Device SIP Profiles Module Documentation
Table of Contents
Section titled “Table of Contents”- Navigation & Access
- Screenshots & Visual Interface
- Module Overview (Technical)
- Module Overview (Commercial/Business)
- Module Overview (End User/Administrator)
- User Roles & Key Capabilities
- Configuration Categories
- Settings Reference
- Common Scenarios & Examples
- Limitations & Important Notes
- Troubleshooting Tips
- Glossary
- Model Context Protocol (MCP) AI Integration
Navigation & Access
Section titled “Navigation & Access”To access the Device Profiles configuration module:
- Log in to the Ring2All Web Portal (
https://<domain-or-ip>/login). - In the left navigation sidebar, expand Settings.
- Under Technology, click Device profiles (
/settings/technology/device-profile). - To add a new device profile template, click + Add Profile (
/settings/technology/device-profile/new). To edit an existing profile, click on the profile row or the Edit action button (/settings/technology/device-profile/:id).
Screenshots & Visual Interface
Section titled “Screenshots & Visual Interface”Device Profiles Directory
Section titled “Device Profiles Directory”Directory of registered device profile templates applied to extensions and IP endpoints, detailing profile names, descriptions, associated Telephony Server profile bindings, and modification history.

Device Profile Configuration Form
Section titled “Device Profile Configuration Form”Granular configuration form for provisioning and extension registration templates, enabling administrators to define NAT traversal parameters, codec negotiation hierarchies, TLS encryption, and custom Sofia directory variables.

1. Module Overview (Technical)
Section titled “1. Module Overview (Technical)”What Are Device SIP Profiles?
Section titled “What Are Device SIP Profiles?”Device SIP Profiles are provisioning templates that define SIP parameters for devices (IP phones, softphones, WebRTC clients). Unlike SIP Profiles (which configure Telephony Server), Device SIP Profiles configure how individual device registrations are handled with specific NAT, codec, and security settings.
Architecture
Section titled “Architecture”┌─────────────────────────────────────────────────────────────────┐│ Device SIP Profiles Architecture │├─────────────────────────────────────────────────────────────────┤│ ││ Admin Panel ││ ┌──────────────────────────────────────────────────────────┐ ││ │ Device SIP Profiles │ ││ │ │ ││ │ Templates: │ ││ │ ├─ LAN Phones (NAT disabled, UDP) │ ││ │ ├─ Remote Phones (NAT enabled, TLS) │ ││ │ └─ WebRTC Clients (WSS, DTLS, ICE) │ ││ │ │ ││ └──────────────────────────────────────────────────────────┘ ││ │ ││ ▼ Assigned to devices ││ ┌──────────────────────────────────────────────────────────┐ ││ │ Extensions / Devices │ ││ │ │ ││ │ Extension 1001 → LAN Phones profile │ ││ │ Extension 1002 → Remote Phones profile │ ││ │ Extension 1003 → WebRTC Clients profile │ ││ │ │ ││ └──────────────────────────────────────────────────────────┘ ││ │ ││ ▼ Applied during registration ││ ┌──────────────────────────────────────────────────────────┐ ││ │ Telephony Server │ ││ │ │ ││ │ Device registers → Profile settings applied: │ ││ │ ├─ NAT handling │ ││ │ ├─ Codec preferences │ ││ │ ├─ Security (TLS, SRTP) │ ││ │ └─ SIP headers │ ││ │ │ ││ └──────────────────────────────────────────────────────────┘ ││ │└─────────────────────────────────────────────────────────────────┘1.1 Dynamic Profile Inheritance vs Explicit Override (None / Inherit from Profile)
Section titled “1.1 Dynamic Profile Inheritance vs Explicit Override (None / Inherit from Profile)”How None (inherit from profile) Works
Section titled “How None (inherit from profile) Works”When creating or editing an extension, the SIP Profile field defaults to None (inherit from profile) (sip_profile_id = null).
- Dynamic Transport Auto-Detection: Without static device profile overrides in the user’s directory XML, Telephony Server’s Sofia
internalprofile auto-detects the connecting transport:- UDP (Port 5060): Automatically negotiates standard RTP for physical desk phones (Yealink, Grandstream, Cisco).
