π‘οΈ Ring2All SBC (Session Border Controller) Deployment Guide
Complete step-by-step guide for installing and configuring Ring2All SBC on Debian 13 (Trixie), shielding your core telephony cluster with perimeter security, NAT traversal, and encrypted WireGuard mesh.
ποΈ Architecture Overview
Section titled βποΈ Architecture OverviewβThe Ring2All SBC (Session Border Controller) serves as the hardened security perimeter between untrusted public networks (internet subscribers, remote softphones, PSTN carrier trunks) and your private core telephony cluster (Ring2All PBX nodes).
flowchart TB
subgraph PublicInternet["Public Internet & Carrier Networks"]
Subscribers["Remote SIP & WebRTC Clients<br/>(Hardphones, Softphones, Mobile Apps)"]
Carriers["Upstream PSTN Carrier Trunks<br/>(Inbound DIDs & Outbound Termination)"]
end
subgraph SBCPerimeter["Ring2All SBC Gateway (Public IP: 203.0.113.10)"]
Firewall["nftables + Pike Anti-Flood Shield"]
Kamailio["Kamailio 6.1+ SIP Signaling Engine<br/>(Dispatcher Load Balancing, LCR, Topology Hiding)"]
RTPEngine["Sipwise RTPEngine 12.5+ Media Relay<br/>(NAT Traversal, SRTP-to-RTP Transcoding)"]
SbcApi["SBC REST API (Fastify 5 :3003)"]
SbcWeb["Nginx Reverse Proxy & Admin Web UI (:443)"]
WGGateway["WireGuard Mesh Hub (wg0: 10.9.0.1)"]
end
subgraph PrivateCore["Private Core Network (Zero Public IP Exposure)"]
direction TB
FS1["Ring2All PBX Node 01<br/>(wg0: 10.9.0.2 / LAN: 192.168.10.41)"]
FS2["Ring2All PBX Node 02<br/>(wg0: 10.9.0.3 / LAN: 192.168.10.42)"]
BSS["Ring2All BSS (Real-Time OCS Engine)<br/>(LAN: 192.168.10.50)"]
end
Subscribers -->|Public SIP :5060 / :5061| Firewall
Carriers -->|Public SIP :5060| Firewall
Subscribers -.->|Public Audio RTP 16384-32768| RTPEngine
Carriers -.->|Public Audio RTP 16384-32768| RTPEngine
Firewall --> Kamailio
Kamailio <--> RTPEngine
Kamailio <--> SbcApi
SbcWeb <--> SbcApi
Kamailio <-->|Encrypted SIP via wg0| WGGateway
WGGateway <==|Encrypted WireGuard Mesh (UDP 51820)|==> FS1
WGGateway <==|Encrypted WireGuard Mesh (UDP 51820)|==> FS2
Kamailio <-->|Sub-millisecond OCS Auth| BSS
Core Responsibilities:
Section titled βCore Responsibilities:β- Topology Hiding & Complete Shielding: Internal FreeSWITCH PBX nodes have zero public IP exposure. They sit safely in private subnets, reachable only via encrypted WireGuard tunnels (
10.9.0.0/24). - High-Performance Media Relay (RTPEngine 12.5+): Seamlessly traverses aggressive symmetric NATs, bridges WebRTC (DTLS-SRTP) with legacy carrier RTP, and handles audio streams without CPU overhead.
- Perimeter Defense (Pike & nftables): Identifies and bans SIP brute-force scanners, floods, and malformed packets in real time.
- Dispatcher Load Balancing & LCR: Evenly distributes SIP calls across the PBX cluster using round-robin or hash-based dispatchers with active SIP OPTIONS health-checks.
