# PJSIP Provider

Use PJSIP technology for res\_pjsip provider trunks. MiRTA PBX maintains related `ps_endpoints`, `ps_aors`, `ps_auths`, and `ps_endpoint_id_ips` rows when realtime is enabled.

<figure id="bkmrk-pjsip-realtime-accou">![PJSIP realtime account settings with fictional res_pjsip trunk values.](https://manual.mirtapbx.com/uploads/images/gallery/2026-06/provider-pjsip-realtime.png)<figcaption>PJSIP realtime account settings with fictional res\_pjsip trunk values.</figcaption></figure>## Common Realtime Fields

<table id="bkmrk-fieldapplies-topurpo"><thead><tr><th>Field</th><th>Applies to</th><th>Purpose</th><th>Fictional example</th></tr></thead><tbody><tr><td>**Use Realtime Account**</td><td>SIP, PJSIP, IAX2</td><td>Creates and maintains the Asterisk realtime peer, endpoint, AOR, auth, or IAX row for the provider.</td><td>`checked`</td></tr><tr><td>**Transport**</td><td>SIP, PJSIP</td><td>SIP signaling transport. For PJSIP this maps to transport objects such as `transport-udp`, `transport-tcp`, or `transport-tls`.</td><td>`UDP` or `TLS`</td></tr><tr><td>**RTP Encryption (SRTP)**</td><td>SIP, PJSIP</td><td>Enables SRTP media encryption when supported by the provider. PJSIP stores this as `media_encryption=sdes`.</td><td>`No` for standard UDP SIP, `Yes` for TLS/SRTP trunks</td></tr><tr><td>**Host**</td><td>SIP, PJSIP, IAX2</td><td>Remote provider address. Use an IP address when inbound realtime matching must identify the carrier by source IP.</td><td>`203.0.113.20`</td></tr><tr><td>**Port**</td><td>SIP, PJSIP, IAX2</td><td>Remote signaling port. Defaults are commonly 5060 for SIP/PJSIP and 4569 for IAX2.</td><td>`5060`</td></tr><tr><td>**Outbound Proxy**</td><td>SIP, PJSIP</td><td>Proxy URI or host used for outbound signaling when required by the carrier.</td><td>`sip-proxy.example.invalid`</td></tr><tr><td>**Username**</td><td>SIP, PJSIP, IAX2</td><td>Authentication username sent to the provider. PJSIP stores this in `ps_auths.username`, chan\_sip as `defaultuser`.</td><td>`docs_sip_user`</td></tr><tr><td>**Password**</td><td>SIP, PJSIP, IAX2</td><td>Authentication secret for the provider. Use a unique carrier-supplied or generated secret.</td><td>`FictionalSecret-2026`</td></tr><tr><td>**Qualify**</td><td>SIP, PJSIP</td><td>Enables SIP OPTIONS reachability checks and controls timeout behavior.</td><td>`Yes`</td></tr><tr><td>**Qualify Frequency**</td><td>SIP, PJSIP</td><td>Interval in seconds between provider reachability checks.</td><td>`60 secs`</td></tr><tr><td>**Codecs**</td><td>SIP, PJSIP, IAX2</td><td>Allowed audio codecs. MiRTA PBX stores `disallow=all` and the selected allow list.</td><td>`alaw`, `ulaw`, `g722`</td></tr><tr><td>**Session Expires**</td><td>SIP, PJSIP</td><td>Maximum SIP session refresh interval in seconds.</td><td>`1800`</td></tr><tr><td>**DTMF Mode**</td><td>SIP, PJSIP</td><td>DTMF signaling method. PJSIP maps RFC 2833 to `rfc4733`.</td><td>`RFC 2833/RFC 4733`</td></tr><tr><td>**RTP Keepalive**</td><td>SIP, PJSIP</td><td>Sends RTP keepalive packets to help keep NAT bindings and media paths active.</td><td>`5` seconds</td></tr></tbody></table>

## PJSIP-Specific Fields

<table id="bkmrk-fieldapplies-topurpo-1"><thead><tr><th>Field</th><th>Applies to</th><th>Purpose</th><th>Fictional example</th></tr></thead><tbody><tr><td>**Transport**</td><td>PJSIP only</td><td>Maps to the selected PJSIP transport object. Use TLS when the carrier requires encrypted signaling.</td><td>`TLS`</td></tr><tr><td>**Host and Port**</td><td>PJSIP only</td><td>Used to build the AOR contact and, when Host is an IP address, the endpoint identify match.</td><td>`198.51.100.30:5061`</td></tr><tr><td>**Username and Password**</td><td>PJSIP only</td><td>Stored in `ps_auths`. If username is empty, MiRTA PBX does not attach username/password auth.</td><td>`docs_pjsip_user`</td></tr><tr><td>**Outbound Proxy**</td><td>PJSIP only</td><td>PJSIP outbound proxy string for the endpoint.</td><td>`sip:edge.example.invalid;transport=tls`</td></tr><tr><td>**Send RPID**</td><td>PJSIP only</td><td>Maps to PJSIP `send_rpid` and `send_pai`.</td><td>`PAI`</td></tr><tr><td>**Direct Media**</td><td>PJSIP only</td><td>Allows PJSIP to attempt direct RTP. Disable when NAT, recording, transcoding, or media control requires Asterisk in the RTP path.</td><td>`No`</td></tr><tr><td>**Allow Transfer**</td><td>PJSIP only</td><td>PJSIP `allow_transfer`. When enabled, the endpoint may request SIP REFER transfers.</td><td>`No`</td></tr><tr><td>**RTP Encryption (SRTP)**</td><td>PJSIP only</td><td>Stores `media_encryption=sdes` when enabled.</td><td>`Yes`</td></tr><tr><td>**Qualify Frequency and Timeout**</td><td>PJSIP only</td><td>Stored on the AOR as `qualify_frequency` and `qualify_timeout`.</td><td>`60 secs`</td></tr></tbody></table>

## Fictional PJSIP Example

```
Name: Docs Telecom PJSIP Trunk
Peer Name: docs_telecom_pjsip
Technology: PJSIP
Transport: TLS
RTP Encryption: Yes
Host: 198.51.100.30
Port: 5061
Outbound Proxy: sip:edge.example.invalid;transport=tls
Send RPID: PAI
Direct Media: No
Allow Transfer: No
```