- WebSocket / WSS (Port 7443): Automatically enables DTLS-SRTP, ICE candidates, and RTCP-mux for browser-based WebRTC clients.
- Hybrid Simultaneous Registration: Leaving the profile as
Noneallows the same extension to be registered simultaneously on a physical desk phone and a web browser app without configuration conflicts.
When to Assign an Explicit Device Profile
Section titled “When to Assign an Explicit Device Profile”Assign an explicit profile (e.g., Default Internal or Default WebRTC) only when you need to enforce static overrides for specific endpoints, such as:
- Forcing a specific re-registration interval (e.g. 120 seconds).
- Forcing strict codec constraints or disabling media transcoding.
- Enforcing custom network ACLs (
authAcl) or bypass media policies.
2. Module Overview (Commercial/Business)
Section titled “2. Module Overview (Commercial/Business)”Business Value
Section titled “Business Value”Device SIP Profiles provides device-specific configuration:
| Without Device Profiles | With Device Profiles |
|---|---|
| One-size-fits-all | Tailored per device type |
| NAT issues | Proper NAT handling |
| Security gaps | TLS/SRTP per profile |
| Codec problems | Optimized codecs |
Use Cases
Section titled “Use Cases”-
LAN Phone Deployment
- Disable NAT traversal
- Use all codecs
-
Remote Workers
- Enable aggressive NAT
- Require TLS/SRTP
-
WebRTC Clients
- Enable WSS, ICE, DTLS
- Configure RTCP-mux
-
Legacy Devices
- Adjust for compatibility
- Specific codec order
Feature Highlights
Section titled “Feature Highlights”| Feature | Benefit |
|---|---|
| Templates | Reusable configurations |
| NAT Settings | Handle any network |
| Codec Control | Optimize quality |
| Security Options | TLS, SRTP, DTLS |
| WebRTC Support | Browser clients |
| Per-Device | Granular control |
3. Module Overview (End User/Administrator)
Section titled “3. Module Overview (End User/Administrator)”What Can You Do?
Section titled “What Can You Do?”- Create device SIP profile templates
- Configure NAT traversal settings
- Set codec preferences
- Enable security (TLS, SRTP)
- Configure WebRTC support
- Assign profiles to devices/extensions
Device SIP Profiles Interface
Section titled “Device SIP Profiles Interface”┌─────────────────────────────────────────────────────────────────┐│ Device SIP Profiles │├─────────────────────────────────────────────────────────────────┤│ ││ [+ Create Device Profile] ││ ││ ┌───────────────────────────────────────────────────────────┐ ││ │ Profile Name │ Description │ Usage │ Status │ ││ ├──────────────────┼──────────────────────┼───────┼────────┤ ││ │ LAN Phones │ Local office phones │ 45 │ ✓ On │ ││ │ Remote Phones │ Work from home │ 20 │ ✓ On │ ││ │ WebRTC Clients │ Browser softphone │ 15 │ ✓ On │ ││ │ Legacy ATA │ Older analog adapters│ 5 │ ✓ On │ ││ └───────────────────────────────────────────────────────────┘ ││ │└─────────────────────────────────────────────────────────────────┘Profile Edit View
Section titled “Profile Edit View”┌─────────────────────────────────────────────────────────────────┐│ Edit Device Profile: WebRTC Clients │├─────────────────────────────────────────────────────────────────┤│ ││ Profile Name: [WebRTC Clients ] ││ Description: [Browser-based softphones ] ││ Sofia Profile: [internal-tls ▼] ││ Enabled: ✓ ││ ││ ▼ Network ││ ├─ Authentication ACL: [ANY ▼] ││ └─ Force Register Domain: ✓ ││ ││ ▼ NAT Traversal ││ ├─ Aggressive NAT Detection: ✓ ││ ├─ Rewrite Contact Header: ✓ ││ └─ Force rport: ✓ ││ ││ ▼ Media Control ││ ├─ RTP Timeout (Seconds): [300 ] ││ ├─ Bypass Media: ☐ ││ └─ Disable Transcoding: ☐ ││ ││ ▼ Codec Preferences ││ ├─ Inbound Codecs: [OPUS, PCMU, PCMA ▼] ││ ├─ Outbound Codecs: [OPUS, PCMU, PCMA ▼] ││ └─ DTMF Method: [RFC 2833 ▼] ││ ││ ▼ Transport & Security ││ ├─ Enable WebSocket (WS): ☐ ││ ├─ Enable Secure WebSocket (WSS): ✓ ││ ├─ Enable TLS: ✓ ││ └─ TLS Only Mode: ✓ ││ ││ ▼ Security & RTP ││ ├─ Enable DTLS-SRTP: ✓ ││ ├─ Enable ICE NAT Traversal: ✓ ││ ├─ Enable RTCP Multiplexing: ✓ ││ └─ Secure RTP (SRTP) Mode: [Always Use SRTP ▼] ││ ││ [Save] [Cancel] ││ │└─────────────────────────────────────────────────────────────────┘Quick Tips
Section titled “Quick Tips”[!TIP] WebRTC: Enable WSS, DTLS, ICE, and RTCP-mux for browser clients.
