--- title: "Ring2All SBC (Session Border Controller) Documentation" description: "Documentation for SBC Overview" --- > **Official Slogan:** *"High-Throughput Perimeter SIP Engine & Carrier LCR"* > **Brand Identity:** Emerald / Cyan (`#10B981`) β€’ Icon: `shield` β€’ Component Code: `sbc` Welcome to the comprehensive technical and operational documentation for **Ring2All SBC**, the perimeter Class 4 Session Border Controller and SIP routing engine of the Ring2All carrier-grade communications suite. --- ## Table of Contents 1. [Platform Overview & Architecture](#1-platform-overview--architecture) 2. [Commercial & Operational Value](#2-commercial--operational-value) 3. [Core Capabilities & High-Throughput Engine](#3-core-capabilities--high-throughput-engine) 4. [SBC Module Documentation Index](#4-sbc-module-documentation-index) 5. [Network Topology & Security Zones](#5-network-topology--security-zones) 6. [Hardware & Sizing Recommendations](#6-hardware--sizing-recommendations) 7. [Glossary of Carrier Terms](#7-glossary-of-carrier-terms) --- ## 1. Platform Overview & Architectu**Ring2All SBC** serves as the hardened perimeter gatekeeper and carrier interconnection core for all inbound and outbound SIP traffic. Built upon **Kamailio 6.1+**, **RTPEngine 12.5+** (with kernel-space `xt_RTPENGINE` packet forwarding), and a responsive Fastify/React administrative suite, it separates untrusted public networks and wholesale carriers from internal application servers (Ring2All PBX) and financial systems (Ring2All Billing). ```mermaid flowchart TD subgraph Untrusted["🌐 Untrusted Public Perimeter"] Carriers["Wholesale PSTN Carriers"] RemoteTrunks["Remote SIP Trunks"] WebRTC["WebRTC Browser Clients"] end subgraph SBC["πŸ›‘οΈ Ring2All SBC (Class 4 Perimeter Gatekeeper)"] direction TB Kamailio["⚑ Kamailio 6.1+ Signalling Engine
β€’ Pike Anti-Flood & Rate Limiting
β€’ Drouting LCR Engine
β€’ Dispatcher Load Balancing
β€’ Topology Hiding"] RTPEngine["🎧 RTPEngine 12.5+ Media Relay
β€’ xt_RTPENGINE Kernel Forwarding
β€’ WebRTC DTLS-SRTP Gateway
β€’ Symmetric NAT Traversal
β€’ MOS / QoS Analytics"] ControlPlane["πŸŽ›οΈ Control Plane (Fastify 5 REST API)
β€’ AI Perimeter Guard
β€’ Whitelist/Blacklist Sync
β€’ Live SIP Ladders"] Kamailio <--> RTPEngine Kamailio --> ControlPlane end subgraph InternalCore["🏒 Protected Core Zone (WireGuard / VPC)"] PBX["βš™οΈ Ring2All PBX Engine (Class 5 Core)"] BSS["πŸ’³ Ring2All BSS (Billing OCS & Accounting)"] end Carriers -->|"SIP 5060/5061"| Kamailio RemoteTrunks -->|"SIP 5060/5061"| Kamailio WebRTC -->|"WSS / DTLS"| Kamailio Carriers <.->|"RTP 10000-40000"| RTPEngine RemoteTrunks <.->|"RTP 10000-40000"| RTPEngine WebRTC <.->|"SRTP / Opus"| RTPEngine Kamailio -->|"Internal SIP Trunk"| PBX Kamailio -->|"Real-time CDR / Fraud Events"| BSS ``` ### Key Architectural CharacteristicsοΏ½οΏ½β”€β”€β”€β”€β”˜ β”‚ Internal WireGuard Tunnel / VPC β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ INTERNAL CORE APPS ZONE β”‚ β”‚ Ring2All PBX (Class 5 Core) β”‚ Ring2All Billing (BSS/OSS & OCS) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ ``` ### Key Architectural Characteristics * **Sub-Millisecond Signalling Latency:** In-memory caching (`shm`) for LCR routing tables, IP access control lists, and dispatcher server lists. * **Kernel-Space Media Processing:** Through `xt_RTPENGINE` iptables integration, media packets are relayed directly within Linux kernel space, bypassing user-space context switches. * **Full Topology Hiding:** Strips internal IP addresses, `Via`, `Record-Route`, and `Server` headers to shield internal infrastructure from external reconnaissance. * **Multi-Master HA Clustering:** Distributed state synchronization across redundant SBC nodes with automatic failover in < 500ms. --- ## 2. Commercial & Operational Value * **Zero Carrier Telecom Fraud:** Immediate automated rate limiting (Pike module) blocks automated SIP brute-force attempts and toll fraud in under 1 second. * **Carrier Cost Optimization (LCR):** Prefix-based Least Cost Routing evaluates wholesale rate cards in real time to route outbound calls via the most economical healthy carrier. * **Unified WebRTC to SIP Gateway:** Bridges browser-based audio/video communications (DTLS-SRTP with Opus) seamlessly to standard G.711/G.729 carrier interconnects. * **Carrier Interconnection Flexibility:** Supports both IP authentication (ACL whitelist) and digest authentication (HA1/HA1B) with independent capacity limits per trunk. --- ## 3. Core Capabilities & High-Throughput Engine | Capability | Specification / Implementation | | :--- | :--- | | **Max Concurrent Calls (CPS)** | 500+ Call Setups per Second per Node | | **Simultaneous Media Sessions** | 10,000+ Concurrent RTP Streams with `xt_RTPENGINE` | | **LCR Route Capacity** | 1,000,000+ E.164 prefix routing entries in memory | | **Media Transcoding** | Opus, G.711u/a, G.729, G.722, AMR-WB, VP8/H.264 | | **Security Blacklists** | Real-time ingestion of APIBAN, VoIPBL, and dynamic IP bans | | **Diagnostic Tracing** | Zero-impact on-demand packet capture with visual ladder diagrams | --- ## 4. SBC Module Documentation Index ### Core Routing Engine | Module Guide | Primary Function | | :--- | :--- | | [**SIP Domains**](routing/domains.md) | Multi-tenant ingress domain mapping, FQDN resolution, and Dispatcher set binding. | | [**MS Teams Direct Routing**](routing/msteams.md) | Microsoft 365 Direct Routing integration, TLS mutual authentication, and SBC FQDN SANs. | | [**PBX Endpoints**](routing/endpoints.md) | Telephony Server and Asterisk telephony cluster pools, health heartbeats, and failover sets. | | [**Carriers & Groups**](routing/carriers.md) | Upstream wholesale gateway pools, IP ACLs, and rate limiting groups. | | [**Quality Routing (SLA)**](routing/quality.md) | Real-time ASR, ACD, and MOS telemetry-driven closed-loop autonomous rerouting. | | [**SIP Accounts**](routing/sip-accounts.md) | Wholesale SIP Trunks, IP vs Credential Authentication, HA1 hashes, Channel and CPS limits. | | [**DIDs & Inbound Routing**](routing/dids.md) | Inbound phone number inventory, E.164 normalization, and automated routing to Ring2All PBX. | | [**Outbound Routes & LCR**](routing/outbound-routes.md) | Class 4 Least Cost Routing (Drouting), prefix trees, carrier failover, and quality-based routing. | | [**STIR/SHAKEN Service**](routing/stirshaken.md) | STI-AS cryptographic call signing, PASSporT tokens, STI-VS identity verification, and x5u repos. | ### Perimeter Infrastructure & Security | Module Guide | Primary Function | | :--- | :--- | | [**Dispatcher & Cluster HA**](dispatcher-load-balancing.md) | Load balancing to Ring2All PBX media servers, health check heartbeats (OPTIONS), and failover algorithms. | | [**RTPEngine Media Relay**](rtpengine-media-relay.md) | Media proxying, symmetric NAT traversal, WebRTC bridging, and real-time MOS quality tracking. | | [**Perimeter Security & Anti-Fraud**](security-antifraud-pike.md) | Pike flood protection, htable rate limiting, Geo-Firewall, VoIPBL, and APIBAN honeypot feeds. | | [**AI Perimeter Guard**](ai-perimeter-guard.md) | Real-time SIP packet capture, ladder diagram inspector, and AI-powered diagnostic copilot. | | [**System & Resource Monitoring**](monitoring-smr.md) | Live CPS dashboard, active dialogs, memory utilization, and administrative RPC terminal (`kamcmd`). | | [**User & Preferences**](account-menu/README.md) | Dashboard layout customization, administrator profile, theme ergonomics, and system architecture details. | --- ## 5. Network Topology & Security Zones Ring2All SBC is designed to sit directly across security perimeters: * **Public Interface (`eth0` / WAN):** Exposes ports UDP/TCP 5060 (SIP), TLS 5061 (SIPS), and UDP 10000–40000 (RTP). Protected by Pike anti-flood and kernel packet filtering. * **Internal Private Interface (`wg0` / Private VPC):** Interconnects with Ring2All PBX nodes, database clusters, and Billing OCS engines. No external traffic is ever routed into this interface. * **Management Interface (HTTPS 443):** Protected by JWT, role profiles, and SHA-256 API keys. --- ## 6. Hardware & Sizing Recommendations | Scale Tier | Concurrent Calls | Target Hardware (Bare Metal / VM) | | :--- | :--- | :--- | | **Small / Lab** | Up to 250 calls | 2 vCPU, 4 GB RAM, 20 GB NVMe | | **Mid Carrier** | 250 – 2,500 calls | 8 vCPU, 16 GB RAM, 100 GB NVMe, 1 Gbps NIC | | **Tier-1 Carrier** | 2,500 – 15,000 calls | 32 vCPU, 64 GB RAM, 500 GB NVMe, 10 Gbps DPDK/NIC | --- ## 7. Glossary of Carrier Terms * **CPS (Calls Per Second):** The rate at which new call setups (`INVITE`) are processed by the signalling engine. * **LCR (Least Cost Routing):** Algorithmic selection of wholesale egress carriers based on rate card cost and quality indicators (ASR/ACD). * **PDD (Post-Dial Delay):** Time elapsed between sending the final digit of the destination number and receiving ringback tone (`180 Ringing`). * **Topology Hiding:** Sanitization of internal IP addresses and server headers in outgoing SIP requests to prevent infrastructure mapping.