Network Topology
The Network Topology screen tells the telephony platform how it sits on your network - whether it has a public IP address, lives behind NAT, or sits behind an SBC - and which network interfaces to use for signaling and media, in which role, and over which transport protocols. Getting this right is what makes SIP signaling and RTP audio flow correctly; a topology mismatch is one of the most common causes of one-way audio or unreachable endpoints.
This screen configures how the telephony components reflect your network; it does not set up the network itself. The public IP address, firewall rules, and NAT mappings must be configured on your network and firewall separately.
General Topology
Choose the scenario that matches how the server (or cluster) reaches the outside world using the General Topology drop-down:
-
Behind NAT
Use this when the system does not have a public IP address of its own and reaches the Internet through NAT. You must supply the network’s public IP address in the appropriate field, and the required NAT rules must already be configured on your firewall. One interface must be set to the Local and Public role - this is the interface holding the local IP used for the NAT mapping. Additional interfaces can use the Local role; each Local interface requires its Local Networks so traffic can be matched to the right LAN. An interface can carry one or several comma-separated LAN ranges, for example192.168.0.0/24,192.168.1.0/24,172.30.0.0/16. -
Public
Use this when a public IP address is configured directly on one of the system’s interfaces. That interface must be set to the Public role. As with Behind NAT, you can configure additional interfaces with the Local role. -
Behind ALG enabled NAT
Use this when all VoIP traffic is handled by a Session Border Controller (SBC) in front of the platform. In this topology only interfaces with the Local role are allowed - the SBC owns the public-facing side.
Network Interfaces and roles
The Network Interfaces section is where you assign each interface a role and enable the transport protocols it should accept. Roles:
- Public - the interface holds a public IP address.
- Local - a private/LAN interface; requires its Local Networks to be specified.
- Local and Public - the local interface used for a NAT mapping to a public address (used in the Behind NAT topology).
- Internal Connection - reserved for communication between Thirdlane system components (for example, between clustered servers) rather than for endpoint telephony.
- Ignore - assign this to any interface not used for telephony (such as a dedicated management NIC) so the platform leaves it alone.
For each telephony interface you can independently enable TCP, UDP, and TLS in any combination, matching the transports your endpoints and trunks use.
Best practices
- Match the topology to reality. If the box has a real public IP, use Public; if it is NATed, use Behind NAT and enter the correct public IP. A wrong topology commonly produces one-way audio.
- Always set Local Networks on Local interfaces so the platform can associate endpoints with the right LAN.
- Assign Ignore to non-telephony interfaces to keep management and backup NICs out of SIP/RTP handling.
- Enable TLS (with TCP/UDP as needed) for any endpoints that connect over untrusted networks - see SIP Encryption (TLS).