Re: Best approach for 2-node active-active Kamailio setup

Henning Westerholt via sr-users <[email protected]>
Newsgroups gmane.comp.voip.ser
Message-ID <AS8PR07MB7221F7820FC806A44CD26346BFD32@AS8PR07MB7221.eurprd07.prod.outlook.com>
Hello,

regarding connection, you can use a private network peering, a VPN or of course also Kamailio TLS for it.

About the media takeover, here you need to look into rtpengine redis clustering. It’s possible to do it, just some work to get it really thoroughly setup. There are also some signalisation protocol extensions that can help here, but they are mostly feasible if you control the user agent.

Cheers,

Henning

From: Asma BOUDDYACH <[email protected]>
Sent: Dienstag, 4. August 2026 15:39
To: Henning Westerholt <[email protected]>
Cc: Kamailio (SER) - Users Mailing List <[email protected]>
Subject: Re: [SR-Users] Best approach for 2-node active-active Kamailio setup

Subject: Re: DMQ setup — follow-up on security and media takeover

Hi,

Thank you very much for the clarification, this is very helpful.

Two follow-up questions if I may:

1. Regarding securing DMQ over the internet between the two datacenters — what would you recommend concretely? Would a VPN tunnel between the two nodes be sufficient, or is there a native Kamailio mechanism (e.g. TLS on the DMQ channel itself) that you would recommend instead?

2. Regarding the media takeover mechanism you mentioned as being more complex — could you point me to any documentation, module, or general approach to investigate? I understand DMQ only replicates dialog information, and I'd like to understand what additional piece would be needed if we wanted in-progress calls to survive a failover, even as a future improvement.

For now we are planning to run Active/Passive without DMQ, with failover handled by the SIP operator via OPTIONS ping. We may revisit DMQ later once the above points are clarified.

Thanks again for your time.

Best regards,
Asmaa

Le mer. 8 juil. 2026 à 21:07, Henning Westerholt <[email protected]<mailto:[email protected]>> a écrit :
Hello Asma,

This are fairly modest requirements from the CPS side.

DMQ should be fine for this kind of setup. Just keep in mind that DMQ is not designed to run over the unprotected internet, consider adding some security to your cfg. It also does not provide a full call take over; it merely replicates the dialog information. For media proxy take over you also need to investigate other mechanism, this is more complicated to setup.

Use the latest Kamailio stable version, e.g. 6.1.3 for a new setup.

Cheers,

Henning

From: Asma BOUDDYACH <[email protected]<mailto:[email protected]>>
Sent: Mittwoch, 8. Juli 2026 17:06
To: Henning Westerholt <[email protected]<mailto:[email protected]>>
Cc: Kamailio (SER) - Users Mailing List <[email protected]<mailto:[email protected]>>
Subject: Re: [SR-Users] Best approach for 2-node active-active Kamailio setup

Hi Henning


Thank you for your  reply

I am deploying a 2-node Kamailio SBC infrastructure with the following setup:

- Node 1 : Datacenter 1
- Node 2 : Datacenter 2
- Maximum simultaneous calls : 54
- Use case : SBC in front of a 3CX IPBX

Given the current state of DMQ dialog fixes (active-active still having issues PR #4774 pointer.), I am considering an active-passive setup with DMQ synchronization, so that in-progress calls are maintained when Node 1 fails and Node 2 takes over.

My questions are:

1. Is active-passive with DMQ dialog synchronization stable enough today for production use?

2. Which Kamailio version would you recommend for this setup?

3. Are there any specific DMQ configuration recommendations for an active-passive setup between 2 datacenters?

Thank you very much for your guidance.

Le mer. 8 juil. 2026 à 16:41, Henning Westerholt <[email protected]<mailto:[email protected]>> a écrit :
Hello,

It’s a bit hard to give a conclusive answer to this, as it’s a matter of taste and also of course depends on the requirements.

Have a look to the past year KamailioWorld conferences talk, which you can find e.g. on youtube. You will get many inspirations for these topics.

