SIP

Last modified by Aaron Blackburn on 2026/09/01 19:00

FirstDigital Voice Operations

SIP Trunking Technical Reference

Network architecture, firewall requirements, and troubleshooting standards for customer SIP trunks.

Customer Responsibility Notice: Customers are responsible for the configuration and maintenance of their own routers, firewalls, and PBX equipment. FirstDigital provides these specifications to assist engineers during trunk integration.
1. SIP Trunk Topology & Traffic Routing
FIRSTDIGITAL CLOUD FirstDigital SBC [FirstDigital_SBC_IP] Signaling & Audio Target UDP 5060 (SIP) UDP 5k-65k (RTP) CUSTOMER FIREWALL Public Edge Router [Customer_Public_IP] SIP ALG: DISABLED Source NAT Active CUSTOMER PBX Internal PBX / SBC 192.168.x.x (LAN)
Figure 1: Standard end-to-end SIP signaling and RTP media pathing via customer firewall.
2. Core Trunk Parameters
Signaling Protocol
UDP 5060
Standard SIP port
Primary Codec
G.711u
20ms packetization
DTMF Mode
RFC 2833
Out-of-band touch tones
DNIS Delivery
10 Digits
+1 stripped; Intl disabled by default
Authentication
IP Registration-less
No user/password required
SIP Advanced
Peer Path / Re-invite
Disabled / No re-invites permitted
3. Firewall Policy Rules & Packet Filter Action
WAN SOURCE [FirstDigital_Subnet] FIREWALL BOUNDARY LAN DESTINATION [Customer_PBX_IP] ✓ SIP: UDP 5060 FORWARD TO PBX ✓ RTP: UDP 5k - 65k ALLOW MEDIA STREAM ✕ SIP ALG / STUN DISABLED (Prevents Header Modification) OUTBOUND EGRESS NAT: All traffic MUST egress sourcing from [Customer_Public_IP]
Figure 2: Firewall packet-filtering policy—explicitly allowing signaling/media while disabling SIP ALG.

Outbound Traffic Requirements

  • Outbound calls to FirstDigital must source directly from the registered Customer Public IP.
  • Outbound calls must send Caller ID matching a phone number assigned to the trunk instance.
  • FirstDigital will automatically reject calls sourcing from unknown or unauthorized IPs.

Firewall & NAT Settings

  • SIP ALG: Must be completely DISABLED on customer edge firewalls and routers.
  • RTP Media: Ensure UDP ports 5000-65000 are permitted for full audio stream delivery.
  • NAT Routing: Confirm outbound NAT egress explicitly maps internal PBX traffic to the registered public IP.
4. Common Audio Defect: Private IP Header Leakage
FirstDigital SBC Public Media Gateway X Audio Fails: 192.168.x.x Unreachable Firewall Customer PBX SDP Header: Audio IP = 192.168.1.50 (Private IP Leak!)
Figure 3: Why one-way audio occurs—the PBX requests return audio to an unreachable internal private IP address.
5. Troubleshooting Matrix
Symptom Root Cause & Resolution Step
No Inbound Calls Verify firewall allows UDP 5060 from FirstDigital's subnet. Confirm SIP ALG is disabled on edge devices.
No Outbound Calls Confirm outbound SIP traffic is directed to FirstDigital's SBC IP on UDP 5060. Verify traffic sources from your registered Public IP and uses an assigned Caller ID.
One-Way or No Audio Common Issue: PBX is leaking private IP addresses (e.g., 10.x.x.x or 192.168.x.x) in the SIP SDP header. Fix PBX NAT settings, SBC Media Address Override, or STUN configuration. Disable SIP ALG.
Touch Tones Not Working Configure PBX and endpoints to send DTMF out-of-band using RFC 2833 (telephony-event).
Calls Routing Incorrectly Inspect received DNIS digit delivery. FirstDigital defaults to 10-digit delivery. Update PBX inbound routing rules to match.
Forwarded Calls Have One-Way Audio Occurs if FirstDigital enabled "NAT Media" as a temporary workaround for private IP header leaks. Resolving the PBX private IP leak allows FirstDigital to disable NAT Media settings, resolving transfer audio.