What a session border controller actually does
Short version: an SBC is a B2BUA that sits where trust changes — between your network and a carrier, or between the internet and your core. It terminates every call on one side and re-originates it on the other, which is why one call becomes two legs with two Call-IDs, and why half of all trace-reading is pairing those legs back together.
Proxy versus B2BUA — the distinction everything else hangs on
A SIP proxy forwards requests: it may add a Via and a Record-Route, but the dialog — Call-ID, tags, CSeq — passes through intact, and the two ends genuinely talk to each other. A back-to-back user agent does something more drastic: it answers the caller as if it were the callee, then places a brand-new call to the real callee as if it were the caller. Two dialogs, two Call-IDs, two independent CSeq spaces, joined only by the SBC's internal state. Every serious SBC is a B2BUA, because only a B2BUA can lie about topology, rewrite what it likes, and drop either leg independently. That freedom is the product.
The jobs, one by one
| Job | What it means | Trace fingerprint |
|---|---|---|
| Topology hiding | Inside addresses never appear outside. Via stacks are collapsed, Contact rewritten, Record-Route replaced with the SBC's own. | Every header on the egress leg names the SBC; the ingress network is invisible. |
| NAT traversal / latching | For endpoints behind NAT, the SBC ignores the addresses in SDP and locks onto wherever media actually arrives from. | SDP says one address, RTP flows to/from another, and it works anyway. See NAT traversal. |
| Protocol repair / manipulation | Header manipulation rules (HMR) that fix one vendor's quirks before they reach another: strip a header, rewrite a URI, normalise numbers. | A header present on one leg and absent — or subtly different — on the other. The diff between legs IS the configuration. |
| Admission control | Caps on sessions and call attempts per second, per peer. The overload valve for the whole interconnect. | Bursts of 503 local to the SBC, arriving in milliseconds, with no far-end fingerprints. |
| Encryption boundary | TLS and SRTP on the untrusted side, plain SIP/RTP inside. The SBC holds the keys. | A capture inside shows everything; a capture outside shows TLS on 5061 and SRTP you cannot read. |
| Codec policing / transcoding | Strips codecs a peer must not use; transcodes when the two sides truly share nothing. | The SDP offer shrinks between legs; or both legs answer different codecs and the SBC bridges them. See codecs. |
| Accounting and intercept | CDRs for billing; the media anchor point where lawful intercept can copy content when required. | None, by design. |
Access SBC versus interconnect SBC
The same machine plays two roles. At the access edge it faces thousands of untrusted endpoints: its work is registration handling, NAT latching, protecting the registrar from floods, and being the far end of the customer's encryption. At the interconnect edge it faces a handful of carriers: its work is codec policy, number normalisation, CPS caps and making sure carrier A never learns your topology or carrier B's existence. In IMS the access role is largely what the P-CSCF is, with the IMS-AGW as its media half.
Reading an SBC trace
- Pair the legs first. Nothing else makes sense until ingress and egress are side by side. Call-ID will not match — use time, the To/From users, and SDP contents. (This pairing is exactly what hiccup automates, with a confidence score and an honest AMBIGUOUS state.)
- Diff the two legs. Whatever the SBC changed, it changed on
purpose: a stripped
P-Asserted-Identity, a rewritten Contact, a codec list cut down. Most "the carrier rejects our calls" tickets are one diff line. - Attribute the failure to a side. A 4xx generated by the SBC itself arrives in milliseconds and names no far-end Via; a relayed one took a round trip and carries the peer's fingerprints. The same three digits, two entirely different investigations.
- Remember media walks its own path. The SBC may anchor media or release it; if it anchored, the RTP addresses in SDP are the SBC's own on both sides, and the "far end" in the media capture is always the SBC.
hiccup was built around exactly this: it pairs ingress and egress legs across a B2BUA and emits a structured delta — headers added or stripped, codec lists narrowed, identity fields changed — so the SBC's work is visible instead of inferred. Self-hosted, free for individual users.
upload a trace