Hey everyone , i've read almost all the posts here , tried everything but this kamailio just won't start , i managed to start at first but with a self signed certificate now i'm using Let's encrypt with an ip&domain .Maybe i misconfigured something here is my codes . This is a Centos7 Server From Digital Ocean , I followed the From Scratch installation & fixed a lot of ip's import databases manually and all that , all the posts have been really helpful

#!KAMAILIO
#
#!define WITH_MYSQL
#!define WITH_AUTH
#!define WITH_USRLOCDB
#!define WITH_NAT
#!define WITH_ANTIFLOOD
#
#
# Kamailio (OpenSER) SIP Server v5.0 - default configuration script
#     - web: http://www.kamailio.org
#     - git: http://sip-router.org
#
# Direct your questions about this file to: 
#
# Refer to the Core CookBook at http://www.kamailio.org/wiki/
# for an explanation of possible statements, functions and parameters.
#
# Several features can be enabled using '#!define WITH_FEATURE' directives:
#
# *** To run in debug mode: 
#     - define WITH_DEBUG
#
# *** To enable mysql: 
#     - define WITH_MYSQL
#
# *** To enable authentication execute:
#     - enable mysql
#     - define WITH_AUTH
#     - add users using 'kamctl'
#
# *** To enable IP authentication execute:
#     - enable mysql
#     - enable authentication
#     - define WITH_IPAUTH
#     - add IP addresses with group id '1' to 'address' table
#
# *** To enable persistent user location execute:
#     - enable mysql
#     - define WITH_USRLOCDB
#
# *** To enable presence server execute:
#     - enable mysql
#     - define WITH_PRESENCE
#
# *** To enable nat traversal execute:
#     - define WITH_NAT
#     - install RTPProxy: http://www.rtpproxy.org
#     - start RTPProxy:
#        rtpproxy -l _your_public_ip_ -s udp:localhost:7722
#     - option for NAT SIP OPTIONS keepalives: WITH_NATSIPPING
#
# *** To enable PSTN gateway routing execute:
#     - define WITH_PSTN
#     - set the value of pstn.gw_ip
#     - check route[PSTN] for regexp routing condition
#
# *** To enable database aliases lookup execute:
#     - enable mysql
#     - define WITH_ALIASDB
#
# *** To enable speed dial lookup execute:
#     - enable mysql
#     - define WITH_SPEEDDIAL
#
# *** To enable multi-domain support execute:
#     - enable mysql
#     - define WITH_MULTIDOMAIN
#
# *** To enable TLS support execute:
#     - adjust CFGDIR/tls.cfg as needed
#     - define WITH_TLS
#
# *** To enable XMLRPC support execute:
#     - define WITH_XMLRPC
#     - adjust route[XMLRPC] for access policy
#
# *** To enable anti-flood detection execute:
#     - adjust pike and htable=>ipban settings as needed (default is
#       block if more than 16 requests in 2 seconds and ban for 300 seconds)
#     - define WITH_ANTIFLOOD
#
# *** To block 3XX redirect replies execute:
#     - define WITH_BLOCK3XX
#
# *** To enable VoiceMail routing execute:
#     - define WITH_VOICEMAIL
#     - set the value of voicemail.srv_ip
#     - adjust the value of voicemail.srv_port
#
# *** To enhance accounting execute:
#     - enable mysql
#     - define WITH_ACCDB
#     - add following columns to database
#!ifdef ACCDB_COMMENT
  ALTER TABLE acc ADD COLUMN src_user VARCHAR(64) NOT NULL DEFAULT '';
  ALTER TABLE acc ADD COLUMN src_domain VARCHAR(128) NOT NULL DEFAULT '';
  ALTER TABLE acc ADD COLUMN src_ip varchar(64) NOT NULL default '';
  ALTER TABLE acc ADD COLUMN dst_ouser VARCHAR(64) NOT NULL DEFAULT '';
  ALTER TABLE acc ADD COLUMN dst_user VARCHAR(64) NOT NULL DEFAULT '';
  ALTER TABLE acc ADD COLUMN dst_domain VARCHAR(128) NOT NULL DEFAULT '';
  ALTER TABLE missed_calls ADD COLUMN src_user VARCHAR(64) NOT NULL DEFAULT '';
  ALTER TABLE missed_calls ADD COLUMN src_domain VARCHAR(128) NOT NULL DEFAULT '';
  ALTER TABLE missed_calls ADD COLUMN src_ip varchar(64) NOT NULL default '';
  ALTER TABLE missed_calls ADD COLUMN dst_ouser VARCHAR(64) NOT NULL DEFAULT '';
  ALTER TABLE missed_calls ADD COLUMN dst_user VARCHAR(64) NOT NULL DEFAULT '';
  ALTER TABLE missed_calls ADD COLUMN dst_domain VARCHAR(128) NOT NULL DEFAULT '';
#!endif

