A session border controller (SBC) is a network element, available as hardware, software or a cloud service, that sits at the border between two voice networks and controls the calls that pass between them. It is most often found between a business phone system and a carrier’s SIP trunks, between Microsoft Teams and a carrier, or between sites and a cloud phone service. An SBC protects the phone system from attack, translates between systems that implement SIP differently, and enforces rules on which calls are allowed and how they are routed.
At a glance
- An SBC sits at the edge of a voice network and handles both call signaling and, usually, call audio.
- It secures VoIP connections, hides internal network details, and blocks or limits suspicious calling patterns.
- It translates between different SIP implementations, codecs and number formats so two systems can interoperate.
- It can be an appliance, a virtual machine, or a managed service run by a carrier or partner.
- Microsoft Teams Direct Routing and many SIP trunking designs use an SBC, often a certified model.
What problem it solves
When a phone system connects to the outside world over IP, it is exposed in ways a traditional phone line was not. Attackers scan for open SIP ports to place fraudulent international calls (toll fraud) or flood systems with traffic. Ordinary firewalls struggle with VoIP because call audio uses ports negotiated inside the signaling, and network address translation can break the audio path.
Interoperability is the other problem. SIP is a standard, but vendors implement it differently: header formats, number formats, codecs and how they handle call transfers vary. Connecting a PBX to a carrier, or Teams to a contact center, can fail on details that neither side will change. An SBC sits in the middle, cleans up the traffic and translates each side into what the other expects.
How it works
Signaling control. The SBC terminates SIP sessions from each side and creates new ones toward the other, so call signaling between the two networks passes through the SBC instead of flowing directly. It can rewrite headers and numbers, apply routing rules, limit call rates and reject calls that don’t meet policy.
Media handling. In most deployments the SBC also relays call audio, which lets it manage network address translation, enforce encryption, and convert between codecs when the two sides don’t share one. Some designs let media flow directly between endpoints to save bandwidth, with the SBC handling only signaling.
Security. SBCs typically support encrypted signaling (TLS) and media (SRTP), hide internal addresses, detect registration or call floods, and restrict which destinations can be called. These features reduce risk; they still need correct configuration, patching and monitoring.
Routing and resilience. An SBC can route calls across several SIP trunks or carriers, fail over when one is unavailable, and connect several phone systems, such as an old PBX and a cloud service, during a migration.
Caller ID and compliance. Depending on the design, the SBC or the carrier passes caller ID information used for call authentication. In the US, carriers are required to authenticate caller ID on IP calls under the STIR/SHAKEN framework; requirements differ by country.
Where it runs. SBCs can be installed on site, in a data center, in a public cloud, or consumed as a service. Microsoft Teams Direct Routing requires an SBC model that Microsoft has certified, run by you or provided as a managed service.
When it matters for buyers
- When connecting Microsoft Teams or another cloud phone service to a carrier of your choice, often called bring your own carrier (BYOC).
- When moving from PRI or analog lines to SIP trunks on an existing phone system.
- When running several phone systems in parallel during a migration or after a merger.
- When a security review flags exposed VoIP services or the business suffers toll fraud.
- When call failures between systems point to SIP compatibility problems.
Questions to ask vendors
- Is the SBC certified or tested with our phone system, our carrier, and Microsoft Teams if relevant?
- Will it run as an appliance, a virtual machine, a cloud instance, or a managed service, and who operates it?
- How is it made redundant, and what happens to active and new calls if one SBC fails?
- Which security features are enabled by default, and how do you monitor for toll fraud?
- How is licensing priced: per concurrent call, per session, per feature, or per user?
- Who handles software updates and security patches, and on what schedule?
- How are emergency calls routed through the SBC, and how is location passed for them?
How it differs from a firewall
A network firewall decides which traffic may pass based on addresses, ports, applications and policy. Some firewalls include SIP helpers, but they typically do not take part in the call itself. An SBC terminates and re-originates calls, so it can change signaling, manage the audio stream, translate between systems and apply voice-specific policy. Most organizations that need an SBC still keep a firewall in front of or alongside it.
To plan carrier connections for Teams, see our Microsoft Teams PSTN connectivity solution page.
