 98 + text-align: center; 99 + } 100 + .fd-sip-doc .diagram-card svg { 101 + max-width: 100%; 102 + height: auto; 103 + } 104 + .fd-sip-doc .diagram-caption { 105 + font-size: 0.85rem; 106 + color: var(--fd-slate); 107 + margin-top: 12px; 108 + font-weight: 500; 109 + } 110 + 111 + /* Specifications Grid */ 89 89 .fd-sip-doc .specs-grid { 90 90 display: grid; 91 91 grid-template-columns: repeat(auto-fit, minmax(260px, 1fr)); ... ... @@ -117,7 +117,7 @@ 117 117 margin-top: 4px; 118 118 } 119 119 120 - /* Rules & Requirements*/143 + /* Rules Grid */ 121 121 .fd-sip-doc .rules-grid { 122 122 display: grid; 123 123 grid-template-columns: 1fr 1fr; ... ... @@ -174,20 +174,65 @@ 174 174 175 175 <div class="fd-sip-doc"> 176 176 177 - <!-- Header --> 200 + <!-- Header Banner --> 178 178 <div class="doc-header"> 179 179 <p class="kicker">FirstDigital Voice Operations</p> 180 - <h1>SIP Trunking Technical Specifications</h1>181 - <p class="sub"> Configuration standards, firewallpolicies, and troubleshootingprocedures forenterpriseSIP trunks.</p>203 + <h1>SIP Trunking Technical Reference</h1> 204 + <p class="sub">Network architecture, firewall requirements, and troubleshooting standards for customer SIP trunks.</p> 182 182 </div> 183 183 184 - <!-- Disclaimer --> 207 + <!-- Disclaimer Notice --> 185 185 <div class="disclaimer-box"> 186 - <strong>Customer Responsibility Notice:</strong> Customers are responsible for the configuration and fine-tuningof their ownedgerouters, firewalls, and PBX equipment.209 + <strong>Customer Responsibility Notice:</strong> Customers are responsible for the configuration and maintenance of their own routers, firewalls, and PBX equipment. FirstDigital provides these specifications to assist engineers during trunk integration. 187 187 </div> 188 188 189 - <!-- Standard Specifications Grid --> 190 - <div class="section-title">Standard Trunk Specifications</div> 212 + <!-- DIAGRAM 1: Network Topology --> 213 + <div class="section-title">1. SIP Trunk Topology & Traffic Routing</div> 214 + <div class="diagram-card"> 215 + <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 800 300" style="font-family:'Host Grotesk', system-ui, sans-serif;"> 216 + <!-- Cloud Node --> 217 + <rect x="30" y="50" width="200" height="200" rx="12" fill="#f0f7fc" stroke="#307ab2" stroke-width="2"/> 218 + <rect x="45" y="35" width="170" height="26" rx="13" fill="#003366"/> 219 + <text x="130" y="52" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">FIRSTDIGITAL CLOUD</text> 220 + <text x="130" y="115" fill="#003366" font-size="14" font-weight="bold" text-anchor="middle">FirstDigital SBC</text> 221 + <rect x="55" y="130" width="150" height="24" rx="4" fill="#e2e8f0"/> 222 + <text x="130" y="146" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[FirstDigital_SBC_IP]</text> 223 + <text x="130" y="180" fill="#2e404d" font-size="10" text-anchor="middle">Signaling & Audio Target</text> 224 + 225 + <!-- Flow Connectors --> 226 + <path d="M 230 110 L 370 110" stroke="#307ab2" stroke-width="3" stroke-dasharray="6,4"/> 227 + <path d="M 370 160 L 230 160" stroke="#38b2e3" stroke-width="3"/> 228 + <polygon points="230,160 238,155 238,165" fill="#38b2e3"/> 229 + <polygon points="370,110 362,105 362,115" fill="#307ab2"/> 230 + <text x="300" y="100" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">UDP 5060 (SIP)</text> 231 + <text x="300" y="180" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">UDP 5k-65k (RTP)</text> 232 + 233 + <!