Use Case

Securing User Access to Hosted Voice Applications with an Access SBC

The Challenge

Service providers delivering hosted voice, whether IP-PBX, contact center, conferencing, or unified communications, face a persistent problem at the access edge. The application works. The network between it and the subscriber does not cooperate.

Thousands of remote endpoints sit behind small-office routers that apply NAT, breaking SIP signaling and media paths in ways the hosted platform was never designed to handle. Registrations arrive from unpredictable addresses. Firewall pinholes close between keepalives. And every endpoint that connects over the public internet is an entry point for scanning, registration floods, and toll fraud attempts aimed at the platform behind it.

Exposing a hosted voice platform directly to subscriber traffic is not a viable architecture. Providers need a controlled edge that solves NAT traversal, forwards registrations reliably, and absorbs security threats, all while scaling to serve a large and growing subscriber base from a single system.

The Solution

How an Access SBC Solves This

An access SBC sits between remote subscriber endpoints and the hosted voice platform. It is the single controlled point through which all subscriber traffic passes, and it handles everything the platform itself cannot.

This is one of the two fundamental SBC deployment roles. Where a peering SBC interconnects two service provider networks as equals, an access SBC connects and protects an organization’s own users, or a provider’s subscribers, reaching a hosted application. The concerns are different: NAT, registration, and securing large numbers of remote endpoints rather than inter-carrier interoperability.

Access SBC topology: remote phones and small business routers connect through a ProSBC to a hosted IP-PBX or UC platform, with the SBC handling NAT traversal, registration forwarding, and security

Access SBC deployment: remote subscribers behind NAT connect through a single ProSBC to the hosted platform. Click to enlarge.

Key Capabilities

What the Access SBC Handles

NAT Traversal

Subscribers connect through IADs and small routers that apply NAT, breaking SIP’s assumption that the address in the signaling matches the address where media should be sent. The access SBC navigates the NAT boundary and maintains firewall pinholes so calls connect and media flows without intervention from the subscriber.

Registration Forwarding

The SBC relays SIP registrations from subscriber endpoints to the registrar behind it. The hosted platform always knows where each device is and can deliver calls to it, even as endpoints roam or reconnect from different addresses.

Security at the Edge

By sitting in front of the hosted platform, the SBC absorbs scanning and attack traffic, enforces access control lists, and applies topology hiding so the platform’s internal addresses are never exposed to the public internet.

Scale and Manageability

Access deployments serve many subscribers from one system. Session capacity, high-performance media handling, and management connectors for provisioning and monitoring a large subscriber base are essential to the role.

Deployment Options

Deploy It Your Way

A provider running hosted voice can operate its access SBC in whatever model fits its team and its infrastructure. Three paths are common:

Self-Managed

Run ProSBC as software on your own infrastructure: AWS, Azure, VMware, KVM, or bare metal. Full control over configuration, routing scripts, and scaling.

Managed Service

Hand deployment and day-to-day operation to TelcoBridges through the ProSBC managed service. Includes 1+1 HA, 24/7 support, setup, integration, and monitoring. Deploys on your platform or ours.

Fully Hosted

TelcoBridges hosts and manages the SBC entirely. You point your subscribers and your hosted platform at a managed access edge with no infrastructure to maintain.

Why ProSBC

ProSBC for the Access Role

ProSBC is a carrier-grade, software-based session border controller built on more than 20 years of SIP deployment experience. For the access use case, it delivers:

60,000 sessions per server with support for up to 350,000 endpoint registrations, enough to serve a large subscriber base from a single deployment.
NAT traversal and registration forwarding built into the core, with topology hiding and DoS/DDoS protection at the access edge.
Flexible deployment on AWS, Azure, VMware, KVM, or bare metal, with annual subscription pricing and no upfront hardware investment.
RESTful API, SNMP, CDR output, MOS scoring, and live call trace for the provisioning and monitoring tooling a provider needs at scale.

Evaluate it with the free, permanent three-session ProSBC Lab, run a full 30-day trial, or start with the managed service.

FAQ

Frequently Asked Questions

What is an access SBC?

An access SBC secures and enables user access to a hosted voice application, such as a hosted IP-PBX, contact center, conferencing platform, or UC service. It sits at the edge between remote subscribers and the platform, handling NAT traversal, registration forwarding, and security.

How is an access SBC different from a peering SBC?

An access SBC connects and protects subscribers or an organization’s users reaching a hosted application, dealing with NAT, registration, and endpoint security. A peering SBC interconnects two service provider networks as equals. They sit at different edges and solve different problems.

Why is NAT traversal such a big part of the access role?

Small businesses connect their phones through routers that use network address translation, which breaks SIP if nothing accounts for it. The access SBC navigates the NAT boundary and keeps the right ports open so calls connect, which is central to delivering hosted voice to remote sites.

How many subscribers can one access SBC serve?

Access deployments are built for scale, aiming to support many businesses, ideally thousands, from a single system. ProSBC supports up to 60,000 concurrent sessions and 350,000 endpoint registrations per server.

Secure Your Hosted-App Access Edge

Talk to a solutions architect about deploying ProSBC for the access use case, or start evaluating on your own.

Prefer to evaluate on your own first? Start your 30-day free trial.