Telephony Basics

What is SIP?

SIP (Session Initiation Protocol) is the "language" that phones and PBXs use to talk to each other: it is responsible for setting up a call, ringing, answering, transferring and hanging up. Almost every IP phone, app and cloud PBX today speaks SIP.

Session Initiation ProtocolSIP protocolSIP account

Reading time: about 10 minutes

Phone / appExtension name + passwordThe PBXRegistration (REGISTER)Approved — can dial and receive
SIP registration: the phone identifies itself to the PBX with the extension name and password, and from then on it receives and makes calls

What is SIP

SIP stands for Session Initiation Protocol. "Session" means a call — or more broadly, any meeting between two parties: voice, video or messages. "Initiation" means the start. "Protocol" is an agreed set of rules that all sides know.

SIP does not carry the voice itself — it manages the call. Think of it as a secretary: she finds out who wants to talk to whom, rings, announces that someone answered, and wraps up at the end. The speech itself is carried by another protocol, RTP, over a separate channel.

How a call is set up: four moments

Say Danny, at extension 201, dials extension 305. Behind the scenes a short dialogue of messages takes place, each with a clear name:

  1. INVITE — an invitation. Danny's phone sends the PBX: "I'm 201, I want to talk to 305." Inside the invitation it also attaches a technical description of the voice it can send — which codecs it supports, and to which address to send it the voice.
  2. Ringing. The PBX passes the invitation to 305, and the phone there starts ringing. A "Ringing" message (180 Ringing) returns to Danny, so he hears a ringback tone in the handset.
  3. 200 OK — answered. When 305 picks up, an "OK" message is sent with the chosen codec. Danny confirms (ACK), and from here the voice channel opens, and packets start flowing in both directions.
  4. BYE — hang up. Whoever hangs up first sends BYE, the other side confirms, and the voice channel closes.

Everything else is also SIP messages: a call transfer is a request to connect the other party to someone else, hold is a request to pause the voice, and "busy" is a response (486 Busy) instead of "Ringing." The response numbers resemble those of websites — and not by chance: SIP was built with inspiration from the protocol of the web.

Registration: how the PBX knows where the phone is

To receive calls, every phone must first let the PBX know that it exists. This is called registration (REGISTER): the phone sends the extension name, the PBX asks for proof, and the phone answers using the password — without sending the password itself over the network. Once registration succeeds, the PBX remembers from which address the phone is connected.

Registration is valid for a limited time, so the phone renews it every few minutes. If the phone is turned off or the internet goes down, the registration expires, and the PBX knows there is nowhere to ring — and it triggers whatever was set for that case, for example voicemail or forwarding to a mobile.

This is also what lets the same extension work from the office, from home or from a mobile: it simply registers from wherever it is. And several devices can register to the same extension together, so they all ring.

A bit of history

SIP was developed in the mid-1990s by academic researchers, within the IETF — the body that drafts the standards of the internet. The first official version was published in 1999, and the version still in use today (RFC 3261) was published in 2002.

At the time it had a competitor, H.323, which came from the world of traditional telephony and was more complex. SIP won thanks to its simplicity: its messages are readable text, in the style of internet protocols, and it is easy to develop software for. Today SIP is used not only in PBXs — modern cellular networks also manage voice calls with it.

Why an open standard matters to you

SIP is an open standard: any manufacturer can implement it, without a special license. In practice this means a phone from one manufacturer works with another provider's PBX, and an app on a computer talks to the same PBX as a desk phone.

  • You don't get stuck with equipment. When you change providers, the phones in most cases keep working — you just set them up again.
  • Free choice. You can combine desk phones, cordless phones, conference phones, softphones and adapters for old phones in the same system.
  • Connection to the network. The connection between the PBX and the telephone network — a SIP trunk — speaks the same language too.

Older PBXs usually worked with "proprietary" phones that fit only them. This is one of the reasons that moving away from such a PBX requires replacing the devices as well.

