Changes for page SIP

Last modified by Aaron Blackburn on 2026/09/01 19:00

From version 1.3
edited by Aaron Blackburn
on 2026/09/01 18:33
Change comment: There is no comment for this version
To version 1.4
edited by Aaron Blackburn
on 2026/09/01 19:00
Change comment: There is no comment for this version

Summary

Details

Page properties
Content
... ... @@ -1,7 +1,7 @@
1 1  {{html clean="false"}}
2 2  <!--
3 3   XWiki usage: Paste into an HTML macro on your page.
4 - Note: All FirstDigital IPs have been sanitized for public safety.
4 + Note: All FirstDigital public IPs have been sanitized for public wiki security.
5 5  -->
6 6  <style>
7 7   @import url('https://fonts.googleapis.com/css2?family=Host+Grotesk:wght@300;400;500;600;700;800&display=swap');
... ... @@ -14,6 +14,7 @@
14 14   --fd-sky: #38b2e3;
15 15   --fd-bright-cyan: #5ed2ff;
16 16   --fd-red: #cf333d;
17 + --fd-green: #2e7d32;
17 17   --fd-slate: #2e404d;
18 18   --fd-grey: #8f9499;
19 19   --fd-lightgrey: #e2e8f0;
... ... @@ -65,7 +65,7 @@
65 65   text-shadow: 0 2px 8px rgba(0, 26, 51, 0.95);
66 66   }
67 67  
68 - /* Notice Banner */
69 + /* Disclaimer Banner */
69 69   .fd-sip-doc .disclaimer-box {
70 70   background: #f0f7fc;
71 71   border-left: 5px solid var(--fd-blue);
... ... @@ -76,16 +76,38 @@
76 76   line-height: 1.5;
77 77   }
78 78  
79 - /* Specifications Grid */
80 + /* Section Titles */
80 80   .fd-sip-doc .section-title {
81 81   color: var(--fd-navy);
82 82   font-size: 1.35rem;
83 83   font-weight: 700;
84 - margin: 32px 0 16px;
85 + margin: 36px 0 16px;
85 85   border-bottom: 2px solid var(--fd-lightgrey);
86 86   padding-bottom: 8px;
87 87   }
88 88  
90 + /* Embedded Diagram Containers */
91 + .fd-sip-doc .diagram-card {
92 + background: #ffffff;
93 + border: 1px solid var(--fd-lightgrey);
94 + border-radius: 16px;
95 + padding: 24px;
96 + margin-bottom: 28px;
97 + box-shadow: 0 6px 20px rgba(0, 30, 60, 0.05);
98 + text-align: center;
99 + }
100 + .fd-sip-doc .diagram-card svg {
101 + max-width: 100%;
102 + height: auto;
103 + }
104 + .fd-sip-doc .diagram-caption {
105 + font-size: 0.85rem;
106 + color: var(--fd-slate);
107 + margin-top: 12px;
108 + font-weight: 500;
109 + }
110 +
111 + /* Specifications Grid */
89 89   .fd-sip-doc .specs-grid {
90 90   display: grid;
91 91   grid-template-columns: repeat(auto-fit, minmax(260px, 1fr));
... ... @@ -117,7 +117,7 @@
117 117   margin-top: 4px;
118 118   }
119 119  
120 - /* Rules & Requirements */
143 + /* Rules Grid */
121 121   .fd-sip-doc .rules-grid {
122 122   display: grid;
123 123   grid-template-columns: 1fr 1fr;
... ... @@ -174,20 +174,65 @@
174 174  
175 175  <div class="fd-sip-doc">
176 176  
177 - <!-- Header -->
200 + <!-- Header Banner -->
178 178   <div class="doc-header">
179 179   <p class="kicker">FirstDigital Voice Operations</p>
180 - <h1>SIP Trunking Technical Specifications</h1>
181 - <p class="sub">Configuration standards, firewall policies, and troubleshooting procedures for enterprise SIP trunks.</p>
203 + <h1>SIP Trunking Technical Reference</h1>
204 + <p class="sub">Network architecture, firewall requirements, and troubleshooting standards for customer SIP trunks.</p>
182 182   </div>
183 183  
184 - <!-- Disclaimer -->
207 + <!-- Disclaimer Notice -->
185 185   <div class="disclaimer-box">
186 - <strong>Customer Responsibility Notice:</strong> Customers are responsible for the configuration and fine-tuning of their own edge routers, firewalls, and PBX equipment.
