Skip to content

πŸ›‘οΈ Ring2All SBC (Session Border Controller) Deployment Guide

9 min readUpdated: Sep 26, 2026
View as Markdown

Complete step-by-step guide for installing and configuring Ring2All SBC on Debian 13 (Trixie), shielding your core telephony cluster with perimeter security, NAT traversal, and encrypted WireGuard mesh.


The Ring2All SBC (Session Border Controller) serves as the hardened security perimeter between untrusted public networks (internet subscribers, remote softphones, PSTN carrier trunks) and your private core telephony cluster (Ring2All PBX nodes).

flowchart TB
    subgraph PublicInternet["Public Internet & Carrier Networks"]
        Subscribers["Remote SIP & WebRTC Clients<br/>(Hardphones, Softphones, Mobile Apps)"]
        Carriers["Upstream PSTN Carrier Trunks<br/>(Inbound DIDs & Outbound Termination)"]
    end

    subgraph SBCPerimeter["Ring2All SBC Gateway (Public IP: 203.0.113.10)"]
        Firewall["nftables + Pike Anti-Flood Shield"]
        Kamailio["Kamailio 6.1+ SIP Signaling Engine<br/>(Dispatcher Load Balancing, LCR, Topology Hiding)"]
        RTPEngine["Sipwise RTPEngine 12.5+ Media Relay<br/>(NAT Traversal, SRTP-to-RTP Transcoding)"]
        SbcApi["SBC REST API (Fastify 5 :3003)"]
        SbcWeb["Nginx Reverse Proxy & Admin Web UI (:443)"]
        WGGateway["WireGuard Mesh Hub (wg0: 10.9.0.1)"]
    end

    subgraph PrivateCore["Private Core Network (Zero Public IP Exposure)"]
        direction TB
        FS1["Ring2All PBX Node 01<br/>(wg0: 10.9.0.2 / LAN: 192.168.10.41)"]
        FS2["Ring2All PBX Node 02<br/>(wg0: 10.9.0.3 / LAN: 192.168.10.42)"]
        BSS["Ring2All BSS (Real-Time OCS Engine)<br/>(LAN: 192.168.10.50)"]
    end

    Subscribers -->|Public SIP :5060 / :5061| Firewall
    Carriers -->|Public SIP :5060| Firewall
    Subscribers -.->|Public Audio RTP 16384-32768| RTPEngine
    Carriers -.->|Public Audio RTP 16384-32768| RTPEngine

    Firewall --> Kamailio
    Kamailio <--> RTPEngine
    Kamailio <--> SbcApi
    SbcWeb <--> SbcApi

    Kamailio <-->|Encrypted SIP via wg0| WGGateway
    WGGateway <==|Encrypted WireGuard Mesh (UDP 51820)|==> FS1
    WGGateway <==|Encrypted WireGuard Mesh (UDP 51820)|==> FS2
    Kamailio <-->|Sub-millisecond OCS Auth| BSS
  1. Topology Hiding & Complete Shielding: Internal FreeSWITCH PBX nodes have zero public IP exposure. They sit safely in private subnets, reachable only via encrypted WireGuard tunnels (10.9.0.0/24).
  2. High-Performance Media Relay (RTPEngine 12.5+): Seamlessly traverses aggressive symmetric NATs, bridges WebRTC (DTLS-SRTP) with legacy carrier RTP, and handles audio streams without CPU overhead.
  3. Perimeter Defense (Pike & nftables): Identifies and bans SIP brute-force scanners, floods, and malformed packets in real time.
  4. Dispatcher Load Balancing & LCR: Evenly distributes SIP calls across the PBX cluster using round-robin or hash-based dispatchers with active SIP OPTIONS health-checks.

Specification Minimum Recommended High Volume / Carrier
Operating System Debian 13 (Trixie) 64-bit Debian 13 (Trixie) 64-bit Debian 13 (Trixie) 64-bit
CPU 4 vCPU 8 vCPU 16+ vCPU
RAM 8 GB 16 GB 32 GB
Storage 80 GB SSD 160 GB NVMe 300+ GB NVMe
Network Interfaces 1 Public IPv4 + 1 Private LAN 1 Public IPv4 + 1 Private LAN 10 Gbps redundant NICs
Concurrent Calls ~500 ~2,500 ~10,000+

Section titled β€œβš‘ Option 1: Automated One-Touch Installation (Recommended)”

Ring2All provides an automated one-touch installer that provisions Kamailio 6.1, RTPEngine 12.5, PostgreSQL 17, WireGuard VPN, Nginx reverse proxies, and the SBC management API in a single run.

