try hiccup

SS7 and ISUP: the phone network SIP had to interwork with

Short version: SS7 is a closed packet network that carries the control plane of classical telephony; ISUP is its call-control protocol, and it maps onto SIP almost message for message. You still care because the PSTN edge of every SIP network speaks it, its cause codes surface inside your SIP as Q.850, and SIP-I traces carry raw ISUP in the message bodies.

The stack, briefly

SS7 separated signalling from voice: the talk path lives on 64 kbit/s trunk circuits, while call control travels a parallel data network of its own. MTP levels 1–3 are that network — links, reliability, and routing between nodes named by point codes. On top: ISUP for trunk call control, and SCCP + TCAP for transaction services — number translation, and the dialogues that mobile networks (MAP: location updates, SMS, roaming) and intelligent-network services (INAP/CAP: prepaid, freephone) run on. The nodes: SSPs (exchanges), STPs (signalling routers), SCPs (service databases). When SS7 is carried over IP rather than TDM links, the SIGTRAN family (M3UA over SCTP) replaces the lower layers and everything above continues unchanged.

An ISUP call, against its SIP twin

ISUP controls circuits: each trunk between two exchanges is a numbered CIC (circuit identification code), and the messages seize, ring, answer and release that circuit.

ISUPMeaningSIP equivalent
IAM — Initial Address MessageSeize a circuit; carries called/calling number, nature of address, charge indicatorsINVITE
ACM — Address CompleteFar end has the full number and is proceeding; often "subscriber free" = ringing180 Ringing (or 183, when ACM says in-band info follows)
CPG — Call ProgressMid-setup progress events (forwarding, queueing)Additional 18x provisionals
ANM — AnswerAnswered; billing starts200 OK
REL — ReleaseTear the call down, with a Q.850 cause valueBYE (or a 4xx/5xx, if before answer)
RLC — Release CompleteCircuit is free again200 to the BYE

The asymmetries are where interworking gets interesting. ISUP has no ACK — answer is one message, not three. Early media is implicit (the voice circuit exists from seizure, so ringback simply plays down it) where SIP needs 183-with-SDP and P-Early-Media to say the same thing. A REL always carries a numeric cause; a SIP failure sometimes has to invent one, which is exactly what the Reason: header carries back. And ISUP worries about things SIP never had to: continuity tests on the voice path (COT), and glare — both ends seizing the same circuit at once, resolved by point-code arithmetic rather than luck.

SIP-I: ISUP riding inside SIP

When two TDM islands connect across a SIP core, the border gateways use SIP-I (ITU-T Q.1912.5; SIP-T is the IETF's earlier take): the SIP messages carry a multipart body with the original ISUP message embedded, Content-Type: application/ISUP. SIP does the routing; the far gateway re-emits the ISUP so nothing telco-specific is lost in translation. For the trace reader this is a gift — the INVITE contains the actual IAM, so the calling-party category, charge indicators and original cause values are right there if your tool decodes them. hiccup does.

Where you still meet all this

Reading it in a trace

  1. On a SIP-I trunk, open the multipart body: compare the ISUP IAM's called number with the SIP Request-URI — mismatches (prefix handling, nature-of-address confusion) are the number-format ticket generator.
  2. On teardown, trust the ISUP cause over the SIP status when both are present: the cause travelled from the far exchange; the status may have been improvised at the border. The mapping table lives on the Q.850 page.
  3. A gateway answering everything with 503 while its peers are fine is often a circuit-group problem underneath (blocked CICs, a failed COT), invisible unless you can see the ISUP side.

hiccup decodes SIP-I: the ISUP messages inside your SIP bodies are parsed and lined up with the SIP ladder, causes and all. Self-hosted, free for individual users.

upload a trace