Design SIP trunk architectures that connect enterprise PBX, carrier and cloud voice platforms.
Voice over IP Trunking and Session Border Controller Configuration
Configure SIP trunks and session border controllers for secure interconnection, covering codec negotiation, NAT traversal, encryption and call quality control.
Course Overview
A SIP trunk that works perfectly in a lab often breaks the first time it crosses a firewall, meets an unexpected codec, or carries a call through a carrier with different signalling conventions, and the session border controller sitting at that boundary is where most of these problems either get resolved or turned into a dropped call. This course covers SIP trunking design and session border controller configuration from first principles: how signalling and media paths are negotiated, why NAT traversal breaks naive SIP deployments, and how an SBC normalises signalling differences between enterprise PBX, carrier and cloud voice platforms. Participants configure codec negotiation and transcoding policies, set up SRTP and TLS encryption for signalling and media security, and design topology hiding and access control rules that protect the voice network from toll fraud and denial of service. Later sessions address quality of service marking, jitter and packet loss monitoring, and the interoperability testing needed before a new carrier or PBX vendor goes live on the platform.
Expected Learning Outcomes
Configure session border controller signalling and media policies for multi-vendor interoperability.
Resolve NAT traversal issues affecting SIP signalling and RTP media paths.
Configure SRTP and TLS encryption to secure voice signalling and media in transit.
Set topology hiding and access control rules that reduce exposure to toll fraud and denial of service.
Apply quality of service marking and monitor jitter, latency and packet loss on voice traffic.
Plan and execute interoperability testing before onboarding a new carrier or PBX vendor.
Who Should Attend
Voice network engineers responsible for SIP trunk and SBC deployment.
Unified communications administrators managing enterprise PBX platforms.
Carrier interconnection engineers handling wholesale voice traffic.
Network security teams responsible for voice infrastructure protection.
Cloud voice and contact centre platform engineers integrating with SIP trunks.
Telecom operations staff troubleshooting call quality and connectivity issues.
Course Modules
Select any module to see its sessions and points.
01SIP Trunking Architecture and Signalling
2 sessions · 8 points
Session 1SIP Signalling and Media Path Fundamentals
- Trace SIP call setup, media negotiation and teardown across an end-to-end trunk architecture.
- Distinguish signalling plane and media plane behaviour and where each can fail independently.
- Explain SDP offer and answer negotiation and its role in establishing compatible media sessions.
- Map a multi-carrier trunk topology showing failover and least-cost routing decision points.
Session 2Codec Negotiation and Transcoding Policy
- Configure codec preference lists that balance call quality against bandwidth consumption.
- Design transcoding policies for calls between endpoints with no common codec.
- Identify when transcoding introduces unacceptable latency or quality degradation.
- Test codec negotiation behaviour across carrier and PBX combinations before go-live.
02Session Border Controller Configuration
2 sessions · 8 points
Session 1NAT Traversal and Topology Normalisation
- Diagnose NAT traversal failures affecting SIP signalling headers and RTP media addressing.
- Configure far-end and near-end NAT traversal handling on the session border controller.
- Apply topology hiding to prevent internal network addressing from being exposed externally.
- Normalise signalling differences between carrier and enterprise SIP implementations.
Session 2Access Control, Toll Fraud and Denial of Service Protection
- Configure access control lists and trunk group policies that restrict signalling to authorised peers.
- Set call rate limiting and anomaly detection thresholds to catch toll fraud patterns early.
- Apply denial of service protection features to shield signalling and media processing capacity.
- Review SBC logs and alarms to distinguish genuine attacks from misconfigured trunk peers.
03Voice Security and Encryption
2 sessions · 8 points
Session 1TLS Signalling Security Configuration
- Configure TLS for SIP signalling between trunk peers and validate certificate trust chains.
- Plan certificate renewal and rotation without causing signalling outages.
- Troubleshoot TLS handshake failures between SBC and carrier or PBX endpoints.
- Enforce signalling security policies consistently across all configured trunk groups.
Session 2SRTP Media Encryption and Key Management
- Configure SRTP media encryption and key exchange between endpoints and the session border controller.
- Handle interworking between encrypted and unencrypted media legs across mixed trunk configurations.
- Test encrypted call setup end to end to confirm media is not silently falling back to clear text.
- Document encryption requirements in interconnection agreements with carrier and enterprise partners.
04Quality Monitoring and Interoperability Testing
2 sessions · 8 points
Session 1Quality of Service Marking and Performance Monitoring
- Apply quality of service marking to signalling and media traffic across the network path.
- Monitor jitter, latency, packet loss and mean opinion score metrics for active calls.
- Set alerting thresholds that flag quality degradation before customers report dropped calls.
- Correlate quality metrics with network congestion events to identify root causes.
Session 2Carrier and PBX Interoperability Testing
- Design a structured test plan covering call setup, transfer, hold and conferencing scenarios.
- Validate number formatting, caller identity presentation and fax over IP handling per carrier.
- Run failover and load testing before a new trunk group is placed into production.
- Document interoperability findings and configuration profiles for future vendor onboarding.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