π₯οΈ System Requirements
Section titled βπ₯οΈ System Requirementsβ| Specification | Minimum | Recommended | High Volume / Carrier |
|---|---|---|---|
| Operating System | Debian 13 (Trixie) 64-bit | Debian 13 (Trixie) 64-bit | Debian 13 (Trixie) 64-bit |
| CPU | 4 vCPU | 8 vCPU | 16+ vCPU |
| RAM | 8 GB | 16 GB | 32 GB |
| Storage | 80 GB SSD | 160 GB NVMe | 300+ GB NVMe |
| Network Interfaces | 1 Public IPv4 + 1 Private LAN | 1 Public IPv4 + 1 Private LAN | 10 Gbps redundant NICs |
| Concurrent Calls | ~500 | ~2,500 | ~10,000+ |
β‘ Option 1: Automated One-Touch Installation (Recommended)
Section titled ββ‘ Option 1: Automated One-Touch Installation (Recommended)βRing2All provides an automated one-touch installer that provisions Kamailio 6.1, RTPEngine 12.5, PostgreSQL 17, WireGuard VPN, Nginx reverse proxies, and the SBC management API in a single run.
Execute the following command as root on your clean Debian 13 server:
wget -O- https://repo.softswitchone.com/apt/install-sbc.sh | bashWhat the Automated Script Configures:
Section titled βWhat the Automated Script Configures:β- Installs base utilities (
curl,gnupg2,openssl,nginx,postgresql,wireguard,fail2ban,nftables). - Registers the official Node.js 22 LTS runtime.
- Installs Kamailio 6.1+ (
kamailio,kamailio-postgres-modules,kamailio-tls-modules,kamailio-websocket-modules,kamcli). - Bootstraps the
kamailiodatabase schema and sets up default domains. - Installs the unified
softswitch-sbcpackage from the Ring2All repository. - Deploys the Fastify-based REST API service (
sbc-api.service) listening on loopback port3003. - Configures Nginx virtual host at
/etc/nginx/sites-available/softswitch-sbcwith TLS and WebSocket proxies. - Initializes the WireGuard VPN hub interface (
wg0on10.9.0.1/24, UDP port51820). - Deploys secure
nftablesfirewall rules protecting administrative ports while opening SIP and media ports.
π οΈ Option 2: Step-by-Step Manual Installation
Section titled βπ οΈ Option 2: Step-by-Step Manual InstallationβIf your infrastructure requires fine-grained control, follow this manual step-by-step process.
Step 1: System Packages & Repositories
Section titled βStep 1: System Packages & Repositoriesβ# Update and install base toolsapt-get update && apt-get install -y curl wget gnupg2 openssl nginx unixodbc odbc-postgresql fail2ban nftables wireguard
# Setup Node.js 22 LTScurl -fsSL https://deb.nodesource.com/setup_22.x | bash -apt-get install -y nodejs build-essential
# Add Ring2All Official Repositorycurl -fsSL https://repo.softswitchone.com/apt/setup_repo | bashapt-get updateStep 2: Database Initialization
Section titled βStep 2: Database Initializationβapt-get install -y postgresql-17
# Create SBC administrative database and usersudo -u postgres psql << 'EOF'CREATE DATABASE sbc_admin;CREATE USER sbc_user WITH ENCRYPTED PASSWORD 'ChangeMeSecurely123!';GRANT ALL PRIVILEGES ON DATABASE sbc_admin TO sbc_user;ALTER DATABASE sbc_admin OWNER TO sbc_user;EOFStep 3: Install Kamailio 6.1 & RTPEngine
Section titled βStep 3: Install Kamailio 6.1 & RTPEngineβ# Install Kamailio core and modulesapt-get install -y kamailio kamailio-postgres-modules kamailio-tls-modules \ kamailio-websocket-modules kamailio-json-modules kamailio-presence-modules kamcli
# Install Sipwise RTPEngineapt-get install -y rtpengine rtpengine-daemon rtpengine-iptablesInitialize the Kamailio PostgreSQL schema:
kamdbctl create# Enter your PostgreSQL credentials when prompted to initialize 'kamailio' database.Step 4: Install Ring2All SBC Core Package
Section titled βStep 4: Install Ring2All SBC Core Packageβapt-get install -y -o Dpkg::Options::="--force-overwrite" softswitch-sbcThis installs:
/var/www/softswitch-sbc/api(SBC Management REST API)/var/www/softswitch-sbc/web(React Administrative Web Console)/etc/softswitch/sbc-api.env(Environment variables)/etc/systemd/system/sbc-api.service