209 + <strong>Customer Responsibility Notice:</strong> Customers are responsible for the configuration and maintenance of their own routers, firewalls, and PBX equipment. FirstDigital provides these specifications to assist engineers during trunk integration.
187 187   </div>
188 188  
189 - <!-- Standard Specifications Grid -->
190 - <div class="section-title">Standard Trunk Specifications</div>
212 + <!-- DIAGRAM 1: Network Topology -->
213 + <div class="section-title">1. SIP Trunk Topology & Traffic Routing</div>
214 + <div class="diagram-card">
215 + <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 800 300" style="font-family:'Host Grotesk', system-ui, sans-serif;">
216 + <!-- Cloud Node -->
217 + <rect x="30" y="50" width="200" height="200" rx="12" fill="#f0f7fc" stroke="#307ab2" stroke-width="2"/>
218 + <rect x="45" y="35" width="170" height="26" rx="13" fill="#003366"/>
219 + <text x="130" y="52" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">FIRSTDIGITAL CLOUD</text>
220 + <text x="130" y="115" fill="#003366" font-size="14" font-weight="bold" text-anchor="middle">FirstDigital SBC</text>
221 + <rect x="55" y="130" width="150" height="24" rx="4" fill="#e2e8f0"/>
222 + <text x="130" y="146" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[FirstDigital_SBC_IP]</text>
223 + <text x="130" y="180" fill="#2e404d" font-size="10" text-anchor="middle">Signaling &amp; Audio Target</text>
224 +
225 + <!-- Flow Connectors -->
226 + <path d="M 230 110 L 370 110" stroke="#307ab2" stroke-width="3" stroke-dasharray="6,4"/>
227 + <path d="M 370 160 L 230 160" stroke="#38b2e3" stroke-width="3"/>
228 + <polygon points="230,160 238,155 238,165" fill="#38b2e3"/>
229 + <polygon points="370,110 362,105 362,115" fill="#307ab2"/>
230 + <text x="300" y="100" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">UDP 5060 (SIP)</text>
231 + <text x="300" y="180" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">UDP 5k-65k (RTP)</text>
232 +
233 + <!-- Firewall Node -->
234 + <rect x="370" y="50" width="180" height="200" rx="12" fill="#fff5f5" stroke="#cf333d" stroke-width="2"/>
235 + <rect x="385" y="35" width="150" height="26" rx="13" fill="#cf333d"/>
236 + <text x="460" y="52" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">CUSTOMER FIREWALL</text>
237 + <text x="460" y="105" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">Public Edge Router</text>
238 + <rect x="385" y="120" width="150" height="24" rx="4" fill="#e2e8f0"/>
239 + <text x="460" y="136" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[Customer_Public_IP]</text>
240 + <text x="460" y="175" fill="#cf333d" font-size="10" font-weight="bold" text-anchor="middle">SIP ALG: DISABLED</text>
241 + <text x="460" y="195" fill="#2e404d" font-size="10" text-anchor="middle">Source NAT Active</text>
242 +
243 + <!-- Internal LAN Path -->
244 + <path d="M 550 135 L 610 135" stroke="#2e404d" stroke-width="2"/>
245 +
246 + <!-- PBX Node -->
247 + <rect x="610" y="50" width="160" height="200" rx="12" fill="#f8fafc" stroke="#003366" stroke-width="2"/>
248 + <rect x="625" y="35" width="130" height="26" rx="13" fill="#003366"/>
249 + <text x="690" y="52" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">CUSTOMER PBX</text>
250 + <text x="690" y="115" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">Internal PBX / SBC</text>
251 + <rect x="625" y="130" width="130" height="24" rx="4" fill="#e2e8f0"/>
252 + <text x="690" y="146" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">192.168.x.x (LAN)</text>
253 + </svg>
254 + <div class="diagram-caption">Figure 1: Standard end-to-end SIP signaling and RTP media pathing via customer firewall.</div>
255 + </div>
256 +
257 + <!-- Specifications Grid -->
258 + <div class="section-title">2. Core Trunk Parameters</div>
191 191   <div class="specs-grid">
192 192   <div class="spec-card">