Execute the following command as root on your clean Debian 13 server:

Terminal window
wget -O- https://repo.softswitchone.com/apt/install-sbc.sh | bash
  1. Installs base utilities (curl, gnupg2, openssl, nginx, postgresql, wireguard, fail2ban, nftables).
  2. Registers the official Node.js 22 LTS runtime.
  3. Installs Kamailio 6.1+ (kamailio, kamailio-postgres-modules, kamailio-tls-modules, kamailio-websocket-modules, kamcli).
  4. Bootstraps the kamailio database schema and sets up default domains.
  5. Installs the unified softswitch-sbc package from the Ring2All repository.
  6. Deploys the Fastify-based REST API service (sbc-api.service) listening on loopback port 3003.
  7. Configures Nginx virtual host at /etc/nginx/sites-available/softswitch-sbc with TLS and WebSocket proxies.
  8. Initializes the WireGuard VPN hub interface (wg0 on 10.9.0.1/24, UDP port 51820).
  9. Deploys secure nftables firewall rules protecting administrative ports while opening SIP and media ports.

πŸ› οΈ Option 2: Step-by-Step Manual Installation

Section titled β€œπŸ› οΈ Option 2: Step-by-Step Manual Installation”

If your infrastructure requires fine-grained control, follow this manual step-by-step process.

Terminal window
# Update and install base tools
apt-get update && apt-get install -y curl wget gnupg2 openssl nginx unixodbc odbc-postgresql fail2ban nftables wireguard
# Setup Node.js 22 LTS
curl -fsSL https://deb.nodesource.com/setup_22.x | bash -
apt-get install -y nodejs build-essential
# Add Ring2All Official Repository
curl -fsSL https://repo.softswitchone.com/apt/setup_repo | bash
apt-get update
Terminal window
apt-get install -y postgresql-17
# Create SBC administrative database and user
sudo -u postgres psql << 'EOF'
CREATE DATABASE sbc_admin;
CREATE USER sbc_user WITH ENCRYPTED PASSWORD 'ChangeMeSecurely123!';
GRANT ALL PRIVILEGES ON DATABASE sbc_admin TO sbc_user;
ALTER DATABASE sbc_admin OWNER TO sbc_user;
EOF
Terminal window
# Install Kamailio core and modules
apt-get install -y kamailio kamailio-postgres-modules kamailio-tls-modules \
kamailio-websocket-modules kamailio-json-modules kamailio-presence-modules kamcli
# Install Sipwise RTPEngine
apt-get install -y rtpengine rtpengine-daemon rtpengine-iptables

Initialize the Kamailio PostgreSQL schema:

Terminal window
kamdbctl create
# Enter your PostgreSQL credentials when prompted to initialize 'kamailio' database.
Terminal window
apt-get install -y -o Dpkg::Options::="--force-overwrite" softswitch-sbc

This installs:

  • /var/www/softswitch-sbc/api (SBC Management REST API)
  • /var/www/softswitch-sbc/web (React Administrative Web Console)
  • /etc/softswitch/sbc-api.env (Environment variables)
  • /etc/systemd/system/sbc-api.service

Enable and start the API service:

Terminal window
systemctl daemon-reload
systemctl enable --now sbc-api
systemctl status sbc-api

Verify /etc/nginx/sites-available/softswitch-sbc:

server {
listen 80;
server_name sbc.example.com;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl http2;
server_name sbc.example.com;
ssl_certificate /etc/ssl/certs/softswitch-sbc.crt;
ssl_certificate_key /etc/ssl/private/softswitch-sbc.key;
# Static Web UI
root /var/www/softswitch-sbc/web;
index index.html;
location / {
try_files $uri $uri/ /index.html;
}
# SBC REST API
location /api/ {
proxy_pass http://127.0.0.1:3003/;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
# Real-Time WebSocket Telemetry
location /ws {
proxy_pass http://127.0.0.1:3003/ws;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_read_timeout 86400;
}
}

Enable and reload:

Terminal window
ln -sf /etc/nginx/sites-available/softswitch-sbc /etc/nginx/sites-enabled/
nginx -t && systemctl reload nginx

In production multi-datacenter environments, your FreeSWITCH PBX nodes must never be directly exposed to the public internet. Instead, they connect to Ring2All SBC via an encrypted WireGuard VPN mesh.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ RING2ALL SBC (Server Hub) β”‚
β”‚ Public IP: 203.0.113.10 β”‚ WireGuard IP: 10.9.0.1 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
πŸ”’ WireGuard Transit (UDP 51820)
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ RING2ALL PBX NODE (Client Spoke) β”‚
β”‚ LAN Only: 192.168.10.41 β”‚ WireGuard IP: 10.9.0.2 β”‚
β”‚ FreeSWITCH bound to: local_ip_v4 = 10.9.0.2 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
Section titled β€œMethod A: Automated via Ring2All SBC Web UI (Recommended)”
  1. Log in to the SBC Web Console (https://sbc.example.com).
  2. Navigate to Network > WireGuard > Peers and click + Add Peer:
    • Peer Name: PBX-Node-01
    • Assigned IP: 10.9.0.2/32
    • Allowed IPs: 10.9.0.2/32
  3. Click Generate Keys & Configuration.
  4. Download or copy the generated client configuration snippet.
  5. On the FreeSWITCH PBX node, paste the content into /etc/wireguard/wg0.conf:
    Terminal window
    apt-get install -y wireguard
    nano /etc/wireguard/wg0.conf
    systemctl enable --now wg-quick@wg0
  6. Verify tunnel connectivity from the PBX node:
    Terminal window
    ping 10.9.0.1