When something doesn't work: three familiar faults

  • The extension is not registered. The phone can't register — because of a wrong password, a disconnected cable or a network that blocks. Without registration, the extension simply doesn't ring.
  • Audio in one direction only. The SIP messages went through and the call opened, but the voice packets can't find their way back. It is almost always a NAT problem or a router that interferes with SIP traffic.
  • The call drops after a fixed time. A disconnect after half a minute or a few minutes, again and again, usually points to a router or firewall that closes the connection midway.

Security: a SIP account is a key

An extension name and password are all it takes to connect to the PBX and dial at your expense. That is why a weak password is a real risk: some people scan the internet constantly, guess passwords, and use a compromised extension to dial expensive destinations abroad. This is called toll fraud.

  • A long, random password for each extension — not 1234 and not the extension number.
  • Don't send login details in WhatsApp groups or in unprotected emails.
  • Check from time to time which devices the extensions are registered from, and delete the extensions of employees who left.

What the phone and the PBX say to each other: registration

SIP messages are text, and are easy to translate into human language. Let's start from the moment a new phone is plugged in at the office:

  • The phone: "Hello, I'm extension 201, and you can reach me at this address on the network. Please register me." (REGISTER)
  • The PBX: "I don't know you yet. Here is a random number — sign it with your password." (401 Unauthorized)
  • The phone: "Here is the same request, and with it a signature made from your number and my password." (REGISTER with a hashed answer — the password itself is not sent)
  • The PBX: "The signature is correct. I've registered you as 201, for the next hour." (200 OK with an expiry time)

From here the phone repeats this exchange every few minutes, before the time runs out. If it doesn't make it — because it was turned off, the cable was pulled, the internet went down — the PBX deletes the registration, and in the control panel the extension shows as "Not registered." This is exactly what you see when a phone "doesn't ring for no reason": it simply didn't manage to register in time.

Three common failures at this stage: the PBX keeps answering "sign" (403 or a repeated 401) — the password is wrong; the phone gets no answer at all — the network is blocking or the PBX address is wrong; and registration succeeds but the calls reach a different device — because someone registered to the same extension from another place, and the control panel shows from which device.

An incoming call from outside: two SIP calls that the PBX joins together

When a customer dials the business number, the PBX does not just "pass" the message to the agent's phone. It stands in the middle and manages two separate SIP calls — one with the network, one with the phone — and connects the voice between them. Here is how it sounds:

  • The network (through the trunk): "There is a call to your number from number 05x. Here are the codecs I know, and here is where to send me voice." (INVITE)
  • The PBX to the network: "Got it, handling it." (100 Trying) — and meanwhile it runs the routing: who is calling, what time it is, which menu. If there is a menu, it answers the network with "answered" and plays the menu itself; the caller presses a key, and the digit arrives as a small event inside the voice channel.
  • The PBX to phone 201: "A call for you, identified as 05x, arriving through the 'Sales' line. Here are my codecs." (a new INVITE, with the caller identification in the From field)
  • The phone: "Ringing." (180 Ringing) — and the PBX translates this to the caller as a ringback tone or queue music.
  • The phone: "I answered. Here is the codec I chose and where to send me voice." (200 OK)
  • The PBX: "Confirmed." (ACK) — and from this moment it passes voice packets between the two sides, or tells them to talk directly.

Understanding that the PBX sits in the middle explains a lot: this is why it can record, listen in, transfer a call and show it on the active calls screen — it is a party to the call, not a pipe. It is also why the caller doesn't see the address of the agent's phone, and doesn't need to know whether the agent is at the office or at home.

If 201 doesn't answer within the set time, the PBX sends it a "cancel" (CANCEL), the phone replies that the call was canceled (487), and the PBX continues along the route — to the next extension, to a queue or to voicemail. The caller doesn't hear any of this.

Call transfer: who says what

The agent at 201 is talking with the customer and wants to transfer him to the accounting department at 204. There are two ways, and both are simple SIP messages.