####### Include Local Config If Exists #########
import_file "kamailio-local.cfg" 

####### Defined Values #########

# *** Value defines - IDs used later in config
#!ifdef WITH_MYSQL
# - database URL - used to connect to database server by modules such
#       as: auth_db, acc, usrloc, a.s.o.
#!ifndef DBURL
#!define DBURL "mysql://kamailiou:kamailiou1234@localhost/kamailio" 
#!endif
#!endif
#!ifdef WITH_MULTIDOMAIN
# - the value for 'use_domain' parameters
#!define MULTIDOMAIN 1
#!else
#!define MULTIDOMAIN 0
#!endif

# - flags
#   FLT_ - per transaction (message) flags
#    FLB_ - per branch flags
#!define FLT_ACC 1
#!define FLT_ACCMISSED 2
#!define FLT_ACCFAILED 3
#!define FLT_NATS 5

#!define FLB_NATB 6
#!define FLB_NATSIPPING 7

#!substdef "!MY_IP_ADDR!165.22.15.111!g" 
#!substdef "!MY_DOMAIN!callcenter.siarum.com!g" 
#!substdef "!MY_WS_PORT!8081!g" 
#!substdef "!MY_WSS_PORT!4443!g" 
#!substdef "!MY_MSRP_PORT!9080!g" 
#!substdef "!MY_WS_ADDR!tcp:MY_IP_ADDR:MY_WS_PORT!g" 
#!substdef "!MY_WSS_ADDR!tls:MY_IP_ADDR:MY_WSS_PORT!g" 
#!substdef "!MY_MSRP_ADDR!tls:MY_IP_ADDR:MY_MSRP_PORT!g" 
#!substdef "!MSRP_MIN_EXPIRES!1800!g" 
#!substdef "!MSRP_MAX_EXPIRES!3600!g" 

#!define WITH_TLS
#!define WITH_WEBSOCKETS
#!define WITH_MSRP

####### Global Parameters #########

### LOG Levels: 3=DBG, 2=INFO, 1=NOTICE, 0=WARN, -1=ERR
#!ifdef WITH_DEBUG
debug=4
log_stderror=no
#!else
debug=2
log_stderror=no
#!endif

memdbg=5
memlog=5

log_facility=LOG_LOCAL0

fork=yes
children=4

/* uncomment the next line to disable TCP (default on) */
#disable_tcp=yes

/* uncomment the next line to disable the auto discovery of local aliases
   based on reverse DNS on IPs (default on) */
#auto_aliases=no

/* add local domain aliases */
alias="callcenter.siarum.com" 
alias="165.22.15.111"

/* uncomment and configure the following line if you want Kamailio to 
   bind on a specific interface/port/proto (default bind on all available) */
listen=udp:165.22.15.111:5060
listen=udp:callcenter.siarum.com:5060
/* port to listen to
 * - can be specified more than once if needed to listen on many ports */
port=5060


#!ifdef WITH_TLS
enable_tls=yes
#!endif

listen=MY_IP_ADDR
#!ifdef WITH_WEBSOCKETS
listen=MY_WS_ADDR
#!ifdef WITH_TLS
listen=MY_WSS_ADDR
#!endif
#!endif
#!ifdef WITH_MSRP
listen=MY_MSRP_ADDR
#!endif
listen=tls:MY_IP_ADDR:5061




tcp_connection_lifetime=3604
tcp_accept_no_cl=yes
tcp_rd_buf_size=16384

# life time of TCP connection when there is no traffic
# - a bit higher than registration expires to cope with UA behind NAT
#tcp_connection_lifetime=3605

####### Custom Parameters #########

# These parameters can be modified runtime via RPC interface
# - see the documentation of 'cfg_rpc' module.
#
# Format: group.id = value 'desc' description
# Access: $sel(cfg_get.group.id) or @cfg_get.group.id
#

#!ifdef WITH_PSTN
# PSTN GW Routing
#
# - pstn.gw_ip: valid IP or hostname as string value, example:
# pstn.gw_ip = "10.0.0.101" desc "My PSTN GW Address" 
#
# - by default is empty to avoid misrouting
pstn.gw_ip = "" desc "tos.cloud.goautodial.com GW Address" 
pstn.gw_port = "" desc "PSTN GW Port" 
#!endif

#!ifdef WITH_VOICEMAIL
# VoiceMail Routing on offline, busy or no answer
#
# - by default Voicemail server IP is empty to avoid misrouting
voicemail.srv_ip = "" desc "VoiceMail IP Address" 
voicemail.srv_port = "5060" desc "VoiceMail Port" 
#!endif

