🔊 Part 6: Compiling, Packaging, and Configuring High-Performance RTPEngine on Debian 13
Welcome to the sixth installment of our “Debian 13 Clustering & Distribution” series. In the previous parts, we set up our custom APT repository, packaged Telephony Server and Kamailio, and deployed high-availability databases and file clusters. In this final guide, we will cover the compilation, packaging, and configuration of Sipwise RTPEngine, the high-performance media proxy. We will walk through building the modular .deb packages, publishing them to our central repository, setting up client-side configuration parameters (such as NAT split-IP mapping), enabling kernel-space packet forwarding for maximum performance, and integrating the engine with Ring2All SBC (Kamailio).
🏗️ Why Use RTPEngine?
Section titled “🏗️ Why Use RTPEngine?”RTPEngine is a user-space/kernel-space media proxy that routes voice and video RTP packets between endpoints. It is particularly critical in systems where:
- NAT Traversal: Rewrites Session Description Protocol (SDP) payloads to bridge private networks and public networks.
- Encryption Bridging: Bridges standard RTP/AVP (used by trunk providers) with encrypted SRTP/SAVPF (used by WebRTC clients).
- Low Latency: Bypasses user-space processing entirely using a kernel module, saving CPU cycles and minimizing voice packet jitter.
🛠️ Phase 1: Environment & Dependency Setup
Section titled “🛠️ Phase 1: Environment & Dependency Setup”Compiling RTPEngine requires build tools along with development libraries for encryption, codec support (FFmpeg), database caching (Redis), systemd integration, and DKMS (Dynamic Kernel Module Support).
1.1 Install Compiling and Packaging Tools
Section titled “1.1 Install Compiling and Packaging Tools”apt-get updateapt-get install -y \ sudo git build-essential devscripts dpkg-dev equivs fakeroot \ autoconf automake libtool libtool-bin cmake pkg-config \ wget curl unzip python-is-python3 python3-all-dev \ python3-setuptools docbook-xsl xsltproc \ libglib2.0-dev graphviz dh-make1.2 Install Build Prerequisites
Section titled “1.2 Install Build Prerequisites”apt-get install -y \ debhelper dh-python dkms dh-dkms default-libmysqlclient-dev \ discount gperf libavcodec-dev libavfilter-dev \ libavformat-dev libavutil-dev libbcg729-dev \ libbencode-perl libcrypt-openssl-rsa-perl \ libcrypt-rijndael-perl libcurl4-openssl-dev \ libdigest-crc-perl libdigest-hmac-perl libevent-dev \ libglib2.0-dev libhiredis-dev libio-multiplex-perl \ libio-socket-inet6-perl libio-socket-ip-perl libiptc-dev \ libjson-glib-dev libjson-perl libjwt-dev libmosquitto-dev \ libncurses-dev libnet-interface-perl libopus-dev \ libpcap-dev libpcre2-dev libsocket6-perl libspandsp-dev \ libssl-dev libswresample-dev libsystemd-dev libtest2-suite-perl \ liburing-dev libwebsockets-dev libwww-perl libxtables-dev \ pandoc pkgconf python3 python3-websockets systemd-dev zlib1g-dev⚙️ Phase 2: Compiling & Packaging RTPEngine
Section titled “⚙️ Phase 2: Compiling & Packaging RTPEngine”We clone Sipwise RTPEngine into /usr/src/rtpengine/src and build modular .deb packages.
2.1 Clone the Repository
Section titled “2.1 Clone the Repository”mkdir -p /usr/src/rtpengine/debgit clone -b master https://github.com/sipwise/rtpengine.git /usr/src/rtpengine/srccd /usr/src/rtpengine/src2.2 Compile and Package
Section titled “2.2 Compile and Package”Clean the repository workspace and run the Debian build script:
# Clean packaging workspacefakeroot debian/rules clean
# Compile binary packages (-b builds binary-only, -us/-uc disables signing)dpkg-buildpackage -us -uc -b -j$(nproc)
# Move all generated packages and build receipts to our deb directorymv /usr/src/rtpengine/*.deb /usr/src/rtpengine/deb/mv /usr/src/rtpengine/*.changes /usr/src/rtpengine/deb/ 2>/dev/null || truemv /usr/src/rtpengine/*.buildinfo /usr/src/rtpengine/deb/ 2>/dev/null || trueThe directory /usr/src/rtpengine/deb/ will contain:
ngcp-rtpengine-daemon_*.deb: The main RTPEngine proxy daemon.ngcp-rtpengine-kernel-dkms_*.deb: The DKMS package that automatically compiles the high-performance kernel module (xt_RTPENGINE) on client nodes.ngcp-rtpengine-recording-daemon_*.deb: Optional call recording service.ngcp-rtpengine-utils_*.deb: Maintenance and administration utilities.ngcp-rtpengine_*.deb: Standard installer meta-package.
🌐 Phase 3: Publishing to the APT Repository Server
Section titled “🌐 Phase 3: Publishing to the APT Repository Server”Upload the packages to your repository server (IP: <YOUR_REPO_IP>, configured in Part 1) to distribute them across client nodes.
