What Is SIP?
SIP is the signaling protocol that starts and manages voice/video sessions; media is defined with SDP and usually carried over RTP.
SIP (Session Initiation Protocol) is an application-layer signaling protocol used to set up, modify, and tear down interactive sessions over IP—voice, video, instant messaging. It is an IETF standard and the most common call control method in enterprise VoIP and IP PBX environments. SIP does not carry audio by itself: it carries session parameters (codec, IP, port) via SDP (Session Description Protocol); the actual media stream usually runs on RTP / SRTP. A text-based message structure similar to HTTP (methods, headers, URI) makes diagnosis and log reading easier.
SIP signaling, SDP/RTP separation, and enterprise use
Typical call flow: endpoint registers with the registrar via REGISTER; INVITE offers a session; 180/183 and 200 OK progress; ACK confirms; BYE closes. Proxy and B2BUA roles differ: a proxy forwards; a B2BUA (most PBXs) terminates the session between two legs. Transport may be UDP (low latency) or TCP/TLS (reliability and encryption); in production, TLS + SRTP policy depends on operator and security requirements. Behind NAT, private IPs in SDP are not reachable from outside; without STUN/TURN, far-end NAT, or an SBC, one-way audio and broken recording are common.
- SIP: who is calling, where to, which status code (1xx–6xx)
- SDP: which codec, which RTP port, which IP
- RTP/SRTP: voice/video packet flow
- RTCP: quality and loss statistics (when supported)
Common methods, response codes, and security
INVITE, ACK, BYE, CANCEL, REGISTER, OPTIONS, and REFER are the most common in daily operations. 401/407 mean authentication; 408 timeout; 486 busy; 503 service unavailable—they should be read together in trunk and endpoint logs. Basic security: Digest (MD5/SHA) authentication, IP allowlists, rate limits, and brute-force protection. TLS encrypts signaling; SRTP encrypts media. S/MIME or end-to-end encryption scenarios are rarer. Consumer routers with SIP ALG can break packets; at the enterprise edge, disable ALG and prefer SBC or correct NAT traversal.
Codec, trunk, and diagnostic notes
G.711 offers high compatibility and bandwidth; G.729 / Opus save bandwidth or improve compression—the choice is made at PBX, trunk, and endpoint intersection. On SIP trunk, CLI, emergency routing, and codec list should be clear in the contract. In diagnosis, check INVITE–200–ACK chain and SDP c= / m= lines with Wireshark or PBX SIP trace; “no audio” is often RTP path breakage (NAT, firewall, wrong IP) independent of signaling. OPTIONS keepalive and REGISTER expiry aligned with operator policy matter for long-lived registration.
Enterprise reminders
Via and Record-Route headers in a proxy chain determine routing; a wrongly added Record-Route can break the return path. Dial plan or PBX rules independent of SIP (hours, queue, class of service) apply after the session—separate protocol layer from business rules. Summary: SIP sets up and manages the session; good voice needs SDP/RTP, network edge, and codec policy designed together.