# don't advertise server headers
server_signature=no
sip_warning=0

####### Modules Section ########

# set paths to location of modules (to sources or installation folders)
#!ifdef WITH_SRCPATH
mpath="modules/" 
#!else
mpath="/usr/lib64/kamailio/modules/" 
#mpath="/usr/lib/x86_64-linux-gnu/kamailio/modules/" 
#!endif

#!ifdef WITH_MYSQL
loadmodule "db_mysql.so" 
#!endif

#loadmodule "topoh.so" 
#loadmodule "mi_fifo.so" 
loadmodule "jsonrpcs.so" 
loadmodule "kex.so" 
loadmodule "corex.so" 
loadmodule "tm.so" 
loadmodule "tmx.so" 
loadmodule "sl.so" 
loadmodule "rr.so" 
loadmodule "pv.so" 
loadmodule "maxfwd.so" 
loadmodule "usrloc.so" 
loadmodule "registrar.so" 
loadmodule "textops.so" 
loadmodule "siputils.so" 
loadmodule "xlog.so" 
loadmodule "sanity.so" 
loadmodule "ctl.so" 
loadmodule "cfg_rpc.so" 
loadmodule "acc.so" 

#!ifdef WITH_AUTH
loadmodule "auth.so" 
loadmodule "auth_db.so" 
#!ifdef WITH_IPAUTH
loadmodule "permissions.so" 
#!endif
#!endif

#!ifdef WITH_ALIASDB
loadmodule "alias_db.so" 
#!endif

#!ifdef WITH_SPEEDDIAL
loadmodule "speeddial.so" 
#!endif

#!ifdef WITH_MULTIDOMAIN
loadmodule "domain.so" 
#!endif

#!ifdef WITH_PRESENCE
loadmodule "presence.so" 
loadmodule "presence_xml.so" 
#!endif

#!ifdef WITH_NAT
loadmodule "nathelper.so" 
loadmodule "rtpengine.so" 
#loadmodule "rtpproxy.so" 
#!endif

#!ifdef WITH_TLS
loadmodule "tls.so" 
#!endif

#!ifdef WITH_MSRP
loadmodule "msrp.so" 
#loadmodule "htable.so" 
loadmodule "cfgutils.so" 
#!endif

#!ifdef WITH_WEBSOCKETS
loadmodule "xhttp.so" 
loadmodule "websocket.so" 
loadmodule "sdpops.so" 
loadmodule "textopsx.so" 
loadmodule "dialog.so" 
loadmodule "sst.so" 
#!endif

#!ifdef WITH_ANTIFLOOD
loadmodule "htable.so" 
loadmodule "pike.so" 
#!endif

#!ifdef WITH_XMLRPC
loadmodule "xmlrpc.so" 
#!endif

#!ifdef WITH_DEBUG
loadmodule "debugger.so" 
#!endif

# ----------------- setting module-specific parameters ---------------

# ---- topoh params -----
#modparam("topoh", "mask_key", "Gu3ssWh@T1tS2016")
#modparam("topoh", "mask_ip", "10.0.0.1")
#modparam("topoh", "mask_callid", 1)

# ----- mi_fifo params -----
#modparam("mi_fifo", "fifo_name", "/var/run/kamailio/kamailio_fifo")

# ----- jsonrpcs params -----
modparam("jsonrpcs", "pretty_format", 1)
/* set the path to RPC fifo control file */
modparam("jsonrpcs", "fifo_name", "/var/run/kamailio/kamailio_rpc.fifo")
/* set the path to RPC unix socket control file */
modparam("jsonrpcs", "dgram_socket", "/var/run/kamailio/kamailio_rpc.sock")

# ----- tm params -----
# auto-discard branches from previous serial forking leg
modparam("tm", "failure_reply_mode", 3)
# default retransmission timeout: 30sec
modparam("tm", "fr_timer", 30000)
# default invite retransmission timeout after 1xx: 120sec
modparam("tm", "fr_inv_timer", 120000)

# ----- rr params -----
# set next param to 1 to add value to ;lr param (helps with some UAs)
modparam("rr", "enable_full_lr", 0)
# do not append from tag to the RR (no need for this script)
modparam("rr", "append_fromtag", 0)

# ----- registrar params -----
modparam("registrar", "method_filtering", 1)
/* uncomment the next line to disable parallel forking via location */
modparam("registrar", "append_branches", 0)
/* uncomment the next line not to allow more than 100 contacts per AOR */
modparam("registrar", "max_contacts", 100)
# max value for expires of registrations
modparam("registrar", "max_expires", 3600)
# set it to 1 to enable GRUU
modparam("registrar", "gruu_enabled", 0)