193 193   <div class="label">Signaling Protocol</div>
... ... @@ -205,7 +205,7 @@
205 205   <div class="subtext">Out-of-band touch tones</div>
206 206   </div>
207 207   <div class="spec-card">
208 - <div class="label">DNIS Digits</div>
276 + <div class="label">DNIS Delivery</div>
209 209   <div class="val">10 Digits</div>
210 210   <div class="subtext">+1 stripped; Intl disabled by default</div>
211 211   </div>
... ... @@ -221,29 +221,116 @@
221 221   </div>
222 222   </div>
223 223  
224 - <!-- Rules & Firewall -->
225 - <div class="section-title">Network & Firewall Rules</div>
292 + <!-- DIAGRAM 2: REWORKED FIREWALL PACKET FILTER & PORT MAP ILLUSTRATION -->
293 + <div class="section-title">3. Firewall Policy Rules & Packet Filter Action</div>
294 + <div class="diagram-card">
295 + <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 800 290" style="font-family:'Host Grotesk', system-ui, sans-serif;">
296 + <!-- Outer Frame -->
297 + <rect x="10" y="10" width="780" height="270" rx="12" fill="#f8fafc" stroke="#e2e8f0" stroke-width="2"/>
298 +
299 + <!-- FirstDigital WAN Side -->
300 + <text x="110" y="40" fill="#003366" font-size="12" font-weight="bold" text-anchor="middle">WAN SOURCE</text>
301 + <text x="110" y="58" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[FirstDigital_Subnet]</text>
302 +
303 + <!-- Firewall Barrier (Middle) -->
304 + <rect x="360" y="30" width="80" height="230" rx="8" fill="#fff5f5" stroke="#cf333d" stroke-width="2"/>
305 + <text x="400" y="135" fill="#cf333d" font-size="12" font-weight="bold" text-anchor="middle" transform="rotate(-90,400,135)">FIREWALL BOUNDARY</text>
306 +
307 + <!-- Customer LAN Side -->
308 + <text x="690" y="40" fill="#003366" font-size="12" font-weight="bold" text-anchor="middle">LAN DESTINATION</text>
309 + <text x="690" y="58" fill="#2e404d" font-size="11" font-family="monospace" text-anchor="middle">[Customer_PBX_IP]</text>
310 +
311 + <!-- ROW 1: SIP SIGNALING (PASS) -->
312 + <path d="M 200 90 L 360 90" stroke="#2e7d32" stroke-width="2.5"/>
313 + <circle cx="380" cy="90" r="10" fill="#2e7d32"/>
314 + <text x="380" y="94" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">✓</text>
315 + <path d="M 400 90 L 580 90" stroke="#2e7d32" stroke-width="2.5"/>
316 + <polygon points="580,90 572,85 572,95" fill="#2e7d32"/>
317 +
318 + <rect x="220" y="72" width="120" height="22" rx="4" fill="#e8f5e9" stroke="#2e7d32"/>
319 + <text x="280" y="87" fill="#2e7d32" font-size="10" font-weight="bold" text-anchor="middle">SIP: UDP 5060</text>
320 + <text x="480" y="82" fill="#2e7d32" font-size="10" font-weight="bold" text-anchor="middle">FORWARD TO PBX</text>
321 +
322 + <!-- ROW 2: RTP AUDIO STREAM (PASS) -->
323 + <path d="M 200 150 L 360 150" stroke="#307ab2" stroke-width="2.5"/>
324 + <circle cx="380" cy="150" r="10" fill="#2e7d32"/>
325 + <text x="380" y="154" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">✓</text>
326 + <path d="M 400 150 L 580 150" stroke="#307ab2" stroke-width="2.5"/>
327 + <polygon points="580,150 572,145 572,155" fill="#307ab2"/>
328 +
329 + <rect x="210" y="132" width="140" height="22" rx="4" fill="#f0f7fc" stroke="#307ab2"/>
330 + <text x="280" y="147" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">RTP: UDP 5k - 65k</text>
331 + <text x="480" y="142" fill="#003366" font-size="10" font-weight="bold" text-anchor="middle">ALLOW MEDIA STREAM</text>
332 +
333 + <!-- ROW 3: SIP ALG / INSPECTION (BLOCKED) -->
334 + <path d="M 200 215 L 360 215" stroke="#cf333d" stroke-width="2.5" stroke-dasharray="4,4"/>
335 + <circle cx="380" cy="215" r="10" fill="#cf333d"/>
336 + <text x="380" y="219" fill="#ffffff" font-size="11" font-weight="bold" text-anchor="middle">✕</text>
337 +
338 + <rect x="220" y="197" width="120" height="22" rx="4" fill="#fff5f5" stroke="#cf333d"/>
