---
title: "Ring2All SBC (Session Border Controller) Documentation"
description: "Documentation for SBC Overview"
---
> **Official Slogan:** *"High-Throughput Perimeter SIP Engine & Carrier LCR"*
> **Brand Identity:** Emerald / Cyan (`#10B981`) β’ Icon: `shield` β’ Component Code: `sbc`
Welcome to the comprehensive technical and operational documentation for **Ring2All SBC**, the perimeter Class 4 Session Border Controller and SIP routing engine of the Ring2All carrier-grade communications suite.
---
## Table of Contents
1. [Platform Overview & Architecture](#1-platform-overview--architecture)
2. [Commercial & Operational Value](#2-commercial--operational-value)
3. [Core Capabilities & High-Throughput Engine](#3-core-capabilities--high-throughput-engine)
4. [SBC Module Documentation Index](#4-sbc-module-documentation-index)
5. [Network Topology & Security Zones](#5-network-topology--security-zones)
6. [Hardware & Sizing Recommendations](#6-hardware--sizing-recommendations)
7. [Glossary of Carrier Terms](#7-glossary-of-carrier-terms)
---
## 1. Platform Overview & Architectu**Ring2All SBC** serves as the hardened perimeter gatekeeper and carrier interconnection core for all inbound and outbound SIP traffic. Built upon **Kamailio 6.1+**, **RTPEngine 12.5+** (with kernel-space `xt_RTPENGINE` packet forwarding), and a responsive Fastify/React administrative suite, it separates untrusted public networks and wholesale carriers from internal application servers (Ring2All PBX) and financial systems (Ring2All Billing).
```mermaid
flowchart TD
subgraph Untrusted["π Untrusted Public Perimeter"]
Carriers["Wholesale PSTN Carriers"]
RemoteTrunks["Remote SIP Trunks"]
WebRTC["WebRTC Browser Clients"]
end
subgraph SBC["π‘οΈ Ring2All SBC (Class 4 Perimeter Gatekeeper)"]
direction TB
Kamailio["β‘ Kamailio 6.1+ Signalling Engine
β’ Pike Anti-Flood & Rate Limiting
β’ Drouting LCR Engine
β’ Dispatcher Load Balancing
β’ Topology Hiding"]
RTPEngine["π§ RTPEngine 12.5+ Media Relay
β’ xt_RTPENGINE Kernel Forwarding
β’ WebRTC DTLS-SRTP Gateway
β’ Symmetric NAT Traversal
β’ MOS / QoS Analytics"]
ControlPlane["ποΈ Control Plane (Fastify 5 REST API)
β’ AI Perimeter Guard
β’ Whitelist/Blacklist Sync
β’ Live SIP Ladders"]
Kamailio <--> RTPEngine
Kamailio --> ControlPlane
end
subgraph InternalCore["π’ Protected Core Zone (WireGuard / VPC)"]
PBX["βοΈ Ring2All PBX Engine (Class 5 Core)"]
BSS["π³ Ring2All BSS (Billing OCS & Accounting)"]
end
Carriers -->|"SIP 5060/5061"| Kamailio
RemoteTrunks -->|"SIP 5060/5061"| Kamailio
WebRTC -->|"WSS / DTLS"| Kamailio
Carriers <.->|"RTP 10000-40000"| RTPEngine
RemoteTrunks <.->|"RTP 10000-40000"| RTPEngine
WebRTC <.->|"SRTP / Opus"| RTPEngine
Kamailio -->|"Internal SIP Trunk"| PBX
Kamailio -->|"Real-time CDR / Fraud Events"| BSS
```
### Key Architectural CharacteristicsοΏ½οΏ½βββββ
β
Internal WireGuard Tunnel / VPC
β
βββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββ
β INTERNAL CORE APPS ZONE β
β Ring2All PBX (Class 5 Core) β Ring2All Billing (BSS/OSS & OCS) β
ββββββββββββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββββββββββββββ
```
### Key Architectural Characteristics
* **Sub-Millisecond Signalling Latency:** In-memory caching (`shm`) for LCR routing tables, IP access control lists, and dispatcher server lists.
* **Kernel-Space Media Processing:** Through `xt_RTPENGINE` iptables integration, media packets are relayed directly within Linux kernel space, bypassing user-space context switches.
* **Full Topology Hiding:** Strips internal IP addresses, `Via`, `Record-Route`, and `Server` headers to shield internal infrastructure from external reconnaissance.
* **Multi-Master HA Clustering:** Distributed state synchronization across redundant SBC nodes with automatic failover in < 500ms.
---
## 2. Commercial & Operational Value
* **Zero Carrier Telecom Fraud:** Immediate automated rate limiting (Pike module) blocks automated SIP brute-force attempts and toll fraud in under 1 second.
* **Carrier Cost Optimization (LCR):** Prefix-based Least Cost Routing evaluates wholesale rate cards in real time to route outbound calls via the most economical healthy carrier.
* **Unified WebRTC to SIP Gateway:** Bridges browser-based audio/video communications (DTLS-SRTP with Opus) seamlessly to standard G.711/G.729 carrier interconnects.
* **Carrier Interconnection Flexibility:** Supports both IP authentication (ACL whitelist) and digest authentication (HA1/HA1B) with independent capacity limits per trunk.