# ----- acc params -----
/* what special events should be accounted ? */
modparam("acc", "early_media", 0)
modparam("acc", "report_ack", 0)
modparam("acc", "report_cancels", 0)
/* by default ww do not adjust the direct of the sequential requests.
   if you enable this parameter, be sure the enable "append_fromtag" 
   in "rr" module */
modparam("acc", "detect_direction", 0)
/* account triggers (flags) */
modparam("acc", "log_flag", FLT_ACC)
modparam("acc", "log_missed_flag", FLT_ACCMISSED)
modparam("acc", "log_extra", 
    "src_user=$fU;src_domain=$fd;src_ip=$si;" 
    "dst_ouser=$tU;dst_user=$rU;dst_domain=$rd")
modparam("acc", "failed_transaction_flag", FLT_ACCFAILED)
/* enhanced DB accounting */
#!ifdef WITH_ACCDB
modparam("acc", "db_flag", FLT_ACC)
modparam("acc", "db_missed_flag", FLT_ACCMISSED)
modparam("acc", "db_url", DBURL)
modparam("acc", "db_extra",
    "src_user=$fU;src_domain=$fd;src_ip=$si;" 
    "dst_ouser=$tU;dst_user=$rU;dst_domain=$rd")
#!endif

# ----- usrloc params -----
/* enable DB persistency for location entries */
#!ifdef WITH_USRLOCDB
modparam("usrloc", "db_url", DBURL)
modparam("usrloc", "db_mode", 1)
modparam("usrloc", "use_domain", MULTIDOMAIN)
modparam("usrloc", "timer_interval", 60)
modparam("usrloc", "timer_procs", 4)
#!endif

# ----- auth_db params -----
#!ifdef WITH_AUTH
modparam("auth_db", "db_url", DBURL)
modparam("auth_db", "calculate_ha1", 0)
modparam("auth_db", "password_column", "ha1")
modparam("auth_db", "load_credentials", "")
modparam("auth_db", "use_domain", MULTIDOMAIN)

modparam("auth", "nonce_count", 1) # enable nonce_count support
modparam("auth", "qop", "auth")    # enable qop=auth
modparam("auth", "nonce_expire", 60)
modparam("auth", "nonce_auth_max_drift", 2)

# For REGISTER requests we hash the Request-URI, Call-ID, and source IP of the
# request into the nonce string. This ensures that the generated credentials
# cannot be used with another registrar, user agent with another source IP
# address or Call-ID. Note that user agents that change Call-ID with every
# REGISTER message will not be able to register if you enable this.
modparam("auth", "auth_checks_register", 11)

# For dialog-establishing requests (such as the original INVITE, OPTIONS, etc)
# we hash the Request-URI and source IP. Hashing Call-ID and From tags takes
# some extra precaution, because these checks could render some UA unusable.
modparam("auth", "auth_checks_no_dlg", 9)

# For mid-dialog requests, such as re-INVITE, we can hash source IP and
# Request-URI just like in the previous case. In addition to that we can hash
# Call-ID and From tag because these are fixed within a dialog and are
# guaranteed not to change. This settings effectively restrict the usage of
# generated credentials to a single user agent within a single dialog.
modparam("auth", "auth_checks_in_dlg", 15)

# ----- permissions params -----
#!ifdef WITH_IPAUTH
modparam("permissions", "db_url", DBURL)
modparam("permissions", "db_mode", 1)
#!endif

#!endif

# ----- alias_db params -----
#!ifdef WITH_ALIASDB
modparam("alias_db", "db_url", DBURL)
modparam("alias_db", "use_domain", MULTIDOMAIN)
#!endif

# ----- speeddial params -----
#!ifdef WITH_SPEEDDIAL
modparam("speeddial", "db_url", DBURL)
modparam("speeddial", "use_domain", MULTIDOMAIN)
#!endif

# ----- domain params -----
#!ifdef WITH_MULTIDOMAIN
modparam("domain", "db_url", DBURL)
# register callback to match myself condition with domains list
modparam("domain", "register_myself", 1)
#!endif

#!ifdef WITH_PRESENCE
# ----- presence params -----
modparam("presence", "db_url", DBURL)

# ----- presence_xml params -----
modparam("presence_xml", "db_url", DBURL)
modparam("presence_xml", "force_active", 1)
#!endif

#!ifdef WITH_NAT
# ----- rtpengine params -----
modparam("rtpengine", "rtpengine_sock", "udp:165.22.15.111:5066")
modparam("rtpengine", "rtpengine_disable_tout", 20)
#modparam("rtpengine", "db_url", DBURL)

# ----- nathelper params -----
modparam("nathelper", "natping_interval", 30)
modparam("nathelper", "ping_nated_only", 1)
modparam("nathelper", "sipping_bflag", FLB_NATSIPPING)
modparam("nathelper", "sipping_from", "sip:pinger@kamailio.org")