[!TIP] Remote Workers: Enable aggressive NAT detection and TLS.
[!NOTE] Usage Count: Shows how many devices use this profile.
🎯 User Roles & Key Capabilities
Section titled “🎯 User Roles & Key Capabilities”| Role | Permissions | Key Capabilities |
|---|---|---|
| Super Administrator | Full Access (read, write, delete, clone) |
Create global and domain-specific device templates, configure default WebRTC/TLS media profiles, and manage encryption rules. |
| PBX Administrator | Domain Management (read, write) |
Assign device profiles to extensions, customize codec ordering (e.g. OPUS first), and enforce aggressive NAT detection for remote softphones. |
| Provisioning Specialist | Operational (read, write) |
Create vendor-tailored device profiles for Yealink, Grandstream, Polycom, and Cisco physical IP phones. |
| Support Specialist | Read & Diagnostic (read) |
Inspect extension device profile assignments, verify DTLS/SRTP settings, and diagnose media negotiation failures. |
4. Configuration Categories
Section titled “4. Configuration Categories”Network
Section titled “Network”| Setting | Description |
|---|---|
| Authentication ACL | LAN, WAN, or ANY |
| Force Register Domain | Lock registration domain |
NAT Traversal
Section titled “NAT Traversal”| Setting | Description |
|---|---|
| Aggressive NAT Detection | Deep NAT inspection |
| Rewrite Contact Header | Fix Contact for NAT |
| Force rport | Use source port |
Media Control
Section titled “Media Control”| Setting | Description |
|---|---|
| RTP Timeout | Inactivity timeout |
| RTP Hold Timeout | Hold inactivity timeout |
| Bypass Media | Direct RTP between devices |
| Disable Transcoding | Allow asymmetric codecs |
| Session Timeout | Maximum call duration |
Codec Preferences
Section titled “Codec Preferences”| Setting | Description |
|---|---|
| Inbound Codec Prefs | Incoming codec priority |
| Outbound Codec Prefs | Outgoing codec priority |
| DTMF Method | RFC2833, SIP INFO, In-band |
| RFC2833 Payload Type | DTMF RTP payload |
SIP Headers
Section titled “SIP Headers”| Setting | Description |
|---|---|
| Send Remote-Party-ID | Include RPID header |
| Send P-Asserted-Identity | Include PAI header |
| Send SIP Diversion | Include Diversion header |
| SIP Caller ID Type | None, PAI, or RPID |
Transport & Security
Section titled “Transport & Security”| Setting | Description |
|---|---|
| Enable WebSocket | WS for debugging |
| Enable Secure WebSocket | WSS for browsers |
| Enable TLS | Encrypted signaling |
| TLS Only Mode | Require TLS |
| Registration Expires | Re-registration interval |
| TLS Verify Policy | Certificate validation |
Security & RTP
Section titled “Security & RTP”| Setting | Description |
|---|---|
| Enable DTLS-SRTP | Encrypted media (WebRTC) |
| Enable ICE | NAT traversal for WebRTC |
| Enable RTCP-mux | Share RTP/RTCP port |
| Secure RTP Mode | Always, Optional, Never |
| Require Secure Media | Enforce SRTP |
5. Settings Reference
Section titled “5. Settings Reference”Profile Types
Section titled “Profile Types”| Profile Type | Key Settings |
|---|---|
| LAN Phones | NAT off, UDP, all codecs |
| Remote Phones | NAT on, TLS, SRTP |
| WebRTC Clients | WSS, ICE, DTLS, RTCP-mux |
| Legacy ATA | Basic codecs, relaxed NAT |
WebRTC Requirements
Section titled “WebRTC Requirements”| Setting | Value |
|---|---|
| WSS | ✓ Required (via Nginx proxy on port 443) |
| DTLS-SRTP | ✓ Required |
| ICE | ✓ Required |
| RTCP-mux | ✓ Required |
| Codecs | OPUS preferred |
[!NOTE] WebRTC clients connect via
wss://domain/wson port 443. Nginx terminates TLS and forwards plain WebSocket to Telephony Server on127.0.0.1:5066. No separate WSS port is needed on Telephony Server.