339 + <text x="280" y="212" fill="#cf333d" font-size="10" font-weight="bold" text-anchor="middle">SIP ALG / STUN</text>
340 + <text x="485" y="212" fill="#cf333d" font-size="11" font-weight="bold">DISABLED (Prevents Header Modification)</text>
341 +
342 + <!-- Bottom Note -->
343 + <rect x="180" y="250" width="440" height="20" rx="4" fill="#e2e8f0"/>
344 + <text x="400" y="264" fill="#2e404d" font-size="10" font-weight="bold" text-anchor="middle">OUTBOUND EGRESS NAT: All traffic MUST egress sourcing from [Customer_Public_IP]</text>
345 + </svg>
346 + <div class="diagram-caption">Figure 2: Firewall packet-filtering policy—explicitly allowing signaling/media while disabling SIP ALG.</div>
347 + </div>
348 +
349 + <!-- Rules Text -->
226 226   <div class="rules-grid">
227 227   <div class="rule-box">
228 - <h4>Outbound Signaling & Caller ID</h4>
352 + <h4>Outbound Traffic Requirements</h4>
229 229   <ul>
230 - <li>Outbound requests to FirstDigital must source directly from the Customer Public IP provided during turn-up.</li>
231 - <li>Outbound calls must present a Caller ID number assigned to the specific trunk instance.</li>
232 - <li>Ensure outbound NAT egress matches the registered public IP address.</li>
354 + <li>Outbound calls to FirstDigital must source directly from the registered Customer Public IP.</li>
355 + <li>Outbound calls must send Caller ID matching a phone number assigned to the trunk instance.</li>
356 + <li>FirstDigital will automatically reject calls sourcing from unknown or unauthorized IPs.</li>
233 233   </ul>
234 234   </div>
235 235   <div class="rule-box">
236 - <h4>Firewall & Perimeter Setup</h4>
360 + <h4>Firewall & NAT Settings</h4>
237 237   <ul>
238 - <li><strong>SIP ALG:</strong> Must be <u>DISABLED</u> globally on customer routers/firewalls.</li>
239 - <li><strong>Inbound Rules:</strong> Allow traffic from FirstDigital's SBC subnet across <code>UDP 5000 - 65000</code>.</li>
240 - <li><strong>Egress Routing:</strong> Verify NAT routing for FirstDigital's subnet exits out of the designated public IP.</li>
362 + <li><strong>SIP ALG:</strong> Must be completely <u>DISABLED</u> on customer edge firewalls and routers.</li>
363 + <li><strong>RTP Media:</strong> Ensure UDP ports 5000-65000 are permitted for full audio stream delivery.</li>
364 + <li><strong>NAT Routing:</strong> Confirm outbound NAT egress explicitly maps internal PBX traffic to the registered public IP.</li>
241 241   </ul>
242 242   </div>
243 243   </div>
244 244  
369 + <!-- DIAGRAM 3: One-Way Audio Problem -->
370 + <div class="section-title">4. Common Audio Defect: Private IP Header Leakage</div>
371 + <div class="diagram-card">
372 + <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 800 240" style="font-family:'Host Grotesk', system-ui, sans-serif;">
373 + <!-- SBC Box -->
374 + <rect x="40" y="40" width="180" height="160" rx="10" fill="#f0f7fc" stroke="#307ab2" stroke-width="2"/>
375 + <text x="130" y="80" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">FirstDigital SBC</text>
376 + <text x="130" y="100" fill="#2e404d" font-size="10" text-anchor="middle">Public Media Gateway</text>
377 +
378 + <!-- Broken Return Audio Path -->
379 + <path d="M 220 160 L 410 160" stroke="#cf333d" stroke-width="3" stroke-dasharray="4,4"/>
380 + <circle cx="420" cy="160" r="12" fill="#cf333d"/>
381 + <text x="420" y="165" fill="#ffffff" font-size="13" font-weight="bold" text-anchor="middle">X</text>
382 + <text x="315" y="150" fill="#cf333d" font-size="10" font-weight="bold" text-anchor="middle">Audio Fails: 192.168.x.x Unreachable</text>
383 +
384 + <!-- Firewall Box -->
385 + <rect x="450" y="40" width="120" height="160" rx="10" fill="#fff5f5" stroke="#cf333d" stroke-width="2"/>
386 + <text x="510" y="120" fill="#cf333d" font-size="12" font-weight="bold" text-anchor="middle">Firewall</text>
387 +
388 + <!-- PBX Box -->