-- Firewall Node --> 234 + <rect x="370" y="50" width="180" height="200" rx="12" fill="#fff5f5" stroke="#cf333d" stroke-width="2"/> 235 + <rect x="385" y="35" width="150" height="26" rx="13" fill="#cf333d"/> 236 + <text x="460" y="52" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">CUSTOMER FIREWALL</text> 237 + <text x="460" y="105" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">Public Edge Router</text> 238 + <rect x="385" y="120" width="150" height="24" rx="4" fill="#e2e8f0"/> 239 + <text x="460" y="136" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[Customer_Public_IP]</text> 240 + <text x="460" y="175" fill="#cf333d" font-size="10" font-weight="bold" text-anchor="middle">SIP ALG: DISABLED</text> 241 + <text x="460" y="195" fill="#2e404d" font-size="10" text-anchor="middle">Source NAT Active</text> 242 + 243 + <!-- Internal LAN Path --> 244 + <path d="M 550 135 L 610 135" stroke="#2e404d" stroke-width="2"/> 245 + 246 + <!-- PBX Node --> 247 + <rect x="610" y="50" width="160" height="200" rx="12" fill="#f8fafc" stroke="#003366" stroke-width="2"/> 248 + <rect x="625" y="35" width="130" height="26" rx="13" fill="#003366"/> 249 + <text x="690" y="52" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">CUSTOMER PBX</text> 250 + <text x="690" y="115" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">Internal PBX / SBC</text> 251 + <rect x="625" y="130" width="130" height="24" rx="4" fill="#e2e8f0"/> 252 + <text x="690" y="146" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">192.168.x.x (LAN)</text> 253 + </svg> 254 + <div class="diagram-caption">Figure 1: Standard end-to-end SIP signaling and RTP media pathing via customer firewall.</div> 255 + </div> 256 + 257 + <!-- Specifications Grid --> 258 + <div class="section-title">2. Core Trunk Parameters</div> 191 191 <div class="specs-grid"> 192 192 <div class="spec-card"> 193 193 <div class="label">Signaling Protocol</div> ... ... @@ -205,7 +205,7 @@ 205 205 <div class="subtext">Out-of-band touch tones</div> 206 206 </div> 207 207 <div class="spec-card"> 208 - <div class="label">DNIS Di gits</div>276 + <div class="label">DNIS Delivery</div> 209 209 <div class="val">10 Digits</div> 210 210 <div class="subtext">+1 stripped; Intl disabled by default</div> 211 211 </div> ... ... @@ -221,29 +221,116 @@ 221 221 </div> 222 222 </div> 223 223 224 - <!-- Rules & Firewall --> 225 - <div class="section-title">Network & Firewall Rules</div> 292 + <!-- DIAGRAM 2: REWORKED FIREWALL PACKET FILTER & PORT MAP ILLUSTRATION --> 293 + <div class="section-title">3. Firewall Policy Rules & Packet Filter Action</div> 294 + <div class="diagram-card"> 295 + <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 800 290" style="font-family:'Host Grotesk', system-ui, sans-serif;"> 296 + <!-- Outer Frame --> 297 + <rect x="10" y="10" width="780" height="270" rx="12" fill="#f8fafc" stroke="#e2e8f0" stroke-width="2"/> 298 + 299 + <!-- FirstDigital WAN Side --> 300 + <text x="110" y="40" fill="#003366" font-size="12" font-weight="bold" text-anchor="middle">WAN SOURCE</text> 301 + <text x="110" y="58" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[FirstDigital_Subnet]</text> 302 + 303 + <!