Enable and start the API service:
systemctl daemon-reloadsystemctl enable --now sbc-apisystemctl status sbc-apiStep 5: Nginx Reverse Proxy Configuration
Section titled βStep 5: Nginx Reverse Proxy ConfigurationβVerify /etc/nginx/sites-available/softswitch-sbc:
server { listen 80; server_name sbc.example.com; return 301 https://$host$request_uri;}
server { listen 443 ssl http2; server_name sbc.example.com;
ssl_certificate /etc/ssl/certs/softswitch-sbc.crt; ssl_certificate_key /etc/ssl/private/softswitch-sbc.key;
# Static Web UI root /var/www/softswitch-sbc/web; index index.html;
location / { try_files $uri $uri/ /index.html; }
# SBC REST API location /api/ { proxy_pass http://127.0.0.1:3003/; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; }
# Real-Time WebSocket Telemetry location /ws { proxy_pass http://127.0.0.1:3003/ws; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_read_timeout 86400; }}Enable and reload:
ln -sf /etc/nginx/sites-available/softswitch-sbc /etc/nginx/sites-enabled/nginx -t && systemctl reload nginxπ Connecting Core Telephony via WireGuard Mesh
Section titled βπ Connecting Core Telephony via WireGuard MeshβIn production multi-datacenter environments, your FreeSWITCH PBX nodes must never be directly exposed to the public internet. Instead, they connect to Ring2All SBC via an encrypted WireGuard VPN mesh.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ RING2ALL SBC (Server Hub) ββ Public IP: 203.0.113.10 β WireGuard IP: 10.9.0.1 ββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββ β π WireGuard Transit (UDP 51820) ββββββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββββββ RING2ALL PBX NODE (Client Spoke) ββ LAN Only: 192.168.10.41 β WireGuard IP: 10.9.0.2 ββ FreeSWITCH bound to: local_ip_v4 = 10.9.0.2 βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββMethod A: Automated via Ring2All SBC Web UI (Recommended)
Section titled βMethod A: Automated via Ring2All SBC Web UI (Recommended)β- Log in to the SBC Web Console (
https://sbc.example.com). - Navigate to Network > WireGuard > Peers and click + Add Peer:
- Peer Name:
PBX-Node-01 - Assigned IP:
10.9.0.2/32 - Allowed IPs:
10.9.0.2/32
- Peer Name:
- Click Generate Keys & Configuration.
- Download or copy the generated client configuration snippet.
- On the FreeSWITCH PBX node, paste the content into
/etc/wireguard/wg0.conf:Terminal window apt-get install -y wireguardnano /etc/wireguard/wg0.confsystemctl enable --now wg-quick@wg0 - Verify tunnel connectivity from the PBX node:
Terminal window ping 10.9.0.1
Method B: Manual WireGuard Server Configuration
Section titled βMethod B: Manual WireGuard Server ConfigurationβOn the Ring2All SBC server, /etc/wireguard/wg0.conf should look like this:
[Interface]Address = 10.9.0.1/24ListenPort = 51820PrivateKey = <SERVER_PRIVATE_KEY>PostUp = nft add rule inet filter input iifname "wg0" acceptPostDown = nft delete rule inet filter input iifname "wg0" accept
# PBX Node 01[Peer]PublicKey = <PBX_NODE_01_PUBLIC_KEY>AllowedIPs = 10.9.0.2/32
# PBX Node 02[Peer]PublicKey = <PBX_NODE_02_PUBLIC_KEY>AllowedIPs = 10.9.0.3/32Restart WireGuard:
systemctl restart wg-quick@wg0wg showWireGuard Audio Performance & Capacity
Section titled βWireGuard Audio Performance & CapacityβWireGuard executes as an in-kernel module (wireguard.ko) utilizing modern ChaCha20-Poly1305 cryptography. It delivers 3 to 5+ Gbps throughput with near-zero CPU footprint:
- 1,000 simultaneous G.711 PCMU calls require only ~80 Mbps and ~50,000 pps.
- WireGuard introduces < 0.1 ms latency, completely undetectable in voice audio quality.
π DNS & Cloudflare Architecture (Crucial)
Section titled βπ DNS & Cloudflare Architecture (Crucial)βWhen configuring DNS for Ring2All SBC, keep in mind that Cloudflare standard proxy (Orange Cloud βοΈπ§‘) supports ONLY HTTP/HTTPS traffic. Cloudflare DOES NOT proxy UDP SIP traffic on port 5060.