# params needed for NAT traversal in other modules
modparam("nathelper|registrar", "received_avp", "$avp(RECEIVED)")
modparam("usrloc", "nat_bflag", FLB_NATB)
#!endif

#!ifdef WITH_TLS
# ----- tls params -----
#modparam("tls", "config", "/etc/kamailio/tls.cfg")
modparam("tls", "private_key", "/etc/letsencrypt/live/callcenter.siarum.com/privkey.pem")
modparam("tls", "certificate", "/etc/letsencrypt/live/callcenter.siarum.com/fullchain.pem")
#modparam("tls", "ca_list", "/etc/httpd/certs/essentialSSL/wildcard.goautodial.com.ca-bundle")
#!endif

#!ifdef WITH_WEBSOCKETS
# ----- nathelper params -----
modparam("nathelper|registrar", "received_avp", "$avp(RECEIVED)")
# Note: leaving NAT pings turned off here as nathelper is _only_ being used for
#       WebSocket connections.  NAT pings are not needed as WebSockets have
#       their own keep-alives.
modparam("dialog", "dlg_flag", 10)
modparam("dialog", "track_cseq_updates", 0)
modparam("dialog", "dlg_match_mode", 2)

modparam("dialog", "timeout_avp", "$avp(i:10)")
# Set the sst modules timeout_avp to be the same value
modparam("sst", "timeout_avp", "$avp(i:10)")
modparam("sst", "sst_flag", 11)
#!endif

#!ifdef WITH_MSRP
# ----- htable params -----
modparam("htable", "htable", "msrp=>size=8;autoexpire=MSRP_MAX_EXPIRES;")
#!endif

#!ifdef WITH_ANTIFLOOD
# ----- pike params -----
modparam("pike", "sampling_time_unit", 2)
modparam("pike", "reqs_density_per_unit", 32)
modparam("pike", "remove_latency", 4)

# ----- htable params -----
# ip ban htable with autoexpire after 5 minutes
# modparam("htable", "htable", "ipban=>size=8;autoexpire=300;")
#!endif

#!ifdef WITH_XMLRPC
# ----- xmlrpc params -----
modparam("xmlrpc", "route", "XMLRPC");
modparam("xmlrpc", "url_match", "^/RPC")
#!endif

#!ifdef WITH_DEBUG
# ----- debugger params -----
modparam("debugger", "cfgtrace", 1)
modparam("debugger", "log_level_name", "exec")
#!endif

####### Routing Logic ########

# Main SIP request routing logic
# - processing of any incoming SIP request starts with this route
# - note: this is the same as route { ... }
request_route {

    # per request initial checks
    route(REQINIT);

#!ifdef WITH_WEBSOCKETS
    if (nat_uac_test(64)) {
        # Do NAT traversal stuff for requests from a WebSocket
        # connection - even if it is not behind a NAT!
        # This won't be needed in the future if Kamailio and the
        # WebSocket client support Outbound and Path.
        force_rport();
        if (is_method("REGISTER")) {
            fix_nated_register();
        } else {
            if (!add_contact_alias()) {
                xlog("L_ERR", "Error aliasing contact <$ct>\n");
                sl_send_reply("400", "Bad Request");
                exit;
            }
        }
    }
#!endif

    # NAT detection
    route(NATDETECT);

    # CANCEL processing
    if (is_method("CANCEL")) {
        if (t_check_trans()) {
            route(RELAY);
        }
        exit;
    }

    # handle requests within SIP dialogs
    route(WITHINDLG);

    ### only initial requests (no To tag)

    # handle retransmissions
    if(t_precheck_trans()) {
        t_check_trans();
        exit;
    }
    t_check_trans();

    # authentication
    route(AUTH);

    # record routing for dialog forming requests (in case they are routed)
    # - remove preloaded route headers
    remove_hf("Route");
    if (is_method("INVITE|SUBSCRIBE"))
        record_route();

    # account only INVITEs
    if (is_method("INVITE")) {
        setflag(FLT_ACC); # do accounting
        setflag(10); # set the dialog flag
        setflag(11); # Set the sst flag
    }

    if (is_method("UPDATE")) {
        setflag(FLT_ACC); # do accounting
        setflag(10); # set the dialog flag
        setflag(11); # Set the sst flag
    }

    # dispatch requests to foreign domains
    route(SIPOUT);

    ### requests for my local domains

    # handle presence related requests
    route(PRESENCE);

    # handle registrations
    route(REGISTRAR);

    if ($rU==$null) {
        # request with no Username in RURI
        sl_send_reply("484","Address Incomplete");
        exit;
    }

