Skip to content
Infrastructure & Technical 10 min read

VoIP Routing Protocols: How SIP, RTP & Packet Routing Work Under the Hood

VoIP protocol stack diagram showing SIP/SDP signaling layer and RTP/RTCP media layer with TLS and SRTP encryption wrappers on a dark teal background

VoIP uses a layered set of protocols: SIP (Session Initiation Protocol) handles call setup and teardown; SDP (Session Description Protocol) negotiates media parameters within SIP messages; RTP (Real-time Transport Protocol) carries the actual audio. TLS encrypts SIP signaling; SRTP encrypts RTP media. Understanding how these interact explains most VoIP troubleshooting patterns.

How a VoIP call works — the 7-step sequence

  1. DNS SRV/NAPTR lookup: caller's device resolves the SIP server address (RFC 3263 — DNS SRV for transport discovery).
  2. SIP INVITE: caller sends INVITE to SIP server containing SDP offer (proposed codecs, media IP:port).
  3. SIP 100 Trying: server acknowledges receipt, begins routing.
  4. SIP 180 Ringing: destination is alerting (you hear ringback generated locally or remotely).
  5. SIP 200 OK: destination answers; contains SDP answer (accepted codec, destination media IP:port).
  6. SIP ACK: caller confirms; RTP media stream begins between the two media IP:port addresses in SDP.
  7. Call in progress: RTP carries audio; RTCP carries quality stats; SIP dialog remains open until BYE.

SIP — Session Initiation Protocol (RFC 3261)

Text-based signaling protocol (like HTTP for calls).

Request methods: INVITE (new call), ACK (confirm), BYE (end call), CANCEL (cancel in-progress call), REGISTER (register endpoint), OPTIONS (probe/capability check).

Response codes: 1xx Provisional, 2xx Success, 3xx Redirect, 4xx Client error (401 Auth, 403 Forbidden, 404 Not Found), 5xx Server error (503 Unavailable), 6xx Global failure.

SIP URI format: sip:user@domain or sips:user@domain (TLS).

See SIP response codes for a complete code reference.

SDP — Session Description Protocol (RFC 4566)

Not a standalone protocol — carried inside SIP messages (in INVITE and 200 OK bodies).

Negotiates: codec list (in order of preference), media IP address, RTP port, other parameters.

Offer/answer model: caller proposes in INVITE SDP offer; callee selects one codec and responds in 200 OK SDP answer; codec negotiation is complete.

Why it matters for troubleshooting: codec mismatch (both sides in different codecs) produces robotic audio; wrong media IP in SDP produces one-way audio.

RTP — Real-time Transport Protocol (RFC 3550)

Carries audio (and video) packets over UDP.

Packet structure: sequence number (detects loss and reordering), timestamp (enables jitter buffer synchronization), SSRC (identifies the media stream).

Jitter buffer: compensates for variable packet arrival time by buffering and reordering packets before playback; too small → gaps/choppy; too large → added latency.

Why UDP not TCP: TCP retransmits lost packets, adding latency that makes voice unintelligible; lost UDP packets produce brief audio artifacts (less damaging than retransmit delay).

RTCP — RTP Control Protocol (RFC 3550)

Companion to RTP; shares same port (typically RTP port +1).

Reports: packet loss rate, jitter, round-trip time, SSRC mapping.

Used for: real-time quality monitoring, MOS estimation, diagnosing one-way audio (if RTCP from one side is absent, that side's media isn't arriving).

TLS and SRTP — encrypting VoIP

  • TLS (Transport Layer Security): encrypts SIP signaling; uses TCP (SIP/TLS); standard for enterprise UCaaS; URI prefix sips:.
  • SRTP (Secure RTP, RFC 3711): encrypts RTP media; session keys exchanged via SDP or DTLS-SRTP; prevents eavesdropping on the audio stream.
  • SIP over TLS + SRTP = encrypted signaling AND encrypted media; both required for truly private calls.
  • SIP over TLS without SRTP: signaling is encrypted but audio is still in cleartext RTP.

UDP vs TCP for SIP

  • UDP: connectionless, lower overhead, standard for SIP; packets can be lost; suitable for LAN/controlled environments.
  • TCP: connection-oriented, reliable delivery, required for large SIP messages (TCP path MTU vs UDP); used for SIP over TLS (SIP/TLS must use TCP or TLS over TCP).
  • UDP SIP reliability issue: large SIP messages (with many SDP attributes or long header lists) can exceed 1500-byte path MTU; fragments may be lost, causing INVITE failure — fix is to use TCP or reduce SDP size.

DNS SRV and NAPTR (RFC 3263)

SIP clients use DNS SRV records to discover SIP servers and preferred transports.

  • SRV records: _sip._tcp.domain → TCP SIP server; _sip._udp.domain → UDP SIP server; _sips._tcp.domain → TLS.
  • NAPTR records: priority-ordered list of services; SIP clients query NAPTR first, then SRV.
  • Why it matters: SIP trunk providers specify SBC hostnames; client resolves via SRV; if SRV is missing or returns wrong records, registration fails; use dig SRV _sip._udp.provider.com to verify.