---
## 3. Core Capabilities & High-Throughput Engine
| Capability | Specification / Implementation |
| :--- | :--- |
| **Max Concurrent Calls (CPS)** | 500+ Call Setups per Second per Node |
| **Simultaneous Media Sessions** | 10,000+ Concurrent RTP Streams with `xt_RTPENGINE` |
| **LCR Route Capacity** | 1,000,000+ E.164 prefix routing entries in memory |
| **Media Transcoding** | Opus, G.711u/a, G.729, G.722, AMR-WB, VP8/H.264 |
| **Security Blacklists** | Real-time ingestion of APIBAN, VoIPBL, and dynamic IP bans |
| **Diagnostic Tracing** | Zero-impact on-demand packet capture with visual ladder diagrams |
---
## 4. SBC Module Documentation Index
### Core Routing Engine
| Module Guide | Primary Function |
| :--- | :--- |
| [**SIP Domains**](routing/domains.md) | Multi-tenant ingress domain mapping, FQDN resolution, and Dispatcher set binding. |
| [**MS Teams Direct Routing**](routing/msteams.md) | Microsoft 365 Direct Routing integration, TLS mutual authentication, and SBC FQDN SANs. |
| [**PBX Endpoints**](routing/endpoints.md) | Telephony Server and Asterisk telephony cluster pools, health heartbeats, and failover sets. |
| [**Carriers & Groups**](routing/carriers.md) | Upstream wholesale gateway pools, IP ACLs, and rate limiting groups. |
| [**Quality Routing (SLA)**](routing/quality.md) | Real-time ASR, ACD, and MOS telemetry-driven closed-loop autonomous rerouting. |
| [**SIP Accounts**](routing/sip-accounts.md) | Wholesale SIP Trunks, IP vs Credential Authentication, HA1 hashes, Channel and CPS limits. |
| [**DIDs & Inbound Routing**](routing/dids.md) | Inbound phone number inventory, E.164 normalization, and automated routing to Ring2All PBX. |
| [**Outbound Routes & LCR**](routing/outbound-routes.md) | Class 4 Least Cost Routing (Drouting), prefix trees, carrier failover, and quality-based routing. |
| [**STIR/SHAKEN Service**](routing/stirshaken.md) | STI-AS cryptographic call signing, PASSporT tokens, STI-VS identity verification, and x5u repos. |
### Perimeter Infrastructure & Security
| Module Guide | Primary Function |
| :--- | :--- |
| [**Dispatcher & Cluster HA**](dispatcher-load-balancing.md) | Load balancing to Ring2All PBX media servers, health check heartbeats (OPTIONS), and failover algorithms. |
| [**RTPEngine Media Relay**](rtpengine-media-relay.md) | Media proxying, symmetric NAT traversal, WebRTC bridging, and real-time MOS quality tracking. |
| [**Perimeter Security & Anti-Fraud**](security-antifraud-pike.md) | Pike flood protection, htable rate limiting, Geo-Firewall, VoIPBL, and APIBAN honeypot feeds. |
| [**AI Perimeter Guard**](ai-perimeter-guard.md) | Real-time SIP packet capture, ladder diagram inspector, and AI-powered diagnostic copilot. |
| [**System & Resource Monitoring**](monitoring-smr.md) | Live CPS dashboard, active dialogs, memory utilization, and administrative RPC terminal (`kamcmd`). |
| [**User & Preferences**](account-menu/README.md) | Dashboard layout customization, administrator profile, theme ergonomics, and system architecture details. |
---
## 5. Network Topology & Security Zones
Ring2All SBC is designed to sit directly across security perimeters:
* **Public Interface (`eth0` / WAN):** Exposes ports UDP/TCP 5060 (SIP), TLS 5061 (SIPS), and UDP 10000β40000 (RTP). Protected by Pike anti-flood and kernel packet filtering.
* **Internal Private Interface (`wg0` / Private VPC):** Interconnects with Ring2All PBX nodes, database clusters, and Billing OCS engines. No external traffic is ever routed into this interface.
* **Management Interface (HTTPS 443):** Protected by JWT, role profiles, and SHA-256 API keys.
---
## 6. Hardware & Sizing Recommendations
| Scale Tier | Concurrent Calls | Target Hardware (Bare Metal / VM) |
| :--- | :--- | :--- |
| **Small / Lab** | Up to 250 calls | 2 vCPU, 4 GB RAM, 20 GB NVMe |
| **Mid Carrier** | 250 β 2,500 calls | 8 vCPU, 16 GB RAM, 100 GB NVMe, 1 Gbps NIC |
| **Tier-1 Carrier** | 2,500 β 15,000 calls | 32 vCPU, 64 GB RAM, 500 GB NVMe, 10 Gbps DPDK/NIC |
---
## 7. Glossary of Carrier Terms
* **CPS (Calls Per Second):** The rate at which new call setups (`INVITE`) are processed by the signalling engine.
* **LCR (Least Cost Routing):** Algorithmic selection of wholesale egress carriers based on rate card cost and quality indicators (ASR/ACD).
* **PDD (Post-Dial Delay):** Time elapsed between sending the final digit of the destination number and receiving ringback tone (`180 Ringing`).
* **Topology Hiding:** Sanitization of internal IP addresses and server headers in outgoing SIP requests to prevent infrastructure mapping.