try hiccup

SIP, H.323 and Diameter: three protocols, three jobs

Short version: SIP and H.323 compete for the same job — setting up calls — and SIP won everywhere except pockets of installed video and some stubborn interconnects. Diameter was never in that fight: it carries the decisions about calls (who you are, what you may do, who pays), and a modern network runs SIP and Diameter side by side.

The division of labour

SIPH.323Diameter
JobSession signallingSession signalling (the 1996 answer)AAA and policy
LineageIETF — looks like HTTP/email, textITU-T — looks like ISDN, binary ASN.1IETF — RADIUS's successor, binary AVPs
Talks betweenPhones, proxies, SBCs, app serversEndpoints, gatekeepers, gateways, MCUsCore nodes: HSS, MME, CSCFs, PCRF, charging
Media descriptionSDP in the bodyH.245 negotiation (or fast-start terminals)None — but Rx carries SDP-derived facts to policy
Typical transportUDP/TCP/TLS 5060–5061TCP 1720 (+ RAS on UDP 1719)TCP/SCTP 3868

H.323 in one page, honestly

H.323 is an umbrella over several sub-protocols. RAS (H.225.0) is the endpoint-to-gatekeeper channel: register (RRQ/RCF), ask permission to call (ARQ/ACF), bandwidth requests. Call signalling (also H.225.0) is Q.931 dressed for IP: SETUP, CALL PROCEEDING, ALERTING, CONNECT — genuinely the same message names ISDN uses, which is no accident and why telco people found it comfortable. H.245 then negotiates media in exhausting detail: capability sets, master/slave determination, opening logical channels one direction at a time. Classic H.323 needed all of that before audio flowed, which is why fast connect (offering channels inside SETUP) and H.245 tunnelling exist — they are the protocol admitting SDP had the right idea.

A gatekeeper is registrar, admission controller and address resolver in one — roughly what a SIP registrar-plus-proxy does, with the notable difference that endpoints can also call each other directly with no gatekeeper at all. Where you still meet H.323: boardroom video estates that predate their SIP migration, some national carriers' legacy interconnects, and air-traffic and defence systems with twenty-year procurement cycles.

The mapping an IWF has to perform

ConceptSIPH.323
Start a callINVITESETUP
"Working on it"100 TryingCALL PROCEEDING
Ringing180 RingingALERTING
Answer200 OK + ACKCONNECT
Hang upBYERELEASE COMPLETE
Media agreementSDP offer/answerH.245 capability exchange + OLC, or fast connect
Failure detailStatus code + Reason: Q.850ReleaseCompleteReason / Q.931 cause
Call identityCall-ID + tagsCall Reference Value + Conference ID / Call ID GUID

The hard parts of interworking are never the happy path in that table. They are the mismatched state machines around early media (SIP's 183-with-SDP has no clean H.323 twin), mid-call renegotiation (re-INVITE versus new logical channels), and failure semantics — a Q.931 cause has to become a SIP status and something is always lost in translation. An IWF trace therefore deserves suspicion precisely at ring time, answer time and teardown time.

And Diameter stays out of the argument

Neither SIP nor H.323 carries authentication vectors, subscriber profiles, charging or QoS authorisation. In any carrier-grade network those ride Diameter: the phone's identity is checked against the HSS, the call's bearer is authorised over Rx/Gx, the money is counted over Ro/Rf — all invisible to the SIP ladder, all capable of killing the call anyway. When a trace shows flawless signalling and a broken call, the third protocol is usually where the answer lives.

hiccup decodes Q.931/H.225 alongside SIP and stitches interworked calls into a single flow with a confidence score — and an honest AMBIGUOUS verdict instead of a silent wrong guess. Self-hosted, free for individual users.

upload a trace