BYO SIP Trunk: RTP port range, SRTP & TLS specs ne...
# support
m
Hi team! 👋 Setting up BYO SIP Trunk with a Japanese carrier (IPS Pro / LIPSE, licensed JP electric telecom operator). Carrier requires technical specs from Vapi side before they can provision service. Could you help confirm: 1. RTP port range What port range does Vapi use for RTP media? - Outbound (Vapi → carrier) - Inbound (carrier → Vapi) 2. SRTP support - Does Vapi support SRTP for BYO SIP Trunks? - Encryption modes? (AES_CM_128_HMAC_SHA1_80, etc.) - Key exchange? (SDES via TLS, DTLS-SRTP, etc.) 3. TLS details - Minimum TLS version (1.2 / 1.3)? - mTLS required or one-way? **Context**: We need TLS + SRTP for compliance with Japanese Telecommunications Business Act (secrecy of communications). Carrier is asking specifically for these. Our Vapi account email: info@topbank.jp Already aware of (from docs): - Outbound SBC IPs: 44.229.228.186, 44.238.177.138 - SIP ports: 5060 UDP/TCP, 5061 TLS Thanks! 🙏
m
You’re on the right track here, especially with the TLS + SRTP compliance requirements in Japan. I’ve worked on similar BYO SIP trunk setups and can help check the Vapi side properly so provisioning goes smoothly. Quick question, are you securing both SIP signaling and RTP media, or just the signaling side? @MK
m
Hi! Thanks so much for jumping in! 🙏 We'd like to secure both layers: 1. SIP signaling → TLS (already planned, port 5061) 2. RTP media → SRTP The reason we need media encryption too is for full compliance with Japanese Telecommunications Business Act Article 4 (電気通信事業法第4条) - "secrecy of communications". This covers not just call metadata but the actual voice content as well. Our lawyer is preparing the registered telecom operator filing (届出電気通信事業者) and recommended both TLS + SRTP as the standard technical safeguard. That said, we understand SRTP support can vary across providers. So: 1. If SRTP is fully supported on Vapi's BYO SIP → great, we'd like to enable it 2. **If SRTP has limitations or known interop issues with carriers in Japan** → please let us know. We can coordinate with our carrier (IPS Pro / LIPSE) on their side For SRTP, we'd appreciate clarification on: - Supported cipher suites (e.g., AES_CM_128_HMAC_SHA1_80, AES_CM_128_HMAC_SHA1_32, AES_256 variants) - Key exchange method (SDES via SIPS, DTLS-SRTP, MIKEY, etc.) - Any known interop quirks with Japanese carriers using IP-to-IP authentication And for RTP/SRTP port range — we still need this for the carrier's SBC firewall config on their side. Thanks so much! 🚀
m
Thanks for the detailed info, your setup and compliance approach honestly sounds solid. The main thing now is making sure Vapi’s SRTP support, RTP port ranges, and SBC compatibility all line up with what IPS Pro/LIPSE expects before they provision the trunk. I’ve handled similar SIP TLS + SRTP integrations before and can help you check through the technical side properly to avoid interop or firewall issues later. If you want, feel free to send me a private message and I’d be happy to help directly. @MK