3.1 Upload Packages
Section titled “3.1 Upload Packages”scp /usr/src/rtpengine/deb/*.deb root@<YOUR_REPO_IP>:/var/www/pbx-repo/ring2all/trixie/apt/pool/b/base/3.2 Rebuild the Repository Index
Section titled “3.2 Rebuild the Repository Index”Log into your repository server over SSH and rebuild the repository index:
ssh root@<YOUR_REPO_IP> "BuildRepoRing2All"The packages are now available to any server registered to your repository.
🔌 Phase 4: Client-Side Installation & Configuration
Section titled “🔌 Phase 4: Client-Side Installation & Configuration”On your dedicated target RTPEngine media server:
4.1 Install Packages from Your Custom Repository
Section titled “4.1 Install Packages from Your Custom Repository”Run the repository bootstrap script, update the cache, and install RTPEngine. We must install the correct linux-headers so the kernel module compiles successfully:
# Bootstrap repositorywget -qO- https://repo.softswitchone.com/apt/setup_repo | bashapt-get update
# Install compiler headers matching the running kernelapt-get install -y dkms linux-headers-$(uname -r)
# Install RTPEngineapt-get install -y ngcp-rtpengine-daemon ngcp-rtpengine-kernel-dkms ngcp-rtpengine-utils ngcp-rtpengineVerify that the kernel module is compiled and loaded into memory:
lsmod | grep xt_RTPENGINE# Expected output: xt_RTPENGINE 32768 04.2 Configure RTPEngine (/etc/rtpengine/rtpengine.conf)
Section titled “4.2 Configure RTPEngine (/etc/rtpengine/rtpengine.conf)”Open /etc/rtpengine/rtpengine.conf and configure the following parameters. Pay close attention to NAT split-IP mappings and port bindings:
[rtpengine]# --- Network Interfaces ---# If the server has a public IP and private IP (NAT split-IP mapping):# Format: logical_name/internal_ip logical_name/external_ipinterface = internal/192.168.10.50 external/76.13.102.50
# --- Port Settings ---# UDP port range for media (RTP/RTCP packets)port-min = 16384port-max = 32768
# --- Control Sockets ---# UDP port for receiving control instructions from Kamailio / Ring2All SBClisten-ng = 192.168.10.50:2223
# --- Kernel Space Data Forwarding ---# Table index (must match the kernel iptables tables configuration)table = 0
# --- Logging & Security ---log-level = 5log-facility = local0run-as-user = rtpenginerun-as-group = rtpengineSave the file and restart the daemon:
systemctl restart ngcp-rtpengine-daemonsystemctl status ngcp-rtpengine-daemon🚀 Phase 5: High-Performance Kernel-Space Optimization
Section titled “🚀 Phase 5: High-Performance Kernel-Space Optimization”By default, RTPEngine acts as a user-space proxy: packets enter the kernel, are copied to user-space, processed, copied back to the kernel, and sent. In high-density environments, this copying causes latency and high CPU usage.
By enabling kernel-space forwarding, RTPEngine delegates the packet routing directly to the kernel network stack, achieving wire-speed performance.
5.1 Load the Kernel Module
Section titled “5.1 Load the Kernel Module”Verify that the xt_RTPENGINE kernel module loads on boot. It should be automatically registered by DKMS during installation. To force load it manually:
modprobe xt_RTPENGINE5.2 Configure kernel tables
Section titled “5.2 Configure kernel tables”The table value in rtpengine.conf is configured to table = 0. Ensure this interfaces with the kernel stack correctly:
# Create the forwarding table file inside sysfs if not automatically createdecho "add 0" > /proc/rtpengine/controlReview your journal logs to confirm kernel forwarding is enabled:
journalctl -u ngcp-rtpengine-daemon | grep -i "kernel"# Expected output: Kernel-space packet forwarding successfully enabled.🔗 Phase 6: Ring2All SBC (Kamailio) Integration
Section titled “🔗 Phase 6: Ring2All SBC (Kamailio) Integration”Now we link our SIP router (Kamailio / Ring2All SBC) to our media engine.
6.1 Register the RTPEngine socket in Kamailio
Section titled “6.1 Register the RTPEngine socket in Kamailio”On your Kamailio application server, edit your configuration file (or the database profile) to register the RTPEngine control socket. In Kamailio’s kamailio.cfg:
# --- RTPEngine module parameters ---loadmodule "rtpengine.so"modparam("rtpengine", "rtpengine_sock", "udp:192.168.10.50:2223")6.2 Verify the Integration
Section titled “6.2 Verify the Integration”Restart Kamailio and test the control socket connection:
kamailio -c -f /etc/kamailio/kamailio.cfgsystemctl restart kamailio
# Query active media engines using Kamailio CLIkamcmd rtpengine.show allKamailio will list the RTPEngine socket status as UP and operational.
Your high-performance RTPEngine media proxy is now fully configured and integrated into your distributed telephony platform!