    # dispatch destinations to PSTN
    route(PSTN);

    # user location service
    route(LOCATION);
    route(RELAY);
}

# Wrapper for relaying requests
route[RELAY] {
    # enable additional event routes for forwarded requests
    # - serial forking, RTP relaying handling, a.s.o.
    if (is_method("INVITE|BYE|SUBSCRIBE|UPDATE")) {
        if(!t_is_set("branch_route")) t_on_branch("MANAGE_BRANCH");
    }
    if (is_method("INVITE|SUBSCRIBE|UPDATE")) {
        if(!t_is_set("onreply_route")) t_on_reply("MANAGE_REPLY");
    }
    if (is_method("INVITE")) {
        dlg_manage();
        route(SETUP_BY_TRANSPORT);
        if(!t_is_set("failure_route")) t_on_failure("MANAGE_FAILURE");
    }
    if (!t_relay()) {
        sl_reply_error();
    }
    exit;
}

route[SETUP_BY_TRANSPORT] {
    if ($ru =~ "transport=ws") {
        xlog("L_INFO", "Request going to WS");
        if(sdp_with_transport("RTP/SAVPF")) {
            xlog("L_INFO", "RTP/SAVPF detected");
            rtpengine_manage("force trust-address replace-origin replace-session-connection ICE=force");
            t_on_reply("REPLY_WS_TO_WS");
            return;
        }
        rtpengine_manage("trust-address replace-origin replace-session-connection ICE=force RTP/SAVPF rtcp-mux-offer rtcp-mux-accept SDES-off");
        t_on_reply("REPLY_FROM_WS");
    }
    else if ($proto =~ "ws") {
        xlog("L_INFO", "Request coming from WS");
        rtpengine_manage("RTP/AVP");
        t_on_reply("REPLY_TO_WS");
    }
    else {
        xlog("L_INFO", "This is a classic phone call");
        rtpengine_manage("trust-address replace-origin replace-session-connection RTP/AVP");
        t_on_reply("MANAGE_CLASSIC_REPLY");
    }
}

onreply_route[REPLY_WS_TO_WS] {
    xlog("L_INFO", "WS to WS");
    if(status=~"[12][0-9][0-9]") {
        rtpengine_manage("force trust-address replace-origin replace-session-connection ICE=force");
        route(NATMANAGE);
    }
}

onreply_route[REPLY_FROM_WS] {
    xlog("L_INFO", "Reply from webrtc client: $rs");
    if(status=~"[12][0-9][0-9]") {
        rtpengine_manage("trust-address replace-origin replace-session-connection ICE=remove RTP/AVP rtcp-mux-offer rtcp-mux-accept SDES-off");
        route(NATMANAGE);
    }
}

onreply_route[REPLY_TO_WS] {
    xlog("L_INFO", "Reply from softphone: $rs");

    if (t_check_status("183")) {
        change_reply_status("180", "Ringing");
        remove_body();
        exit;
    }

    if(!(status=~"[12][0-9][0-9]"))
        return;

    rtpengine_manage("froc+SP");
    route(NATMANAGE);
}

onreply_route[MANAGE_CLASSIC_REPLY] {
    xlog("L_INFO", "Boring reply from softphone: $rs");

    if(status=~"[12][0-9][0-9]") {
        xlog("L_INFO", "rtpengine_manage - trust-address replace-origin replace-session-connection RTP/AVP");
        rtpengine_manage("trust-address replace-origin replace-session-connection RTP/AVP");    
                route(NATMANAGE);
    }
}

# Per SIP request initial checks
route[REQINIT] {
#!ifdef WITH_ANTIFLOOD
    # flood dection from same IP and traffic ban for a while
    # be sure you exclude checking trusted peers, such as pstn gateways
    # - local host excluded (e.g., loop to self)
    if(src_ip!=myself) {
        if($sht(ipban=>$si)!=$null) {
            # ip is already blocked
            xdbg("request from blocked IP - $rm from $fu (IP:$si:$sp)\n");
            exit;
        }
        if (!pike_check_req()) {
            xlog("L_ALERT","ALERT: pike blocking $rm from $fu (IP:$si:$sp)\n");
            $sht(ipban=>$si) = 1;
            exit;
        }
    }
    if($ua =~ "friendly-scanner") {
        sl_send_reply("200", "OK");
        exit;
    }
#!endif

    if (!mf_process_maxfwd_header("10")) {
        sl_send_reply("483","Too Many Hops");
        exit;
    }

    if(is_method("OPTIONS") && uri==myself && $rU==$null) {
        sl_send_reply("200","Keepalive");
        exit;
    }

    if(!sanity_check("1511", "7")) {
        xlog("Malformed SIP message from $si:$sp\n");
        exit;
    }
}