Security Levels
Section titled “Security Levels”| Level | TLS | SRTP | Use Case |
|---|---|---|---|
| None | ☐ | ☐ | LAN only |
| Signaling | ✓ | ☐ | Basic security |
| Full | ✓ | ✓ | Remote/WFH |
| Maximum | ✓ | Required | High security |
6. Common Scenarios & Examples
Section titled “6. Common Scenarios & Examples”Scenario 1: LAN Office Phones
Section titled “Scenario 1: LAN Office Phones”- Create new profile
- Set Authentication ACL = LAN
- Disable NAT settings
- Set codecPrefs = PCMU,PCMA,G722
- Save and assign to extensions
Scenario 2: Remote Worker
Section titled “Scenario 2: Remote Worker”- Create new profile
- Enable Aggressive NAT Detection
- Enable Rewrite Contact, Force rport
- Enable TLS and SRTP
- Save and assign
Scenario 3: WebRTC Softphone
Section titled “Scenario 3: WebRTC Softphone”- Create new profile
- Set Authentication ACL = ANY
- Enable all NAT options
- Enable WSS, DTLS, ICE, RTCP-mux
- Set codecs to OPUS
- DTMF = RFC2833
[!NOTE] WebRTC connection flow: Browser →
wss://domain/ws(Nginx, port 443) →ws://127.0.0.1:5066(Telephony Server). TLS is handled by Nginx.
Scenario 4: Legacy ATA
Section titled “Scenario 4: Legacy ATA”- Create new profile
- Basic NAT settings
- Set codecs = PCMU,PCMA only
- Set DTMF = Inband or INFO
- Longer timeouts
7. Limitations & Important Notes
Section titled “7. Limitations & Important Notes”Technical Notes
Section titled “Technical Notes”[!NOTE] Profile Assignment: Profiles are assigned to extensions/devices.
[!NOTE] Sofia Profile: Must select base SIP profile (internal/external).
[!WARNING] Cannot Delete In-Use: Profiles with assigned devices cannot be deleted.
Best Practices
Section titled “Best Practices”- Create Per Type: Different profiles for different device types
- Test Thoroughly: Test NAT settings before deployment
- Security First: Use TLS/SRTP for remote devices
- Codec Matching: Match codecs to device capabilities
- Document Profiles: Note what each profile is for
8. Troubleshooting Tips
Section titled “8. Troubleshooting Tips”Common Issues
Section titled “Common Issues”| Symptom | Possible Cause | Solution |
|---|---|---|
| Registration fails | Wrong ACL | Check Authentication ACL |
| One-way audio | NAT issues | Enable NAT options |
| No audio | Codec mismatch | Check codec preferences |
| WebRTC not working | Missing WSS/ICE | Enable WebRTC settings |
| DTMF not working | Wrong DTMF type | Change DTMF method |
WebRTC Checklist
Section titled “WebRTC Checklist”| Setting | Required |
|---|---|
| Enable WSS | ✓ |
| Enable DTLS-SRTP | ✓ |
| Enable ICE | ✓ |
| Enable RTCP-mux | ✓ |
| Secure RTP | Optional or Always |
| Codecs | Include OPUS |
NAT Checklist
Section titled “NAT Checklist”| Setting | Remote Devices |
|---|---|
| Aggressive NAT Detection | ✓ |
| Rewrite Contact | ✓ |
| Force rport | ✓ |
9. Glossary
Section titled “9. Glossary”| Term | Definition |
|---|---|
| Device Profile | SIP settings template for devices |
| NAT | Network Address Translation |
| SRTP | Secure Real-time Transport Protocol |
| DTLS | Datagram TLS for media |
| ICE | Interactive Connectivity Establishment |
| WSS | WebSocket Secure |
| RTCP-mux | RTP/RTCP on same port |
| OPUS | High-quality audio codec |
Model Context Protocol (MCP) AI Integration
Section titled “Model Context Protocol (MCP) AI Integration”The Ring2All PBX platform integrates deep AI assistance via the Model Context Protocol (MCP). The Device SIP Profiles module exposes intelligent tools allowing the PBX AI Copilot to query available device templates, analyze codec and NAT profiles, and recommend optimal settings for IP phones, softphones, and browser-based WebRTC endpoints.
