How it works
In the dashboard, your PBX gets a trunk with a username and a password, shown on its card once. Save the password somewhere safe: we keep only a scrambled copy, so if you lose it, issue a new one and update your PBX. Your PBX signs in with them and sends the calls you choose: a number, an IVR option, a ring group nobody answered, or everything out of hours.
The steps send calls to the trunk by dialling 7000, a number no extension uses. That’s how most PBXs send a call to a trunk: an outbound route that matches it. The number your caller dialled goes along with the call, so different numbers can reach different agents.
While you set it up, the trunk’s card shows whether your PBX has signed in, or tried with the wrong password, within seconds. After 10 wrong tries in 5 minutes, that address is blocked for a while.
The steps for your PBX
The card shows the server, username and password; the steps call them “the server from the card” and so on. The dashboard shows the same steps for the PBX you pick.
3CX
- In the 3CX Admin Console, open Voice & Chat and choose Add Trunk. Pick your country, then the generic VoIP provider.
- Registrar: the server from the card, port 5060. Type of authentication: Register/Account based, with the Authentication ID and password from the card. Main trunk number: your main phone number.
- Under Options, move G.722 to the top of the codecs, then G.711 U-law and A-law.
- Under Outbound Rules, add a rule: calls to numbers starting with 7000, 4 digits long, go out on this trunk.
- Add a user extension for the agent, with no phone. In its forwarding rules, send every status to the external number 7000. Then point your numbers, an IVR option, a ring group’s no-answer or out-of-hours at that extension.
To encrypt calls: In the trunk’s Options, set the transport to TLS and the port to 5061, and switch on SRTP.
Menus differ between versions. If yours doesn’t match, 3CX: SIP trunks has the vendor’s own steps.
FreePBX
- Connectivity → Trunks → Add Trunk → Add SIP (chan_pjsip) Trunk. Call it Vorelai.
- pjsip Settings → General: Username and Secret from the card, Authentication Outbound, Registration None, SIP Server the server from the card, SIP Server Port 5060.
- pjsip Settings → Codecs: g722 first, then ulaw and alaw. Submit.
- Connectivity → Inbound Routes: for the numbers the agent answers, set the destination to Trunks → Vorelai. The number the caller dialled goes with the call.
- For an IVR option or a time condition: an Outbound Route with dial pattern 7000 on the Vorelai trunk, and Applications → Misc Destinations dialling 7000. Then Apply Config.
To encrypt calls: In Settings → Asterisk SIP Settings → SIP Settings [chan_pjsip], switch on the TLS transport with SSL method tlsv1_2. On the trunk: Transport 0.0.0.0-tls, SIP Server Port 5061, and under Advanced, Media Encryption SRTP via in-SDP.
Menus differ between versions. If yours doesn’t match, FreePBX: trunks has the vendor’s own steps.
Yeastar
- Extension and Trunk → Trunk → Add. ITSP Template: General. Trunk Type: Register Trunk. Call it Vorelai.
- Transport UDP. Hostname/IP and Domain: the server from the card. Port 5060. Username and Authentication Name: the username on the card. Password from the card.
- In the trunk’s codec settings, put G.722 first, then G.711 U-law and A-law.
- Call Control → Outbound Route → Add: dial pattern 7000, trunk Vorelai.
- Call Control → Inbound Route: for the numbers or hours the agent answers, set the destination to Outbound Route and pick the one above. An IVR option can dial External Number 7000.
To encrypt calls: Set the trunk’s transport to TLS and the port to 5061, and switch on SRTP in its advanced settings.
Menus differ between versions. If yours doesn’t match, Yeastar: create a SIP register trunk has the vendor’s own steps.
Grandstream UCM
- Extension/Trunk → VoIP Trunks → Add SIP Trunk. Type: Register SIP Trunk. Provider name: Vorelai.
- Host Name: the server from the card, port 5060. Username and Authenticate ID: the username on the card. Password from the card.
- In the trunk’s advanced settings, allow G.722 first, then PCMU and PCMA.
- Extension/Trunk → Outbound Routes → Add: pattern 7000, Use Trunk Vorelai.
- Extension/Trunk → Inbound Routes: for the numbers the agent answers, set Default Destination to External Number 7000, with a privilege level that may use the route above.
To encrypt calls: Set the trunk’s transport to TLS and the port to 5061, and SRTP to enabled.
Menus differ between versions. If yours doesn’t match, Grandstream: SIP trunks guide has the vendor’s own steps.
Another SIP PBX
- Add a SIP trunk to the server and port on the card, over UDP or TCP.
- Digest authentication with the username and password from the card. Registering is fine; so is not registering.
- Allow G.722 first, then G.711 µ-law or A-law. G.722 lets the agent hear callers clearly in noise.
- Add an outbound route that sends 7000 to this trunk.
- Send the calls you want answered to 7000: a number, an IVR option, a ring group’s no-answer or out-of-hours.
To encrypt calls: Use TLS 1.2 or newer to port 5061, with SRTP (SDES keys in the SDP).
Your network
- Use the name
sip.vorelai.com, never an IP address. The address behind it can change. - Your firewall lets SIP out to port 5060 (5061 if you encrypt calls), and audio out to UDP 10000–20000. We never call your PBX first, so nothing needs to be open towards it.
- Registering the trunk is up to your PBX: we accept it, but don’t need it.
- Keep the caller’s number on calls your PBX sends on, so the agent knows who’s calling.
- Put G.722 first. It’s wideband audio, clearer than an ordinary phone line, so the agent hears callers well even in noise.
Encrypted calls
Every trunk takes calls over TLS (port 5061) with SRTP audio; each PBX’s steps above say how. Once your calls arrive encrypted, switch on Encrypted calls only in the trunk’s settings. From then on, a call that isn’t encrypted goes to your fallback instead of the agent. The setting shows whether the latest call was encrypted both ways, so you can check before you switch it on.
Transfers and the fallback
When the agent transfers a caller, it hands the call back to your PBX to ring the extension or number, then leaves the call. Your PBX must accept transfers on the trunk (SIP REFER); most do by default. Your fallback works the same way: give the trunk a front-desk extension, a queue or a number for the calls the agent can’t take, and use Test transfer to check your PBX accepts it before you go live. See Transfers and The fallback.
Several offices
Each PBX gets its own trunk, up to your plan’s number of phone systems. Each trunk has a default agent, and any number can have an agent of its own under Phone system → Numbers.