Attended transfer (the agent talks to 204 first):

  • 201 to the PBX: "Put the customer on hold." (a re-INVITE asking to pause the voice) — the customer hears music played by the PBX.
  • 201 to the PBX: "Open a new call for me to 204." (INVITE) — 204 answers, and the agent tells them who it is about.
  • 201 to the PBX: "Connect the call on hold to this call, and take me out." (REFER, with a reference to the other call)
  • The PBX to 201: "Trying... succeeded." (NOTIFY) — and then "goodbye" (BYE) to extension 201, which drops out of the call.

Blind transfer (without talking to 204 first): 201 sends REFER right away — "Transfer the customer to 204" — and hangs up. The PBX dials 204, and if no one answers there, it triggers whatever is set for extension 204 when there is no answer. The customer does not return to 201, which is why a blind transfer to an extension that may not answer is a common mistake.

In both cases the customer himself receives no new SIP message: from his phone's point of view it is the same call continuing, only the voice reaching him changes. Again — because the PBX sits in the middle and quietly swaps the other party. And in the call log the whole transfer appears as one call with a path: arrived at 201, transferred to 204.

A short glossary of SIP responses

When you look at a phone's log or at an error message, numbers appear. These are the common ones, and what they mean in plain English:

  • 100 Trying — "Got it, handling it." Nothing has happened yet.
  • 180 Ringing — the other side is ringing.
  • 200 OK — success: it was answered, you are registered, or the request was accepted.
  • 401 / 407 — "Identify yourself": a normal step in registration, a problem only if it keeps repeating.
  • 403 Forbidden — authentication failed or the action is not allowed for this extension, for example dialing a blocked destination.
  • 404 Not Found — there is no such extension or number.
  • 486 Busy Here — busy.
  • 487 Request Terminated — the call was canceled before it was answered (the caller hung up, or the ringing timed out).
  • 503 Service Unavailable — the other side is not available: the trunk is down, there is no free channel, or the PBX is overloaded.

Rule of thumb: numbers starting with 1 are "in progress," 2 — success, 4 — a problem on the requesting side (password, destination, permission), 5 — a problem on the answering side. This saves a lot of guessing when reporting a fault.

How it works with us at Kesher

With us, every extension is a SIP account, with a name and a strong password generated by the system. You don't need to invent passwords or remember them — they go into the device settings.

We configure the phones in advance, and the equipment arrives ready to connect: desk phones, cordless phones, conference phones and adapters for old phones. Anyone who works from an app or from software on a computer receives the login details from us.

In the control panel you can see for each extension whether it is registered right now, and from which device. This makes it immediately clear why an extension isn't ringing — the phone is off, disconnected from the network, or someone is connecting from a device you don't recognize.

And for anyone who doesn't want to deal with SIP at all — a SIM extension works on a regular mobile phone, without an app and without data.

FAQ

What is the difference between SIP and VoIP?

VoIP is the general name for carrying voice over the internet. SIP is the protocol that manages the call inside VoIP: who dials whom, ringing, answering, transferring and hanging up.

What is a SIP account?

A username and password that let a device register with the PBX as an extension. Any phone or app that supports SIP can use it.

Why does the phone show that the extension is not registered?

Usually because there is no internet connection, the password is wrong, or the router is blocking the traffic. It's best to check the cable and the network first, and then the login details.

Which port does SIP use?

The common default is 5060, and 5061 for an encrypted connection. The voice itself is carried by other ports, in a separate range.

Can I use any SIP phone with any PBX?

In most cases yes, because SIP is an open standard. Advanced features, such as presence keys, sometimes depend on the settings of the specific model.

What is SIP ALG, and why is it recommended to turn it off?

A feature in home routers that tries to "help" SIP get through NAT, and often garbles the messages along the way: one-way audio, registration that drops. In most cases the PBX handles NAT on its own, and this feature only gets in the way.

What is the difference between SIP and RTP?

SIP sets the terms of the call: who, to whom, which codec, and where to send voice. RTP is the stream of voice packets itself. So it's possible for a call to be "opened" in SIP but you hear nothing — the RTP is blocked.

Back to the Knowledge Center — all terms

Want to hear how it would work for you?

Tell us how your phones work today — how many calls, who answers, what gets in the way — and we'll get back to you with an organized proposal.

Leave your details and we'll get back to you
077-921-9000