SIP & WebRTC production checklist
Use this on live incidents and before go-live. Most “network issues” are signaling, codec, NAT or tenant-boundary bugs.
1. Capture first
- SIP trace on both legs (UAC + UAS) for the failing call ID
- RTP/RTCP capture on the media path (not only SIP)
- Browser
webrtc-internalsdump for WebRTC legs - Exact timestamps, caller/callee, extension IDs, tenant ID
2. One-way audio
- Confirm SDP direction and hold (sendrecv vs sendonly)
- Verify RTP ports opened on firewall (not only SIP 5060)
- Check asymmetric RTP / NAT: correct
external_*on FreeSWITCH or Asterisk RTP settings - WebRTC: STUN reachable; TURN provisioned for symmetric NAT; ICE selected pair has bidirectional packets
- Codec mismatch (opus vs PCMU) or transcoding disabled on one leg
3. Registered but no calls
- Dialplan context matches registration domain
- Auth user ≠ dial string; tenant routing on multi-tenant systems
- Trunk IP allow-list vs registration expiry
- 503/403 from carrier — check RURI, From, P-Asserted-Identity
4. WebRTC agent desk
- WSS certificate valid; mixed content blocked?
- Microphone permission; headset switching on Windows
- SIP.js / JsSIP: contact URI, via host, register expires
- Queue transfer: Re-INVITE vs REFER — who owns media?
5. Multi-tenant isolation
- CDR and recordings scoped by tenant ID in API and storage paths
- Super-admin actions audited; extension numbers unique per tenant
- Shared trunk: verify dialed domain maps to correct tenant dialplan
6. Before production cutover
- Parallel run with rollback DIDs documented
- Load test: concurrent registrations + at least one campaign/queue path
- Monitoring: SIP OPTIONS, RTP loss, ESL/AMI health, disk for recordings
Need hands-on rescue or architecture review? Send the full brief or request a 15-minute intro.