SIP infrastructure components

  • SIP Proxy: routes SIP messages; doesn't maintain dialog state.
  • SIP Registrar: accepts REGISTER messages; maps SIP URI → current contact address (IP:port).
  • SIP B2BUA (Back-to-Back User Agent): terminates one SIP dialog and originates another; maintains full call state; most SBCs are B2BUAs.
  • SBC (Session Border Controller): sits at network edge; provides NAT traversal, security (SIP normalization, IP ACL), topology hiding, transcoding, and recording integration.

Common protocol-level problems

Symptom Protocol layer Likely cause
Call drops at 30s SIP ACK not received — NAT/firewall blocking response
One-way audio SDP/RTP Wrong media IP in SDP, SIP ALG rewrote it
Registration fails with 401 SIP Auth challenge — wrong credentials
No audio (both directions) RTP RTP ports blocked; media proxy misconfigured
Codec mismatch (robotic) SDP SDP answer selected incompatible codec
Call fails with 503 SIP Provider SBC down or unreachable

Frequently asked questions

What is the difference between SIP and VoIP? +
VoIP (Voice over IP) is the general category: any voice communication carried over IP networks. SIP is one specific protocol used for call setup and teardown in VoIP systems. Most business VoIP systems use SIP for signaling because it is the industry standard, but VoIP can also use proprietary protocols (Cisco SCCP, H.323, WebRTC). When people say "SIP trunk" they mean a VoIP connection that uses SIP signaling specifically.
Why does VoIP use UDP instead of TCP? +
RTP audio streams use UDP because voice communication requires low latency, not guaranteed delivery. If a TCP packet is lost and retransmitted, the retransmission arrives too late to be useful for real-time audio — it would just cause a brief gap in audio playback but arrive after the audio moment it belongs to. UDP packets that are lost simply produce a brief audio artifact; the stream continues without waiting for retransmission. SIP signaling can use either UDP or TCP; TCP is preferred for encrypted SIP (TLS).
What is a codec and how does it affect call quality? +
A codec (coder-decoder) compresses audio for transmission and decompresses it for playback. G.711 (PCM) is the highest quality standard codec, using ~64 kbps per call; it is the basis for MOS score reference quality. G.729 uses ~8 kbps (8:1 compression) but introduces audible artifacts at high compression. Opus is modern and adaptive, supporting 6–510 kbps with good quality at low bitrates. Codec selection is negotiated via SDP; a mismatch (where both sides select different codecs) produces garbled or robotic audio and is a common misconfiguration symptom.
What does it mean when a call "times out" in SIP? +
SIP dialogs have timers. A SIP INVITE that receives no response within Timer B (32 seconds by default) times out — the caller hangs up and retries or returns an error. In-progress calls have session timers (RFC 4028): both sides send re-INVITEs periodically to confirm the call is still active; if re-INVITEs stop, the call is terminated. A call "timing out" mid-call usually means session timer re-INVITEs are failing, often because the SIP dialog path has changed (transfer, NAT rebinding) and the re-INVITE can no longer reach the destination.
How does encryption work in a SIP call? +
Signaling encryption: SIP messages travel inside a TLS session (port 5061), so an eavesdropper between the client and server cannot read the SIP headers, dial strings, or session parameters. Media encryption: RTP streams are wrapped in SRTP, which encrypts the audio payload using AES. The SRTP session key is exchanged via SDES (inside SDP) or DTLS-SRTP (in WebRTC). Without SRTP, even with TLS on SIP, the audio stream is unencrypted and could be intercepted at any network hop between the endpoints.
What is the difference between a SIP proxy and an SBC? +
A SIP proxy routes SIP messages based on the Request-URI and record-route headers; it does not terminate sessions, meaning both legs of a call pass through it but it doesn't maintain full call state. An SBC (Session Border Controller) is a B2BUA: it terminates the inbound SIP dialog and originates a new outbound one, maintaining full state for both legs. This allows the SBC to perform security filtering (block malformed SIP, IP ACL), topology hiding (replace internal IP addresses with public IP), SIP normalization (fix vendor-specific SIP incompatibilities), RTP anchoring (ensure media flows through the SBC for recording/monitoring), and transcoding.

Related Articles

SIP Trunking

SIP Trunking

Read article →

Troubleshooting

SIP Response Codes

Read article →

Troubleshooting

One-Way Audio

Read article →

Call Quality

VoIP Call Quality

Read article →

Troubleshooting

UCaaS Troubleshooting

Read article →

Related articles

UCaaS & Business Phone

VoIP for Law Firms: Phone System Features and Buyer Guide

Law firms use VoIP as the communication layer for incoming client calls, attorney direct lines, practice-area routing, after-hours handling, and remote attorney access. This guide covers the features to evaluate, call recording considerations, confidentiality questions, and a provider evaluation checklist.

CCaaS & Contact Center

Financial Services Contact Centers: Technology & Buyer Guide

Financial services contact centers manage customer service calls, application inquiries, dispute handling, outbound campaigns, and after-hours routing across departments and teams. This guide covers the capabilities financial organizations evaluate, security and customer-information considerations, payment-card and recording guidance, AI scope boundaries, and questions to ask a provider.

Get Started

Infrastructure that speaks the right protocols

EaseDial's platform handles SIP, RTP, TLS, and SRTP — so you get encrypted, reliable voice without managing the protocol stack yourself.