Diameter: the protocol that runs VoLTE's back office
Short version: SIP decides what a call wants; Diameter decides whether the network will let it happen and who pays. Authentication, subscriber lookup, policy, charging and the voice bearer itself all ride on Diameter — which is why a VoLTE call can die without a single SIP message ever looking wrong.
Where it came from
Diameter (RFC 6733, originally RFC 3588 — the name is a dry joke: twice RADIUS) was built to replace RADIUS for authentication, authorisation and accounting. It fixed the things that made RADIUS unfit for a carrier core: it runs over TCP or SCTP (port 3868) instead of fire-and-forget UDP, every request gets an answer, peers monitor each other with watchdogs, failover is defined rather than improvised, and the message format extends cleanly. 3GPP then adopted it as the control-plane glue of LTE and IMS, which is where nearly everyone meets it today.
The building blocks
- AVPs. Every message is a header plus a list of attribute-value pairs — typed, numbered, nestable. Vendor-specific AVPs (3GPP's live under vendor id 10415) extend the protocol without breaking anyone who ignores them.
- Commands. Messages come in request/answer pairs sharing a command code: CER/CEA to open a peering (capabilities exchange), DWR/DWA as the watchdog heartbeat, and per-application codes like UAR/UAA or CCR/CCA.
- Applications. An application id names the dialect: Cx is one application, Gx another, S6a another. Peers advertise at CER time which applications they speak, and a message for an unsupported application is refused outright.
- Sessions. A
Session-IdAVP correlates the messages of one logical transaction — the equivalent of SIP's Call-ID, and the key you group by when reading a capture. - Routing. Requests carry Origin-Host/Origin-Realm and Destination-Realm (sometimes Destination-Host). Diameter Routing Agents (DRAs) relay on realm the way SIP proxies route on domain; the hop-by-hop id is rewritten per hop while the end-to-end id survives, which is exactly how you match a request to its answer across a relay.
The interfaces that matter for voice
| Interface | Between | What it decides |
|---|---|---|
| S6a | MME ↔ HSS | Can this device attach to LTE at all, and with what subscription data. Fails here and the phone has no data, never mind voice. |
| Cx / Dx | I/S-CSCF ↔ HSS (SLF) | IMS registration: does the user exist, which S-CSCF serves them, and the AKA vectors to authenticate them. |
| Sh | Application server ↔ HSS | Service data for supplementary services — where the TAS reads and writes forwarding rules and the like. |
| Rx | P-CSCF ↔ PCRF | The voice bearer trigger: the P-CSCF describes the media from the SDP, the policy function decides whether a dedicated bearer gets built. |
| Gx | PCRF ↔ PGW | The enforcement half of Rx: policy rules pushed down so the packet core actually installs the bearer and its QoS. |
| Ro / Rf (Gy) | Network ↔ charging | Online (credit-checked, can refuse mid-call) and offline (records after the fact) charging. |
Reading a Diameter capture
Diameter is binary, so you read it with a decoder rather than your eyes — but the
questions are always the same three. Did the request reach the right place?
Follow Destination-Realm and watch a DRA rewrite hop-by-hop ids.
What did the answer say? Result-Code 2001 is DIAMETER_SUCCESS;
3xxx codes are routing/protocol failures (3002 UNABLE_TO_DELIVER is the classic
"nobody peers with that realm"), 4xxx are transient, 5xxx are permanent refusals —
and 3GPP applications often put the truth in Experimental-Result-Code
instead, e.g. 5001 USER_UNKNOWN from an HSS. Did it answer at all? Watchdog
DWR/DWA pairs tell you whether the peering itself was alive.
What Diameter failure looks like from the SIP side
- REGISTER answered 504 or hanging: Cx not answering — HSS or DRA down, or realm routing broken.
- REGISTER answered 403/404 for a subscriber who should exist: Cx answered, but with USER_UNKNOWN or a profile mismatch — a provisioning fault wearing a SIP costume.
- Call signalling perfect, then the call drops at answer or has one-way audio: Rx/Gx failed, the dedicated bearer never got built, and the media had nothing to ride on.
- Calls refused mid-dialog with policy-flavoured reasons: online charging (Ro) said no — an empty prepaid balance shows up here, not in the HSS.
hiccup decodes the Diameter it finds alongside your SIP — Cx, Rx and friends — so "the SIP looks fine" and "the Result-Code was 5001" can sit in the same timeline. Self-hosted, free for individual users.
upload a trace