-- Firewall Barrier (Middle) --> 304 + <rect x="360" y="30" width="80" height="230" rx="8" fill="#fff5f5" stroke="#cf333d" stroke-width="2"/> 305 + <text x="400" y="135" fill="#cf333d" font-size="12" font-weight="bold" text-anchor="middle" transform="rotate(-90,400,135)">FIREWALL BOUNDARY</text> 306 + 307 + <!-- Customer LAN Side --> 308 + <text x="690" y="40" fill="#003366" font-size="12" font-weight="bold" text-anchor="middle">LAN DESTINATION</text> 309 + <text x="690" y="58" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[Customer_PBX_IP]</text> 310 + 311 + <!-- ROW 1: SIP SIGNALING (PASS) --> 312 + <path d="M 200 90 L 360 90" stroke="#2e7d32" stroke-width="2.5"/> 313 + <circle cx="380" cy="90" r="10" fill="#2e7d32"/> 314 + <text x="380" y="94" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">✓</text> 315 + <path d="M 400 90 L 580 90" stroke="#2e7d32" stroke-width="2.5"/> 316 + <polygon points="580,90 572,85 572,95" fill="#2e7d32"/> 317 + 318 + <rect x="220" y="72" width="120" height="22" rx="4" fill="#e8f5e9" stroke="#2e7d32"/> 319 + <text x="280" y="87" fill="#2e7d32" font-size="10" font-weight="bold" text-anchor="middle">SIP: UDP 5060</text> 320 + <text x="480" y="82" fill="#2e7d32" font-size="10" font-weight="bold" text-anchor="middle">FORWARD TO PBX</text> 321 + 322 + <!-- ROW 2: RTP AUDIO STREAM (PASS) --> 323 + <path d="M 200 150 L 360 150" stroke="#307ab2" stroke-width="2.5"/> 324 + <circle cx="380" cy="150" r="10" fill="#2e7d32"/> 325 + <text x="380" y="154" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">✓</text> 326 + <path d="M 400 150 L 580 150" stroke="#307ab2" stroke-width="2.5"/> 327 + <polygon points="580,150 572,145 572,155" fill="#307ab2"/> 328 + 329 + <rect x="210" y="132" width="140" height="22" rx="4" fill="#f0f7fc" stroke="#307ab2"/> 330 + <text x="280" y="147" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">RTP: UDP 5k - 65k</text> 331 + <text x="480" y="142" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">ALLOW MEDIA STREAM</text> 332 + 333 + <!-- ROW 3: SIP ALG / INSPECTION (BLOCKED) --> 334 + <path d="M 200 215 L 360 215" stroke="#cf333d" stroke-width="2.5" stroke-dasharray="4,4"/> 335 + <circle cx="380" cy="215" r="10" fill="#cf333d"/> 336 + <text x="380" y="219" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">✕</text> 337 + 338 + <rect x="220" y="197" width="120" height="22" rx="4" fill="#fff5f5" stroke="#cf333d"/> 339 + <text x="280" y="212" fill="#cf333d" font-size="10" font-weight="bold" text-anchor="middle">SIP ALG / STUN</text> 340 + <text x="485" y="212" fill="#cf333d" font-size="11" font-weight="bold">DISABLED (Prevents Header Modification)</text> 341 + 342 + <!-- Bottom Note --> 343 + <rect x="180" y="250" width="440" height="20" rx="4" fill="#e2e8f0"/> 344 + <text x="400" y="264" fill="#2e404d" font-size="10" font-weight="bold" text-anchor="middle">OUTBOUND EGRESS NAT: All traffic MUST egress sourcing from [Customer_Public_IP]</text> 345 + </svg> 346 + <div class="diagram-caption">Figure 2: Firewall packet-filtering policy—explicitly allowing signaling/media while disabling SIP ALG.</div> 347 + </div> 348 + 349 + <!-- Rules Text --> 226 226 <div class="rules-grid"> 227 227 <div class="rule-box"> 228 - <h4>Outbound Signaling& CallerID</h4>352 + <h4>Outbound Traffic Requirements</h4> 229 229 <ul> 230 - <li>Outbound requeststo FirstDigital must source directly from the Customer Public IPprovided during turn-up.