# Handle requests within SIP dialogs
route[WITHINDLG] {
    if (!has_totag()) return;

    # sequential request withing a dialog should
    # take the path determined by record-routing
    if (loose_route()) {
#!ifdef WITH_WEBSOCKETS
        if ($du == "") {
            if (!handle_ruri_alias()) {
                xlog("L_ERR", "Bad alias <$ru>\n");
                sl_send_reply("400", "Bad Request");
                exit;
            }
        }
#!endif
        route(DLGURI);
        if (is_method("BYE")) {
            setflag(FLT_ACC); # do accounting ...
            setflag(FLT_ACCFAILED); # ... even if the transaction fails
        }
        else if ( is_method("ACK") ) {
            # ACK is forwarded statelessy
            route(NATMANAGE);
        }
        else if ( is_method("NOTIFY") ) {
            # Add Record-Route for in-dialog NOTIFY as per RFC 6665.
            record_route();
        }
        route(RELAY);
        exit;
    }

    if (is_method("SUBSCRIBE") && uri == myself) {
        # in-dialog subscribe requests
        route(PRESENCE);
        exit;
    }
    if ( is_method("ACK") ) {
        if ( t_check_trans() ) {
            # no loose-route, but stateful ACK;
            # must be an ACK after a 487
            # or e.g. 404 from upstream server
            route(RELAY);
            exit;
        } else {
            # ACK without matching transaction ... ignore and discard
            exit;
        }
    }
    sl_send_reply("404","Not here");
    exit;
}

# Handle SIP registrations
route[REGISTRAR] {
    if (!is_method("REGISTER")) return;

    if(isflagset(FLT_NATS)) {
        setbflag(FLB_NATB);
#!ifdef WITH_NATSIPPING
        # do SIP NAT pinging
        setbflag(FLB_NATSIPPING);
#!endif
    }
    if (!save("location", "0x04"))
        sl_reply_error();
    exit;
}

# User location service
route[LOCATION] {

#!ifdef WITH_SPEEDDIAL
    # search for short dialing - 2-digit extension
    if($rU=~"^[0-9][0-9]$")
        if(sd_lookup("speed_dial"))
            route(SIPOUT);
#!endif

#!ifdef WITH_ALIASDB
    # search in DB-based aliases
    if(alias_db_lookup("dbaliases"))
        route(SIPOUT);
#!endif

    $avp(oexten) = $rU;
    if (!lookup("location")) {
        $var(rc) = $rc;
        route(TOVOICEMAIL);
        t_newtran();
        switch ($var(rc)) {
            case -1:
            case -3:
                send_reply("404", "Not Found");
                exit;
            case -2:
                send_reply("405", "Method Not Allowed");
                exit;
        }
    }

    # when routing via usrloc, log the missed calls also
    if (is_method("INVITE")) {
        setflag(FLT_ACCMISSED);
    }

    # t_on_failure("UA_FAILURE");
    route(RELAY);
    exit;
}

# Presence server processing
route[PRESENCE] {
    if(!is_method("PUBLISH|SUBSCRIBE"))
        return;

    if(is_method("SUBSCRIBE") && $hdr(Event)=="message-summary") {
        route(TOVOICEMAIL);
        # returns here if no voicemail server is configured
        sl_send_reply("404", "No voicemail service");
        exit;
    }

#!ifdef WITH_PRESENCE
    if (!t_newtran()) {
        sl_reply_error();
        exit;
    }

    if(is_method("PUBLISH")) {
        handle_publish();
        t_release();
    } else if(is_method("SUBSCRIBE")) {
        handle_subscribe();
        t_release();
    }
    exit;
#!endif

    # if presence enabled, this part will not be executed
    if (is_method("PUBLISH") || $rU==$null) {
        sl_send_reply("404", "Not here");
        exit;
    }
    return;
}

# IP authorization and user uthentication
route[AUTH] {
#!ifdef WITH_AUTH

#!ifdef WITH_IPAUTH
    if((!is_method("REGISTER")) && allow_source_address()) {
        # source IP allowed
        return;
    }
#!endif

    if (is_method("REGISTER") || from_uri==myself)
    {
        # authenticate requests
        if (!auth_check("$fd", "subscriber", "1")) {
            auth_challenge("$fd", "0");
            exit;
        }        
        # user authenticated - remove auth header
        if(!is_method("REGISTER|PUBLISH"))
            consume_credentials();
    }
    # if caller is not local subscriber, then check if it calls
    # a local destination, otherwise deny, not an open relay here
    if (from_uri!=myself && uri!=myself) {
        sl_send_reply("403","Not relaying");
        exit;
    }

#!endif
    return;
}

# Caller NAT detection
route[NATDETECT] {
#!ifdef WITH_NAT
    force_rport();
    if (nat_uac_test("19")) {
        if (is_method("REGISTER")) {
            fix_nated_register();
        } else {
            if(is_first_hop())
                set_contact_alias();
        }
        setflag(FLT_NATS);
    }
#!endif
    return;
}