1. SIP Signaling DNS Records (Mandatory Grey Cloud βοΈπ©Ά)
Section titled β1. SIP Signaling DNS Records (Mandatory Grey Cloud βοΈπ©Ά)βFor SIP registration and carrier trunking, you must create a DNS record with the Cloudflare proxy disabled (Grey Cloud βοΈπ©Ά) pointing directly to the SBC public IP:
| Type | Name | Content | Proxy Status | Purpose |
|---|---|---|---|---|
| A | sbc.example.com |
203.0.113.10 |
DNS Only (Grey Cloud βοΈπ©Ά) | SIP UDP/TCP Signaling |
| A | sip.example.com |
203.0.113.10 |
DNS Only (Grey Cloud βοΈπ©Ά) | Hardphone Registrar |
2. SIP Auto-Discovery via SRV Records (RFC 3263)
Section titled β2. SIP Auto-Discovery via SRV Records (RFC 3263)βTo enable zero-touch provisioning and allow phones to discover the SBC without typing port numbers:
_sip._udp.example.com. IN SRV 10 50 5060 sbc.example.com._sips._tcp.example.com. IN SRV 10 50 5061 sbc.example.com.3. Web Admin Console DNS Records (Orange Cloud βοΈπ§‘)
Section titled β3. Web Admin Console DNS Records (Orange Cloud βοΈπ§‘)βThe web administration interface can safely use Cloudflareβs CDN and WAF (Orange Cloud βοΈπ§‘):
| Type | Name | Content | Proxy Status | Purpose |
|---|---|---|---|---|
| CNAME | sbc-admin.example.com |
sbc.example.com |
Proxied (Orange Cloud βοΈπ§‘) | Web Dashboard & WAF |
π Verification & Health Checks
Section titled βπ Verification & Health ChecksβRun these commands to verify that Ring2All SBC is operating correctly:
1. Service Status
Section titled β1. Service Statusβsystemctl status kamailiosystemctl status rtpenginesystemctl status sbc-apisystemctl status nginxsystemctl status wg-quick@wg02. Local API Health Check
Section titled β2. Local API Health Checkβcurl -s http://127.0.0.1:3003/health# Expected: {"status":"ok","service":"sbc-api","version":"1.0.0"}3. Active Port Listeners
Section titled β3. Active Port Listenersβss -ulnp | grep -E '5060|51820'# Expected: Kamailio listening on 0.0.0.0:5060 and 10.9.0.1:5060; WireGuard on 0.0.0.0:518204. Kamailio Runtime Inspection
Section titled β4. Kamailio Runtime Inspectionβ# Check loaded moduleskamcmd system.listMethods
# Check dispatcher status (PBX cluster nodes)kamcmd dispatcher.list
# Inspect active RTPEngine media sessionsrtpengine-ctl list sessionsπ§ Production Troubleshooting
Section titled βπ§ Production Troubleshootingβ1. Phones fail to register with βRequest Timeout (408)β
Section titled β1. Phones fail to register with βRequest Timeout (408)ββ- Cause: DNS is pointing through Cloudflare Orange Cloud (which drops UDP port 5060) or
nftablesis dropping inbound SIP packets. - Solution: Set DNS record to Grey Cloud (DNS Only) in Cloudflare. Check firewall rules:
Terminal window nft list ruleset | grep 5060
2. One-Way Audio on Calls Traversing SBC
Section titled β2. One-Way Audio on Calls Traversing SBCβ- Cause: RTPEngine is advertising an internal IP instead of the public IP in SDP headers.
- Solution: Verify
/etc/rtpengine/rtpengine.confinterface configuration:Ensure RTP port rangeinterface = external/203.0.113.10;internal/10.9.0.116384-32768/udpis permitted through the cloud security group.
π Next Steps
Section titled βπ Next Stepsβ- Web Cluster & Load Balancing Guide: Scale your frontend interfaces.
- Distributed PBX Cluster Guide: Scale out N+1 FreeSWITCH telephony nodes behind this SBC.
- Ring2All BSS Deployment: Connect carrier billing, OCS rating, and customer self-care portals.

