try hiccup

What a session border controller actually does

Short version: an SBC is a B2BUA that sits where trust changes — between your network and a carrier, or between the internet and your core. It terminates every call on one side and re-originates it on the other, which is why one call becomes two legs with two Call-IDs, and why half of all trace-reading is pairing those legs back together.

Proxy versus B2BUA — the distinction everything else hangs on

A SIP proxy forwards requests: it may add a Via and a Record-Route, but the dialog — Call-ID, tags, CSeq — passes through intact, and the two ends genuinely talk to each other. A back-to-back user agent does something more drastic: it answers the caller as if it were the callee, then places a brand-new call to the real callee as if it were the caller. Two dialogs, two Call-IDs, two independent CSeq spaces, joined only by the SBC's internal state. Every serious SBC is a B2BUA, because only a B2BUA can lie about topology, rewrite what it likes, and drop either leg independently. That freedom is the product.

The jobs, one by one

JobWhat it meansTrace fingerprint
Topology hidingInside addresses never appear outside. Via stacks are collapsed, Contact rewritten, Record-Route replaced with the SBC's own.Every header on the egress leg names the SBC; the ingress network is invisible.
NAT traversal / latchingFor endpoints behind NAT, the SBC ignores the addresses in SDP and locks onto wherever media actually arrives from.SDP says one address, RTP flows to/from another, and it works anyway. See NAT traversal.
Protocol repair / manipulationHeader manipulation rules (HMR) that fix one vendor's quirks before they reach another: strip a header, rewrite a URI, normalise numbers.A header present on one leg and absent — or subtly different — on the other. The diff between legs IS the configuration.
Admission controlCaps on sessions and call attempts per second, per peer. The overload valve for the whole interconnect.Bursts of 503 local to the SBC, arriving in milliseconds, with no far-end fingerprints.
Encryption boundaryTLS and SRTP on the untrusted side, plain SIP/RTP inside. The SBC holds the keys.A capture inside shows everything; a capture outside shows TLS on 5061 and SRTP you cannot read.
Codec policing / transcodingStrips codecs a peer must not use; transcodes when the two sides truly share nothing.The SDP offer shrinks between legs; or both legs answer different codecs and the SBC bridges them. See codecs.
Accounting and interceptCDRs for billing; the media anchor point where lawful intercept can copy content when required.None, by design.

Access SBC versus interconnect SBC

The same machine plays two roles. At the access edge it faces thousands of untrusted endpoints: its work is registration handling, NAT latching, protecting the registrar from floods, and being the far end of the customer's encryption. At the interconnect edge it faces a handful of carriers: its work is codec policy, number normalisation, CPS caps and making sure carrier A never learns your topology or carrier B's existence. In IMS the access role is largely what the P-CSCF is, with the IMS-AGW as its media half.

Reading an SBC trace

  1. Pair the legs first. Nothing else makes sense until ingress and egress are side by side. Call-ID will not match — use time, the To/From users, and SDP contents. (This pairing is exactly what hiccup automates, with a confidence score and an honest AMBIGUOUS state.)
  2. Diff the two legs. Whatever the SBC changed, it changed on purpose: a stripped P-Asserted-Identity, a rewritten Contact, a codec list cut down. Most "the carrier rejects our calls" tickets are one diff line.
  3. Attribute the failure to a side. A 4xx generated by the SBC itself arrives in milliseconds and names no far-end Via; a relayed one took a round trip and carries the peer's fingerprints. The same three digits, two entirely different investigations.
  4. Remember media walks its own path. The SBC may anchor media or release it; if it anchored, the RTP addresses in SDP are the SBC's own on both sides, and the "far end" in the media capture is always the SBC.

hiccup was built around exactly this: it pairs ingress and egress legs across a B2BUA and emits a structured delta — headers added or stripped, codec lists narrowed, identity fields changed — so the SBC's work is visible instead of inferred. Self-hosted, free for individual users.

upload a trace