Smol
Highly explosive experimental.
Your mileage may vary.
Intro
Smol – is a small (thus, the name) Docker Compose installation acting as a local proxy to our PBX. On the local side, it exposes SIP server to your LAN to avoid NAT-related issues. On the remote side, it establishes TLS+SRTP secured connection over WireGuard tunnel (SIPRNET) to PBX.
It’s only purpose is to allow connections from stupid dumb non-standard-following outdated stupid stupid stupid shitty SIP phones to remote PBX, overcoming issues with:
Double NAT – on your and Lanskoe site sides.
Modern encryption – TLS 1.2, AES-SRTP-SDES with a tiny pinch of WireGuard on top.
Trusted CA – uses
ca-certificatesdistro package.
Security consideration
Smol does not secure connection between itself and your phone over the LAN. Quirks of setting up TLS+SRTP for your particular phone model is your responsibility, and you can do that by patching Asterisk configuration files manually.
Requirements
Docker Engine with Compose.
1vCPU / 1GB of RAM / 5GB of storage would be more than enough.
Kernel with builtin WireGuard support.
Kernel IPv6 support – SIPRNET is IPv6-only network.
Support of
NET_ADMINcapability andnetwork_mode: host
Setting up an Account
To continue, you need to have a SIP account with client-siprnet connection type.
You can either:
Create a new account using this guide.
Edit your existing account, changing Endpoint’s template to
client-siprnet
Creating a SIPRNET Peer
Next, you need to create a new WireGuard peer.
# On your local machine
# Generate PSK
wg genpsk
# Generate keypair
wg genkey > private.key
wg pubkey < private.key
# Connect to Phonebooth via Teleport
tsh ssh root@phonebooth
# Edit bksp-siprnet configuration
# At the end of the file, add a new peer filling the template below.
nano /etc/wireguard/bksp-siprnet.conf
# Restart interface
systemctl restart wg-quick@bksp-siprnetPeer template. Replace XXXX with your prefix:
# @johndoe Home (username, and what device?)
[Peer]
AllowedIPs = fd91:652e:271a:e164::XXXX/128
PublicKey = public key from wg pubkey
PresharedKey = preshared key from wg genpsk
PersistentKeepalive = 30Setting up Smol
Exquisitely simple! Clone the repo, copy .env.example file, fill the values, and spin it up!
Follow README for setup guide.
Connecting the phone
When Smol is up and running, you may test your local connection using these credentials:
Server | Port | Protocol | Username | Password |
|---|---|---|---|---|
LAN IP of your Smol host | 5060 | TCP | Local username set in Smol’s configuration (default: 100) | Local password set in Smol’s configuration |
Before setting it up for a real phone, we strongly suggest you to test it with softphone first.
Here are a few destinations you may use for testing:
Current date & time:
*60Echo test:
*43Phone in Open Space:
100