Skip to content

Ring2All SBC (Session Border Controller) Documentation

6 min readUpdated: Sep 26, 2026
View as Markdown

Official Slogan: “High-Throughput Perimeter SIP Engine & Carrier LCR”
Brand Identity: Emerald / Cyan (#10B981) • Icon: shield • Component Code: sbc

Welcome to the comprehensive technical and operational documentation for Ring2All SBC, the perimeter Class 4 Session Border Controller and SIP routing engine of the Ring2All carrier-grade communications suite.


  1. Platform Overview & Architecture
  2. Commercial & Operational Value
  3. Core Capabilities & High-Throughput Engine
  4. SBC Module Documentation Index
  5. Network Topology & Security Zones
  6. Hardware & Sizing Recommendations
  7. Glossary of Carrier Terms

1. Platform Overview & ArchitectuRing2All SBC serves as the hardened perimeter gatekeeper and carrier interconnection core for all inbound and outbound SIP traffic. Built upon Kamailio 6.1+, RTPEngine 12.5+ (with kernel-space xt_RTPENGINE packet forwarding), and a responsive Fastify/React administrative suite, it separates untrusted public networks and wholesale carriers from internal application servers (Ring2All PBX) and financial systems (Ring2All Billing).

Section titled “1. Platform Overview & ArchitectuRing2All SBC serves as the hardened perimeter gatekeeper and carrier interconnection core for all inbound and outbound SIP traffic. Built upon Kamailio 6.1+, RTPEngine 12.5+ (with kernel-space xt_RTPENGINE packet forwarding), and a responsive Fastify/React administrative suite, it separates untrusted public networks and wholesale carriers from internal application servers (Ring2All PBX) and financial systems (Ring2All Billing).”
flowchart TD
    subgraph Untrusted["🌐 Untrusted Public Perimeter"]
        Carriers["Wholesale PSTN Carriers"]
        RemoteTrunks["Remote SIP Trunks"]
        WebRTC["WebRTC Browser Clients"]
    end

    subgraph SBC["🛡️ Ring2All SBC (Class 4 Perimeter Gatekeeper)"]
        direction TB
        Kamailio["⚡ Kamailio 6.1+ Signalling Engine<br/>• Pike Anti-Flood & Rate Limiting<br/>• Drouting LCR Engine<br/>• Dispatcher Load Balancing<br/>• Topology Hiding"]
        RTPEngine["🎧 RTPEngine 12.5+ Media Relay<br/>• xt_RTPENGINE Kernel Forwarding<br/>• WebRTC DTLS-SRTP Gateway<br/>• Symmetric NAT Traversal<br/>• MOS / QoS Analytics"]
        ControlPlane["🎛️ Control Plane (Fastify 5 REST API)<br/>• AI Perimeter Guard<br/>• Whitelist/Blacklist Sync<br/>• Live SIP Ladders"]
        
        Kamailio <--> RTPEngine
        Kamailio --> ControlPlane
    end

    subgraph InternalCore["🏢 Protected Core Zone (WireGuard / VPC)"]
        PBX["⚙️ Ring2All PBX Engine (Class 5 Core)"]
        BSS["💳 Ring2All BSS (Billing OCS & Accounting)"]
    end

    Carriers -->|"SIP 5060/5061"| Kamailio
    RemoteTrunks -->|"SIP 5060/5061"| Kamailio
    WebRTC -->|"WSS / DTLS"| Kamailio

    Carriers <.->|"RTP 10000-40000"| RTPEngine
    RemoteTrunks <.->|"RTP 10000-40000"| RTPEngine
    WebRTC <.->|"SRTP / Opus"| RTPEngine

    Kamailio -->|"Internal SIP Trunk"| PBX
    Kamailio -->|"Real-time CDR / Fraud Events"| BSS

Key Architectural Characteristics��────┘

Section titled “Key Architectural Characteristics��────┘”
│
Internal WireGuard Tunnel / VPC
│

┌───────────────────────────────────▼────────────────────────────────────┐ │ INTERNAL CORE APPS ZONE │ │ Ring2All PBX (Class 5 Core) │ Ring2All Billing (BSS/OSS & OCS) │ └──────────────────────────────────┴─────────────────────────────────────┘