</li>231 - <li>Outbound calls must presentaCaller ID number assigned to thespecifictrunk instance.</li>232 - <li> Ensure outboundNAT egressmatches theregisteredpublicIPaddress.</li>354 + <li>Outbound calls to FirstDigital must source directly from the registered Customer Public IP.</li> 355 + <li>Outbound calls must send Caller ID matching a phone number assigned to the trunk instance.</li> 356 + <li>FirstDigital will automatically reject calls sourcing from unknown or unauthorized IPs.</li> 233 233 </ul> 234 234 </div> 235 235 <div class="rule-box"> 236 - <h4>Firewall & PerimeterSetup</h4>360 + <h4>Firewall & NAT Settings</h4> 237 237 <ul> 238 - <li><strong>SIP ALG:</strong> Must be <u>DISABLED</u> globally on customerrouters/firewalls.</li>239 - <li><strong> InboundRules:</strong>Allow traffic from FirstDigital's SBC subnet across <code>UDP 5000-65000</code>.</li>240 - <li><strong> EgressRouting:</strong>Verify NATroutingforFirstDigital'ssubnetexitsout ofthedesignated public IP.</li>362 + <li><strong>SIP ALG:</strong> Must be completely <u>DISABLED</u> on customer edge firewalls and routers.</li> 363 + <li><strong>RTP Media:</strong> Ensure UDP ports 5000-65000 are permitted for full audio stream delivery.</li> 364 + <li><strong>NAT Routing:</strong> Confirm outbound NAT egress explicitly maps internal PBX traffic to the registered public IP.</li> 241 241 </ul> 242 242 </div> 243 243 </div> 244 244 369 + <!-- DIAGRAM 3: One-Way Audio Problem --> 370 + <div class="section-title">4. Common Audio Defect: Private IP Header Leakage</div> 371 + <div class="diagram-card"> 372 + <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 800 240" style="font-family:'Host Grotesk', system-ui, sans-serif;"> 373 + <!-- SBC Box --> 374 + <rect x="40" y="40" width="180" height="160" rx="10" fill="#f0f7fc" stroke="#307ab2" stroke-width="2"/> 375 + <text x="130" y="80" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">FirstDigital SBC</text> 376 + <text x="130" y="100" fill="#2e404d" font-size="10" text-anchor="middle">Public Media Gateway</text> 377 + 378 + <!-- Broken Return Audio Path --> 379 + <path d="M 220 160 L 410 160" stroke="#cf333d" stroke-width="3" stroke-dasharray="4,4"/> 380 + <circle cx="420" cy="160" r="12" fill="#cf333d"/> 381 + <text x="420" y="165" fill="#ffffff" font-size="13" font-weight="bold" text-anchor="middle">X</text> 382 + <text x="315" y="150" fill="#cf333d" font-size="10" font-weight="bold" text-anchor="middle">Audio Fails: 192.168.x.x Unreachable</text> 383 + 384 + <!-- Firewall Box --> 385 + <rect x="450" y="40" width="120" height="160" rx="10" fill="#fff5f5" stroke="#cf333d" stroke-width="2"/> 386 + <text x="510" y="120" fill="#cf333d" font-size="12" font-weight="bold" text-anchor="middle">Firewall</text> 387 + 388 + <!-- PBX Box --> 389 + <rect x="620" y="40" width="140" height="160" rx="10" fill="#f8fafc" stroke="#003366" stroke-width="2"/> 390 + <text x="690" y="75" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">Customer PBX</text> 391 + 392 + <!-- Problem Header Packet --> 393 + <path d="M 620 85 L 230 85" stroke="#307ab2" stroke-width="2"/> 394 + <rect x="310" y="60" width="240" height="24" rx="4" fill="#fffbe0" stroke="#d97706"/> 395 + <text x="430" y="76" fill="#b45309" font-size="10" font-weight="bold" text-anchor="middle">SDP Header: Audio IP = 192.168.1.50 (Private IP Leak!)