389 + <rect x="620" y="40" width="140" height="160" rx="10" fill="#f8fafc" stroke="#003366" stroke-width="2"/>
390 + <text x="690" y="75" fill="#003366" font-size="13" font-weight="bold" text-anchor="middle">Customer PBX</text>
391 +
392 + <!-- Problem Header Packet -->
393 + <path d="M 620 85 L 230 85" stroke="#307ab2" stroke-width="2"/>
394 + <rect x="310" y="60" width="240" height="24" rx="4" fill="#fffbe0" stroke="#d97706"/>
395 + <text x="430" y="76" fill="#b45309" font-size="10" font-weight="bold" text-anchor="middle">SDP Header: Audio IP = 192.168.1.50 (Private IP Leak!)</text>
396 + </svg>
397 + <div class="diagram-caption">Figure 3: Why one-way audio occurs—the PBX requests return audio to an unreachable internal private IP address.</div>
398 + </div>
399 +
245 245   <!-- Troubleshooting Matrix -->
246 - <div class="section-title">SIP Trunk Troubleshooting Matrix</div>
401 + <div class="section-title">5. Troubleshooting Matrix</div>
247 247   <table class="tb-table">
248 248   <thead>
249 249   <tr>
... ... @@ -254,27 +254,27 @@
254 254   <tbody>
255 255   <tr>
256 256   <td class="symptom">No Inbound Calls</td>
257 - <td>Verify firewall permits <code>UDP 5060</code> from FirstDigital's subnet. Confirm <strong>SIP ALG is disabled</strong> on edge devices.</td>
412 + <td>Verify firewall allows <code>UDP 5060</code> from FirstDigital's subnet. Confirm <strong>SIP ALG is disabled</strong> on edge devices.</td>
258 258   </tr>
259 259   <tr>
260 260   <td class="symptom">No Outbound Calls</td>
261 - <td>Confirm destination SIP target and port (<code>UDP 5060</code>). Verify outbound traffic sources from your designated public IP. Ensure Caller ID matches an active number on the trunk.</td>
416 + <td>Confirm outbound SIP traffic is directed to FirstDigital's SBC IP on <code>UDP 5060</code>. Verify traffic sources from your registered Public IP and uses an assigned Caller ID.</td>
262 262   </tr>
263 263   <tr>
264 264   <td class="symptom">One-Way or No Audio</td>
265 - <td><strong>Common Issue:</strong> PBX is sending private IP addresses (e.g., <code>10.x.x.x</code> or <code>192.168.x.x</code>) inside the SIP SDP header. Check PBX NAT settings, SBC Media Address Override, or STUN. Disable SIP ALG.</td>
420 + <td><strong>Common Issue:</strong> PBX is leaking private IP addresses (e.g., <code>10.x.x.x</code> or <code>192.168.x.x</code>) in the SIP SDP header. Fix PBX NAT settings, SBC Media Address Override, or STUN configuration. Disable SIP ALG.</td>
266 266   </tr>
267 267   <tr>
268 - <td class="symptom">DTMF Tones Not Recognized</td>
423 + <td class="symptom">Touch Tones Not Working</td>
269 269   <td>Configure PBX and endpoints to send DTMF out-of-band using <strong>RFC 2833</strong> (telephony-event).</td>
270 270   </tr>
271 271   <tr>
272 - <td class="symptom">Calls Not Ringing Correct Extension</td>
273 - <td>Inspect sent/received <strong>DNIS digit delivery</strong>. FirstDigital defaults to sending 10 digits. Adjust PBX inbound routing rules to match.</td>
427 + <td class="symptom">Calls Routing Incorrectly</td>
428 + <td>Inspect received <strong>DNIS digit delivery</strong>. FirstDigital defaults to 10-digit delivery. Update PBX inbound routing rules to match.</td>
274 274   </tr>
275 275   <tr>
276 276   <td class="symptom">Forwarded Calls Have One-Way Audio</td>
277 - <td>Typically caused when FirstDigital enables "NAT Media" as a temporary workaround for private IP leaks. Resolving the PBX private IP header leak allows FirstDigital to remove NAT Media settings, restoring call transfer audio.</td>
432 + <td>Occurs if FirstDigital enabled "NAT Media" as a temporary workaround for private IP header leaks. Resolving the PBX private IP leak allows FirstDigital to disable NAT Media settings, resolving transfer audio.</td>
278 278   </tr>
279 279   </tbody>
280 280   </table>