### Key Architectural Characteristics
* **Sub-Millisecond Signalling Latency:** In-memory caching (`shm`) for LCR routing tables, IP access control lists, and dispatcher server lists.
* **Kernel-Space Media Processing:** Through `xt_RTPENGINE` iptables integration, media packets are relayed directly within Linux kernel space, bypassing user-space context switches.
* **Full Topology Hiding:** Strips internal IP addresses, `Via`, `Record-Route`, and `Server` headers to shield internal infrastructure from external reconnaissance.
* **Multi-Master HA Clustering:** Distributed state synchronization across redundant SBC nodes with automatic failover in < 500ms.
---
## 2. Commercial & Operational Value
* **Zero Carrier Telecom Fraud:** Immediate automated rate limiting (Pike module) blocks automated SIP brute-force attempts and toll fraud in under 1 second.
* **Carrier Cost Optimization (LCR):** Prefix-based Least Cost Routing evaluates wholesale rate cards in real time to route outbound calls via the most economical healthy carrier.
* **Unified WebRTC to SIP Gateway:** Bridges browser-based audio/video communications (DTLS-SRTP with Opus) seamlessly to standard G.711/G.729 carrier interconnects.
* **Carrier Interconnection Flexibility:** Supports both IP authentication (ACL whitelist) and digest authentication (HA1/HA1B) with independent capacity limits per trunk.
---
## 3. Core Capabilities & High-Throughput Engine
| Capability | Specification / Implementation |
| :--- | :--- |
| **Max Concurrent Calls (CPS)** | 500+ Call Setups per Second per Node |
| **Simultaneous Media Sessions** | 10,000+ Concurrent RTP Streams with `xt_RTPENGINE` |
| **LCR Route Capacity** | 1,000,000+ E.164 prefix routing entries in memory |
| **Media Transcoding** | Opus, G.711u/a, G.729, G.722, AMR-WB, VP8/H.264 |
| **Security Blacklists** | Real-time ingestion of APIBAN, VoIPBL, and dynamic IP bans |
| **Diagnostic Tracing** | Zero-impact on-demand packet capture with visual ladder diagrams |
---
## 4. SBC Module Documentation Index
### Core Routing Engine
| Module Guide | Primary Function |
| :--- | :--- |
| [**SIP Domains**](routing/domains.md) | Multi-tenant ingress domain mapping, FQDN resolution, and Dispatcher set binding. |
| [**MS Teams Direct Routing**](routing/msteams.md) | Microsoft 365 Direct Routing integration, TLS mutual authentication, and SBC FQDN SANs. |
| [**PBX Endpoints**](routing/endpoints.md) | Telephony Server and Asterisk telephony cluster pools, health heartbeats, and failover sets. |
| [**Carriers & Groups**](routing/carriers.md) | Upstream wholesale gateway pools, IP ACLs, and rate limiting groups. |
| [**Quality Routing (SLA)**](routing/quality.md) | Real-time ASR, ACD, and MOS telemetry-driven closed-loop autonomous rerouting. |
| [**SIP Accounts**](routing/sip-accounts.md) | Wholesale SIP Trunks, IP vs Credential Authentication, HA1 hashes, Channel and CPS limits. |
| [**DIDs & Inbound Routing**](routing/dids.md) | Inbound phone number inventory, E.164 normalization, and automated routing to Ring2All PBX. |
| [**Outbound Routes & LCR**](routing/outbound-routes.md) | Class 4 Least Cost Routing (Drouting), prefix trees, carrier failover, and quality-based routing. |
| [**STIR/SHAKEN Service**](routing/stirshaken.md) | STI-AS cryptographic call signing, PASSporT tokens, STI-VS identity verification, and x5u repos. |
### Perimeter Infrastructure & Security
| Module Guide | Primary Function |
| :--- | :--- |
| [**Dispatcher & Cluster HA**](dispatcher-load-balancing.md) | Load balancing to Ring2All PBX media servers, health check heartbeats (OPTIONS), and failover algorithms. |
| [**RTPEngine Media Relay**](rtpengine-media-relay.md) | Media proxying, symmetric NAT traversal, WebRTC bridging, and real-time MOS quality tracking. |
| [**Perimeter Security & Anti-Fraud**](security-antifraud-pike.md) | Pike flood protection, htable rate limiting, Geo-Firewall, VoIPBL, and APIBAN honeypot feeds. |
| [**AI Perimeter Guard**](ai-perimeter-guard.md) | Real-time SIP packet capture, ladder diagram inspector, and AI-powered diagnostic copilot. |
| [**System & Resource Monitoring**](monitoring-smr.md) | Live CPS dashboard, active dialogs, memory utilization, and administrative RPC terminal (`kamcmd`). |
| [**User & Preferences**](account-menu/README.md) | Dashboard layout customization, administrator profile, theme ergonomics, and system architecture details. |
---
## 5. Network Topology & Security Zones
Ring2All SBC is designed to sit directly across security perimeters:
* **Public Interface (`eth0` / WAN):** Exposes ports UDP/TCP 5060 (SIP), TLS 5061 (SIPS), and UDP 10000–40000 (RTP). Protected by Pike anti-flood and kernel packet filtering.
* **Internal Private Interface (`wg0` / Private VPC):** Interconnects with Ring2All PBX nodes, database clusters, and Billing OCS engines. No external traffic is ever routed into this interface.
* **Management Interface (HTTPS 443):** Protected by JWT, role profiles, and SHA-256 API keys.
---
## 6. Hardware & Sizing Recommendations
| Scale Tier | Concurrent Calls | Target Hardware (Bare Metal / VM) |
| :--- | :--- | :--- |
| **Small / Lab** | Up to 250 calls | 2 vCPU, 4 GB RAM, 20 GB NVMe |
| **Mid Carrier** | 250 – 2,500 calls | 8 vCPU, 16 GB RAM, 100 GB NVMe, 1 Gbps NIC |
| **Tier-1 Carrier** | 2,500 – 15,000 calls | 32 vCPU, 64 GB RAM, 500 GB NVMe, 10 Gbps DPDK/NIC |
---
## 7. Glossary of Carrier Terms
* **CPS (Calls Per Second):** The rate at which new call setups (`INVITE`) are processed by the signalling engine.
* **LCR (Least Cost Routing):** Algorithmic selection of wholesale egress carriers based on rate card cost and quality indicators (ASR/ACD).
* **PDD (Post-Dial Delay):** Time elapsed between sending the final digit of the destination number and receiving ringback tone (`180 Ringing`).
* **Topology Hiding:** Sanitization of internal IP addresses and server headers in outgoing SIP requests to prevent infrastructure mapping.