You can also find older discussions of these topics in our mailing list archives, or with search engines.

Cheers,

Henning


--
Henning Westerholt
Kamailio services – https://gilawa.com<https://gilawa.com/>

From: Asma BOUDDYACH via sr-users <[email protected]<mailto:[email protected]>>
Sent: Mittwoch, 8. Juli 2026 15:44
To: asma.bouddyach--- via sr-users <[email protected]<mailto:[email protected]>>
Cc: Asma BOUDDYACH <[email protected]<mailto:[email protected]>>
Subject: [SR-Users] Best approach for 2-node active-active Kamailio setup

Hi ,

I am currently deploying a Kamailio SBC infrastructure with 2 nodes, one per datacenter, and I would like to set them up in active-active mode.

I have no experience yet with multi-node Kamailio setups and I would like to ask:

1. What is the recommended approach for a 2-node active-active Kamailio deployment today?

2. What modules or mechanisms should I use to synchronize state between the two nodes (calls, registrations, etc.)?

3. Are there any known issues or limitations I should be aware of before starting the configuration?

Any guidance or documentation pointers would be greatly appreciated.

Best regards,


This message and any of its attachments is intended solely for the addresses and is confidential. If you receive this message in error, please delete it and immediately notify the sender. Any use not in accord with its purpose, any dissemination or disclosure, either whole or partial, is prohibited except formal approval. The internet cannot guarantee the integrity of this message. The INTELCIA Group shall (will) not therefore be liable for the message if modified.

———————————————

Ce message et toutes les pièces jointes sont établis à l'intention exclusive de ses destinataires et sont confidentiels. Si vous recevez ce message par erreur, merci de le détruire et d’en avertir immédiatement l’expéditeur. Toute utilisation de ce message non conforme à sa destination, toute diffusion ou toute publication, même partielle, est interdite, sauf autorisation expresse. L’internet ne permettant pas d’assurer l’intégrité de ce message, le groupe INTELCIA décline toute responsabilité au titre de ce message, dans l’hypothèse où il aurait été modifié.


This message and any of its attachments is intended solely for the addresses and is confidential. If you receive this message in error, please delete it and immediately notify the sender. Any use not in accord with its purpose, any dissemination or disclosure, either whole or partial, is prohibited except formal approval. The internet cannot guarantee the integrity of this message. The INTELCIA Group shall (will) not therefore be liable for the message if modified.

———————————————

Ce message et toutes les pièces jointes sont établis à l'intention exclusive de ses destinataires et sont confidentiels. Si vous recevez ce message par erreur, merci de le détruire et d’en avertir immédiatement l’expéditeur. Toute utilisation de ce message non conforme à sa destination, toute diffusion ou toute publication, même partielle, est interdite, sauf autorisation expresse. L’internet ne permettant pas d’assurer l’intégrité de ce message, le groupe INTELCIA décline toute responsabilité au titre de ce message, dans l’hypothèse où il aurait été modifié.


This message and any of its attachments is intended solely for the addresses and is confidential. If you receive this message in error, please delete it and immediately notify the sender. Any use not in accord with its purpose, any dissemination or disclosure, either whole or partial, is prohibited except formal approval. The internet cannot guarantee the integrity of this message. The INTELCIA Group shall (will) not therefore be liable for the message if modified.

———————————————

Ce message et toutes les pièces jointes sont établis à l'intention exclusive de ses destinataires et sont confidentiels. Si vous recevez ce message par erreur, merci de le détruire et d’en avertir immédiatement l’expéditeur. Toute utilisation de ce message non conforme à sa destination, toute diffusion ou toute publication, même partielle, est interdite, sauf autorisation expresse. L’internet ne permettant pas d’assurer l’intégrité de ce message, le groupe INTELCIA décline toute responsabilité au titre de ce message, dans l’hypothèse où il aurait été modifié.

__________________________________________________________
Kamailio - Users Mailing List - Non Commercial Discussions -- [email protected]
To unsubscribe send an email to [email protected]
Important: keep the mailing list in the recipients, do not reply only to the sender!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.