# SIP Provider

Use SIP technology for chan\_sip provider trunks. SIP providers can create and maintain a global `sipfriends` realtime row when **Use Realtime Account** is enabled.

<figure id="bkmrk-sip-realtime-account">![SIP realtime account settings with fictional chan_sip trunk values.](https://manual.mirtapbx.com/uploads/images/gallery/2026-06/provider-sip-realtime.png)<figcaption>SIP realtime account settings with fictional chan\_sip trunk values.</figcaption></figure>## Common Realtime Fields

<table id="bkmrk-fieldapplies-topurpo"><thead><tr><th>Field</th><th>Applies to</th><th>Purpose</th><th>Fictional example</th></tr></thead><tbody><tr><td>**Use Realtime Account**</td><td>SIP, PJSIP, IAX2</td><td>Creates and maintains the Asterisk realtime peer, endpoint, AOR, auth, or IAX row for the provider.</td><td>`checked`</td></tr><tr><td>**Transport**</td><td>SIP, PJSIP</td><td>SIP signaling transport. For PJSIP this maps to transport objects such as `transport-udp`, `transport-tcp`, or `transport-tls`.</td><td>`UDP` or `TLS`</td></tr><tr><td>**RTP Encryption (SRTP)**</td><td>SIP, PJSIP</td><td>Enables SRTP media encryption when supported by the provider. PJSIP stores this as `media_encryption=sdes`.</td><td>`No` for standard UDP SIP, `Yes` for TLS/SRTP trunks</td></tr><tr><td>**Host**</td><td>SIP, PJSIP, IAX2</td><td>Remote provider address. Use an IP address when inbound realtime matching must identify the carrier by source IP.</td><td>`203.0.113.20`</td></tr><tr><td>**Port**</td><td>SIP, PJSIP, IAX2</td><td>Remote signaling port. Defaults are commonly 5060 for SIP/PJSIP and 4569 for IAX2.</td><td>`5060`</td></tr><tr><td>**Outbound Proxy**</td><td>SIP, PJSIP</td><td>Proxy URI or host used for outbound signaling when required by the carrier.</td><td>`sip-proxy.example.invalid`</td></tr><tr><td>**Username**</td><td>SIP, PJSIP, IAX2</td><td>Authentication username sent to the provider. PJSIP stores this in `ps_auths.username`, chan\_sip as `defaultuser`.</td><td>`docs_sip_user`</td></tr><tr><td>**Password**</td><td>SIP, PJSIP, IAX2</td><td>Authentication secret for the provider. Use a unique carrier-supplied or generated secret.</td><td>`FictionalSecret-2026`</td></tr><tr><td>**Qualify**</td><td>SIP, PJSIP</td><td>Enables SIP OPTIONS reachability checks and controls timeout behavior.</td><td>`Yes`</td></tr><tr><td>**Qualify Frequency**</td><td>SIP, PJSIP</td><td>Interval in seconds between provider reachability checks.</td><td>`60 secs`</td></tr><tr><td>**Codecs**</td><td>SIP, PJSIP, IAX2</td><td>Allowed audio codecs. MiRTA PBX stores `disallow=all` and the selected allow list.</td><td>`alaw`, `ulaw`, `g722`</td></tr><tr><td>**Session Expires**</td><td>SIP, PJSIP</td><td>Maximum SIP session refresh interval in seconds.</td><td>`1800`</td></tr><tr><td>**DTMF Mode**</td><td>SIP, PJSIP</td><td>DTMF signaling method. PJSIP maps RFC 2833 to `rfc4733`.</td><td>`RFC 2833/RFC 4733`</td></tr><tr><td>**RTP Keepalive**</td><td>SIP, PJSIP</td><td>Sends RTP keepalive packets to help keep NAT bindings and media paths active.</td><td>`5` seconds</td></tr></tbody></table>

## SIP-Only Fields

<table id="bkmrk-fieldapplies-topurpo-1"><thead><tr><th>Field</th><th>Applies to</th><th>Purpose</th><th>Fictional example</th></tr></thead><tbody><tr><td>**From User**</td><td>SIP only</td><td>chan\_sip `fromuser` value used in the SIP From header.</td><td>`+15551230000`</td></tr><tr><td>**From Domain**</td><td>SIP only</td><td>chan\_sip `fromdomain` value used when the provider requires a specific domain in the From header.</td><td>`sip.example.invalid`</td></tr><tr><td>**Send RPID**</td><td>SIP only</td><td>Controls whether caller identity is sent using Remote-Party-ID, P-Asserted-Identity, or both.</td><td>`PAI`</td></tr><tr><td>**Trust RPID**</td><td>SIP only</td><td>Controls whether inbound Remote-Party-ID or P-Asserted-Identity data is trusted for caller identity.</td><td>`PAI`</td></tr><tr><td>**Trust Outbound for CallerID Presentation**</td><td>SIP only</td><td>Controls how prohibited caller presentation is handled in RPID/PAI headers.</td><td>`Legacy`</td></tr><tr><td>**Session Timers**</td><td>SIP only</td><td>chan\_sip session timer policy: accept remote requests, originate timers, or refuse timers.</td><td>`Accept`</td></tr><tr><td>**Progress inband**</td><td>SIP only</td><td>Controls whether Asterisk generates in-band progress audio before answer.</td><td>`Yes`</td></tr><tr><td>**NAT**</td><td>SIP only</td><td>chan\_sip NAT behavior. `force_rport,comedia` is common for symmetric RTP and response routing.</td><td>`force_rport,comedia`</td></tr><tr><td>**Call response timer (ms) - T1**</td><td>SIP only</td><td>Milliseconds to wait for response to SIP messages.</td><td>`500`</td></tr><tr><td>**Call setup timer (ms) - B**</td><td>SIP only</td><td>Maximum milliseconds to wait for call setup before autocongestion when no provisional response arrives.</td><td>`5000`</td></tr><tr><td>**Can Reinvite**</td><td>SIP only</td><td>Allows Asterisk to attempt direct media re-invites. Use No when recording, NAT, or media control should keep Asterisk in the RTP path.</td><td>`No`</td></tr><tr><td>**Allow Transfer**</td><td>SIP only</td><td>chan\_sip `allowtransfer`. When enabled, the peer may request SIP REFER transfers.</td><td>`No`</td></tr><tr><td>**Insecure**</td><td>SIP only</td><td>chan\_sip authentication matching option. Port, Invite is common for IP-authenticated trunks.</td><td>`Port, Invite`</td></tr></tbody></table>

## Fictional SIP Example

```
Name: Docs Telecom SIP Trunk
Peer Name: docs_telecom_sip
Technology: SIP
Host: 203.0.113.20
Port: 5060
Username: docs_sip_user
From User: +15551230000
From Domain: sip.example.invalid
NAT: force_rport,comedia
Insecure: Port, Invite
```