SIP 503 Service Unavailable on a trunk: finding who sent it
A 503 says a server could not handle the call right now. On a trunk the hard part is that any device in the path can generate it, and each one passes it back as if it came from further away.
Find the device that generated it
- Find the first leg it appears on. Trace the call across every device you can see. The device that sent a 503 without having received one is the source.
- Read the Server or User-Agent header. It often names the product that built the response.
- Read the Reason header. A cause such as
Q.850;cause=34(no circuit available) orcause=41(temporary failure) tells you what the sender believed went wrong. - Check the timing. A 503 that arrives in a few milliseconds was generated nearby. One that arrives after several seconds usually follows a timeout further on.
- Look for Retry-After. Its presence points to an overloaded or rate-limited server.
When the carrier or cloud service sent it
Typical reasons are congestion, a channel or concurrent-call limit on your account, or a failure further into their network. Collect the Call-ID, the time with time zone, and the numbers, and open a ticket. A second trunk or a second carrier is the only immediate remedy.
When your own gateway or SBC sent it
- The next hop is marked down. A keepalive to the destination failed, so the outbound route was taken out of service. On a Cisco CUBE,
show dial-peer voice summaryshows the keepalive state of each dial-peer. - The next hop could not be reached. The connection was refused, the name did not resolve, or the TLS handshake did not complete. An INVITE that was sent and simply never answered usually ends as a 408 or 504 instead.
- A limit was reached. Call admission control, a maximum-connections setting on a dial-peer, or a license count refused the call.
- No remaining route. Every outbound choice was tried and failed, and the last failure was returned.
Intermittent 503s
Count them by hour and by destination. A pattern that follows busy periods points to capacity. A pattern that follows one destination address points to one unhealthy server behind a name that resolves to several.
Prove where the 503 came from before you open a ticket. It decides whose ticket it is.
Where Workbench helps
End-to-End Troubleshooting joins the call manager, gateway and cloud records for one call, so the first leg carrying the 503 is visible. Voice Reference Tables decodes the cause value in the Reason header.