On the Ring2All SBC server, /etc/wireguard/wg0.conf should look like this:

[Interface]
Address = 10.9.0.1/24
ListenPort = 51820
PrivateKey = <SERVER_PRIVATE_KEY>
PostUp = nft add rule inet filter input iifname "wg0" accept
PostDown = nft delete rule inet filter input iifname "wg0" accept
# PBX Node 01
[Peer]
PublicKey = <PBX_NODE_01_PUBLIC_KEY>
AllowedIPs = 10.9.0.2/32
# PBX Node 02
[Peer]
PublicKey = <PBX_NODE_02_PUBLIC_KEY>
AllowedIPs = 10.9.0.3/32

Restart WireGuard:

Terminal window
systemctl restart wg-quick@wg0
wg show

WireGuard executes as an in-kernel module (wireguard.ko) utilizing modern ChaCha20-Poly1305 cryptography. It delivers 3 to 5+ Gbps throughput with near-zero CPU footprint:

  • 1,000 simultaneous G.711 PCMU calls require only ~80 Mbps and ~50,000 pps.
  • WireGuard introduces < 0.1 ms latency, completely undetectable in voice audio quality.

When configuring DNS for Ring2All SBC, keep in mind that Cloudflare standard proxy (Orange Cloud ☁️🧑) supports ONLY HTTP/HTTPS traffic. Cloudflare DOES NOT proxy UDP SIP traffic on port 5060.

1. SIP Signaling DNS Records (Mandatory Grey Cloud ☁️🩢)

Section titled β€œ1. SIP Signaling DNS Records (Mandatory Grey Cloud ☁️🩢)”

For SIP registration and carrier trunking, you must create a DNS record with the Cloudflare proxy disabled (Grey Cloud ☁️🩢) pointing directly to the SBC public IP:

Type Name Content Proxy Status Purpose
A sbc.example.com 203.0.113.10 DNS Only (Grey Cloud ☁️🩢) SIP UDP/TCP Signaling
A sip.example.com 203.0.113.10 DNS Only (Grey Cloud ☁️🩢) Hardphone Registrar

To enable zero-touch provisioning and allow phones to discover the SBC without typing port numbers:

_sip._udp.example.com. IN SRV 10 50 5060 sbc.example.com.
_sips._tcp.example.com. IN SRV 10 50 5061 sbc.example.com.

3. Web Admin Console DNS Records (Orange Cloud ☁️🧑)

Section titled β€œ3. Web Admin Console DNS Records (Orange Cloud ☁️🧑)”

The web administration interface can safely use Cloudflare’s CDN and WAF (Orange Cloud ☁️🧑):

Type Name Content Proxy Status Purpose
CNAME sbc-admin.example.com sbc.example.com Proxied (Orange Cloud ☁️🧑) Web Dashboard & WAF

Run these commands to verify that Ring2All SBC is operating correctly:

Terminal window
systemctl status kamailio
systemctl status rtpengine
systemctl status sbc-api
systemctl status nginx
systemctl status wg-quick@wg0
Terminal window
curl -s http://127.0.0.1:3003/health
# Expected: {"status":"ok","service":"sbc-api","version":"1.0.0"}
Terminal window
ss -ulnp | grep -E '5060|51820'
# Expected: Kamailio listening on 0.0.0.0:5060 and 10.9.0.1:5060; WireGuard on 0.0.0.0:51820
Terminal window
# Check loaded modules
kamcmd system.listMethods
# Check dispatcher status (PBX cluster nodes)
kamcmd dispatcher.list
# Inspect active RTPEngine media sessions
rtpengine-ctl list sessions

1. Phones fail to register with β€œRequest Timeout (408)”

Section titled β€œ1. Phones fail to register with β€œRequest Timeout (408)””
  • Cause: DNS is pointing through Cloudflare Orange Cloud (which drops UDP port 5060) or nftables is dropping inbound SIP packets.
  • Solution: Set DNS record to Grey Cloud (DNS Only) in Cloudflare. Check firewall rules:
    Terminal window
    nft list ruleset | grep 5060
  • Cause: RTPEngine is advertising an internal IP instead of the public IP in SDP headers.
  • Solution: Verify /etc/rtpengine/rtpengine.conf interface configuration:
    interface = external/203.0.113.10;internal/10.9.0.1
    Ensure RTP port range 16384-32768/udp is permitted through the cloud security group.