</text> 396 + </svg> 397 + <div class="diagram-caption">Figure 3: Why one-way audio occurs—the PBX requests return audio to an unreachable internal private IP address.</div> 398 + </div> 399 + 245 245 <!-- Troubleshooting Matrix --> 246 - <div class="section-title"> SIPTrunk Troubleshooting Matrix</div>401 + <div class="section-title">5. Troubleshooting Matrix</div> 247 247 <table class="tb-table"> 248 248 <thead> 249 249 <tr> ... ... @@ -254,27 +254,27 @@ 254 254 <tbody> 255 255 <tr> 256 256 <td class="symptom">No Inbound Calls</td> 257 - <td>Verify firewall permits <code>UDP 5060</code> from FirstDigital's subnet. Confirm <strong>SIP ALG is disabled</strong> on edge devices.</td>412 + <td>Verify firewall allows <code>UDP 5060</code> from FirstDigital's subnet. Confirm <strong>SIP ALG is disabled</strong> on edge devices.</td> 258 258 </tr> 259 259 <tr> 260 260 <td class="symptom">No Outbound Calls</td> 261 - <td>Confirm destination SIP targetandport(<code>UDP 5060</code>). Verifyoutbound traffic sources from yourdesignatedpublic IP.EnsureCaller ID matches an activenumberon thetrunk.</td>416 + <td>Confirm outbound SIP traffic is directed to FirstDigital's SBC IP on <code>UDP 5060</code>. Verify traffic sources from your registered Public IP and uses an assigned Caller ID.</td> 262 262 </tr> 263 263 <tr> 264 264 <td class="symptom">One-Way or No Audio</td> 265 - <td><strong>Common Issue:</strong> PBX is sending private IP addresses (e.g., <code>10.x.x.x</code> or <code>192.168.x.x</code>) insidethe SIP SDP header.CheckPBX NAT settings, SBC Media Address Override, or STUN. Disable SIP ALG.</td>420 + <td><strong>Common Issue:</strong> PBX is leaking private IP addresses (e.g., <code>10.x.x.x</code> or <code>192.168.x.x</code>) in the SIP SDP header. Fix PBX NAT settings, SBC Media Address Override, or STUN configuration. Disable SIP ALG.</td> 266 266 </tr> 267 267 <tr> 268 - <td class="symptom"> DTMFTones NotRecognized</td>423 + <td class="symptom">Touch Tones Not Working</td> 269 269 <td>Configure PBX and endpoints to send DTMF out-of-band using <strong>RFC 2833</strong> (telephony-event).</td> 270 270 </tr> 271 271 <tr> 272 - <td class="symptom">Calls NotRingingCorrectExtension</td>273 - <td>Inspect sent/received <strong>DNIS digit delivery</strong>. FirstDigital defaults tosending10digits.Adjust PBX inbound routing rules to match.</td>427 + <td class="symptom">Calls Routing Incorrectly</td> 428 + <td>Inspect received <strong>DNIS digit delivery</strong>. FirstDigital defaults to 10-digit delivery. Update PBX inbound routing rules to match.</td> 274 274 </tr> 275 275 <tr> 276 276 <td class="symptom">Forwarded Calls Have One-Way Audio</td> 277 - <td> TypicallycausedwhenFirstDigital enables"NAT Media" as a temporary workaround for private IP leaks. Resolving the PBX private IPheaderleak allows FirstDigital toremoveNAT Media settings, restoringcalltransfer audio.</td>432 + <td>Occurs if FirstDigital enabled "NAT Media" as a temporary workaround for private IP header leaks. Resolving the PBX private IP leak allows FirstDigital to disable NAT Media settings, resolving transfer audio.</td> 278 278 </tr> 279 279 </tbody> 280 280 </table>