Available MCP Tools
Section titled “Available MCP Tools”| Tool Name | Operation Type | RBAC Risk Level | Description |
|---|---|---|---|
list_device_sip_profiles |
Read / Query | low |
Lists Directory / Device SIP Profiles (configuration templates for physical IP phones, softphones, and WebRTC clients) with domain isolation. |
diagnose_media_nat |
Diagnostic / Query | low |
Performs deep operational diagnostic on VoIP media, RTP audio flow, and NAT traversal: checks Sofia profile IP parameters (ext-rtp-ip), detects RFC1918 private IP leaks in SDP, verifies UDP 16384-32768 port availability, and detects one-way audio/silence on live channels. |
Tool Input Schemas & Parameters
Section titled “Tool Input Schemas & Parameters”1. list_device_sip_profiles
Section titled “1. list_device_sip_profiles”{ "name": "list_device_sip_profiles", "description": "List Directory / Device SIP Profiles (configuration templates for physical IP phones, softphones, and WebRTC clients).", "inputSchema": { "type": "object", "properties": { "search": { "type": "string", "description": "Filter by device profile name or description (e.g. 'WebRTC', 'Internal Phones')." } } }}2. diagnose_media_nat
Section titled “2. diagnose_media_nat”{ "name": "diagnose_media_nat", "description": "Perform deep diagnostic on VoIP media, RTP audio flow, and NAT traversal (Sofia ext-rtp-ip, RFC1918 SDP leaks, one-way audio detection).", "inputSchema": { "type": "object", "properties": { "callUuid": { "type": "string", "description": "Optional active or recent call UUID to inspect live RTP packet counters." }, "extension": { "type": "string", "description": "Optional extension number to inspect SIP registration NAT contact." } } }}Natural Language Prompts
Section titled “Natural Language Prompts”| User Request | Invoked MCP Tool | Expected AI Response |
|---|---|---|
| “List all device SIP profiles available for our extensions.” | list_device_sip_profiles |
Returns profile list (Default Internal, Default WebRTC, Default External) with base profile mappings. |
| “Do we have a device profile configured for WebRTC softphones?” | list_device_sip_profiles({ search: "WebRTC" }) |
Locates and displays WebRTC profile details, verifying WSS, DTLS, and ICE status. |
| “Which device profile should be assigned to remote teleworkers behind NAT?” | list_device_sip_profiles |
Recommends Default External with aggressive NAT detection and rewrite contact enabled. |
Multi-Tenant & Security Safeguards
Section titled “Multi-Tenant & Security Safeguards”- Strict Domain Isolation: Device profiles are queried within the caller’s active domain (
domain_id) or global system defaults (domain_id IS NULL), ensuring complete tenant boundary separation. - Anti-Collision Protection: Device profile names are uniquely enforced within their domain to avoid collision across extension assignments.
- Secure Media Verification: WebRTC profiles are validated for mandatory DTLS-SRTP and encryption compliance before activation.
- Audit Logging: All administrative profile views and updates are recorded in the central audit ledger.
Documentation last updated: January 2026

