What is an SBC? A Session Border Controller (SBC) terminates SIP sessions at the edge where the enterprise voice network meets the internet, SIP trunks, and cloud services; in practice it is a dedicated SIP security layer for voice traffic. SIP signaling and media are inspected on the SBC; security, compliance, and capacity rules apply before trunks reach the IP PBX or Teams directly.
Nolto positions the SBC layer with the SBC product catalog, AudioCodes brand page, and Microsoft Teams Direct Routing solutions. Complete the switch side with IP PBX or cloud PBX; clarify trunk codec, QoS, and licensing with technical support before the project.
Who needs it and when?
An SBC is not mandatory in every project, but border planning is recommended when:
- Microsoft Teams phone and PSTN: Outbound calling from Teams with corporate numbers (Direct Routing) or carrier trunk connectivity
- SIP trunk and IP PBX: Secure internet connection of carrier lines to IP PBX or cloud PBX
- Multiple carriers and backup trunks: LCR, failover, and trunk load balancing
- Recording and audit: Media proxy, call recording redirection, and topology hiding
- Codec and SIP mismatch: Mixed environments needing transcoding or DTMF normalization
Under heavy trunk load, CPS (calls per second) limits, concurrent sessions, and failover should be part of capacity planning. Example targets (dozens of concurrent calls, dual trunk failover) are calculated with the carrier and PBX capacity at project start; exact numbers depend on the product model.
How does a Session Border Controller work?
SIP registrations and call sessions between internal IP PBX, cloud PBX, or Microsoft Teams and the carrier SIP trunk terminate on the SBC. Internal PBX addresses are hidden (topology hiding); unauthorized registration attempts and abnormal traffic patterns are filtered early. When a trunk fails or the carrier changes, often only the SBC profile is updated, reducing bulk reprovisioning on endpoints.
SBCs deploy as physical appliances, virtualized software, or cloud services. Size concurrent calls (CC), calls per second (CPS), transcoding needs, and high availability (active-passive pairs) together.
Transcoding and protocol normalization
Transcoding reconciles codec differences between two endpoints on the SBC. A carrier trunk may offer G.711 while internal PBX or Teams prefers another codec; the SBC converts media so both sides can talk.
- Codec conversion (e.g., G.711, G.729, Opus)
- DTMF transport alignment (RFC2833, SIP INFO, in-band)
- SIP header and URI normalization
- Session interoperability across PBX and trunk brands
SIP header and URI editing
SIP normalization aligns header and URI formats from different PBX and carrier vendors. From/To, Contact, Route, and Record-Route fields are adjusted per SBC profile so devices behind NAT and multi-domain setups stay stable.
IP PBX and SIP trunk integrations
IP PBX plus SIP trunk is a common outbound model in Turkey. The SBC applies TLS/SRTP encryption, IP allowlists, and bandwidth policy before passing internet trunk sessions to the PBX. On-premises systems such as Yeastar or cloud PBX platforms take trunks through the SBC, reducing NAT traversal and firewall pinhole issues.
- Carrier SIP trunk → SBC → IP PBX flow
- Shared trunk policy between branch and headquarters
- Encrypted signaling (TLS) and media (SRTP) termination
- SIP security filtering at the internet edge
Load balancing and trunk failover
With multiple carrier trunks or geo backup, the SBC defines LCR and failover rules. Sessions can move to a backup profile when a trunk fails. Set per-trunk concurrent session limits on the SBC so CPS limits are not exceeded during campaigns and business hours.
Microsoft Teams Direct Routing and Teams phone
Direct Routing defines use of a certified SBC between Teams Phone System and carrier SIP trunk. SIP from Teams terminates on the SBC; secure egress to the carrier completes PSTN calls. Operator Connect or Calling Plan depends on licensing; Direct Routing offers trunk and number flexibility.
- Teams Phone System license and user assignment
- SBC model on the Microsoft certification list (e.g., AudioCodes families)
- Carrier trunk, number plan, and emergency address registration
- Inbound/outbound test calls and DTMF verification
Validate corporate number plan, user licensing, and emergency address records at project start. Nolto summarizes Direct Routing steps on the Teams solutions page.
Security and SIP border protection
An SBC does not replace a general firewall; it applies rules specific to SIP and RTP. It blocks DoS and SIP scanning at the edge and limits unauthorized registration and toll fraud via policy.
- Topology hiding and SIP border filtering
- TLS/SRTP encryption and certificate management
- DoS/DDoS and abnormal CPS protection
- Codec, DTMF, and SIP header normalization
- Media proxy and call recording redirection
SBC brand portfolio and catalog mapping
Nolto's dealer channel covers two SBC layers: models on the SBC catalog and alternative brands available project-by-project. Use the dealership portal for stock and pricing; for brands not on the catalog, ask technical support for model and lead time.
- AudioCodes: SBC and media gateway families; models on the Microsoft Teams Direct Routing certification list
- FraFos ABC SBC: software SBC for scalable border control in data center and cloud—catalog and project supply
- TE-Systems AnyNode (Anynode): integration layer for Teams, CRM, and third-party SIP apps—project-based
- Patton and Dinstar: gateway / SBC-class devices for branch, SME, and trunk bridge projects—evaluate with VoIP gateway and SBC catalog
- Synway: alternative voice infrastructure portfolio—confirm models via brands and catalog
- Ribbon Communications: enterprise hardware and software SBC for high-capacity trunk scenarios—catalog and project supply
Choose brands based on trunk codec, CPS, Teams certification, and redundancy; alternatives on the list may be suggested when needed.
Nolto service scope
Nolto is not an end-user store; it supplies product, stock, and technical guidance to dealers and integrators. Typical SBC project scope:
- Pre-design: trunk, codec, CPS, and redundancy scenario
- Product and license selection (SBC catalog, AudioCodes)
- Configuration guidance: SIP profile, certificates, firewall, and QoS marking
- Interop testing: inbound/outbound calls, DTMF, recording verification
- Go-live support and dealer channel sales (dealership)
Combine CRM click-to-call and screen pop with integration solutions. For high availability, evaluate active-passive pairs or clustered deployment.
Deployment and model selection
Plan SBC deployment with trunk SIP profile, certificate chain, and firewall rules. Load license keys and firmware per vendor procedure; run test calls before production.
Key selection criteria
Concurrent sessions and CPS, TLS/SRTP support, Teams certification list, transcoding capacity, and licensing model drive the choice. If you plan to scale, align license growth and trunk CPS limits with the carrier early. Questions: technical support; commercial channel: dealership.