How to read these guides
Every page follows the same shape. First the mechanism — what problem the protocol exists to solve and how it solves it, because the message flows only make sense once you know what question each message is answering. Then the concrete details: the interfaces, the tables, the timer values, the header names. Last, and deliberately last, what the thing looks like in a capture, because that is where theory either survives contact with the network or does not.
Nothing here is copied from a specification or a vendor manual. Where a standard matters it is named — RFC and 3GPP numbers are the coordinates the industry navigates by — but the text is written from the trace-reader's side of the desk: what you can observe, what you can infer, and which of the moving parts is usually the one lying to you.
hiccup is the working end of these pages: a self-hosted analyser that reads pcaps and SBC logs, pairs the legs across a B2BUA, decodes SIP, RTP, SDP, Diameter, H.323 and SIP-I/ISUP, and tells you where the call went wrong. Free for individual users.
upload a trace