# RTPengine control and singaling updates for NAT traversal
route[NATMANAGE] {
#!ifdef WITH_NAT
    if (is_request()) {
        if(has_totag()) {
            if(check_route_param("nat=yes")) {
                setbflag(FLB_NATB);
            }
        }
    }
    if (!(isflagset(FLT_NATS) || isbflagset(FLB_NATB)))
        return;

    if (is_request()) {
        if (!has_totag()) {
            if(t_is_branch_route()) {
                add_rr_param(";nat=yes");
            }
        }
    }
    if (is_reply()) {
        if(isbflagset(FLB_NATB)) {
            if(is_first_hop())
                set_contact_alias();
        }
    }
#!endif
    return;
}

# URI update for dialog requests
route[DLGURI] {
#!ifdef WITH_NAT
    if(!isdsturiset()) {
        handle_ruri_alias();
    }
#!endif
    return;
}

# Routing to foreign domains
route[SIPOUT] {
    if (uri==myself) return;

    append_hf("P-hint: outbound\r\n");
    route(RELAY);
    exit;
}

# PSTN GW routing
route[PSTN] {
#!ifdef WITH_PSTN
    # check if PSTN GW IP is defined
    if (strempty($sel(cfg_get.pstn.gw_ip))) {
        xlog("SCRIPT: PSTN rotuing enabled but pstn.gw_ip not defined\n");
        return;
    }

    # route to PSTN dialed numbers starting with '+' or '00'
    #     (international format)
    # - update the condition to match your dialing rules for PSTN routing
    if(!($rU=~"^(\+|00)[1-9][0-9]{3,20}$"))
        return;

    # only local users allowed to call
    if(from_uri!=myself) {
        sl_send_reply("403", "Not Allowed");
        exit;
    }

    if (strempty($sel(cfg_get.pstn.gw_port))) {
        $ru = "sip:" + $rU + "@" + $sel(cfg_get.pstn.gw_ip);
    } else {
        $ru = "sip:" + $rU + "@" + $sel(cfg_get.pstn.gw_ip) + ":" 
                    + $sel(cfg_get.pstn.gw_port);
    }

    route(RELAY);
    exit;
#!endif

    return;
}

# XMLRPC routing
#!ifdef WITH_XMLRPC
route[XMLRPC] {
    # allow XMLRPC from localhost
    if ((method=="POST" || method=="GET")
            && (src_ip==165.22.15.111)) {
        # close connection only for xmlrpclib user agents (there is a bug in
        # xmlrpclib: it waits for EOF before interpreting the response).
        if ($hdr(User-Agent) =~ "xmlrpclib")
            set_reply_close();
        set_reply_no_connect();
        dispatch_rpc();
        exit;
    }
    send_reply("403", "Forbidden");
    exit;
}
#!endif

# Routing to voicemail server
route[TOVOICEMAIL] {
#!ifdef WITH_VOICEMAIL
    if(!is_method("INVITE|SUBSCRIBE"))
        return;

    # check if VoiceMail server IP is defined
    if (strempty($sel(cfg_get.voicemail.srv_ip))) {
        xlog("SCRIPT: VoiceMail rotuing enabled but IP not defined\n");
        return;
    }
    if(is_method("INVITE")) {
        if($avp(oexten)==$null)
            return;
        $ru = "sip:" + $avp(oexten) + "@" + $sel(cfg_get.voicemail.srv_ip)
                + ":" + $sel(cfg_get.voicemail.srv_port);
    } else {
        if($rU==$null)
            return;
        $ru = "sip:" + $rU + "@" + $sel(cfg_get.voicemail.srv_ip)
                + ":" + $sel(cfg_get.voicemail.srv_port);
    }
    route(RELAY);
    exit;
#!endif

    return;
}

# Manage outgoing branches
branch_route[MANAGE_BRANCH] {
    xdbg("new branch [$T_branch_idx] to $ru\n");
    route(NATMANAGE);
}

# Manage incoming replies
onreply_route[MANAGE_REPLY] {
    xdbg("incoming reply\n");
    if(status=~"[12][0-9][0-9]")
        route(NATMANAGE);
}

# Manage failure routing cases
failure_route[MANAGE_FAILURE] {
    route(NATMANAGE);

    if (t_is_canceled()) {
        exit;
    }

#!ifdef WITH_BLOCK3XX
    # block call redirect based on 3xx replies.
    if (t_check_status("3[0-9][0-9]")) {
        t_reply("404","Not found");
        exit;
    }
#!endif

#!ifdef WITH_VOICEMAIL
    # serial forking
    # - route to voicemail on busy or no answer (timeout)
    if (t_check_status("486|408")) {
        $du = $null;
        route(TOVOICEMAIL);
        exit;
    }
#!endif
}

#!ifdef WITH_WEBSOCKETS
onreply_route {
    if ((($Rp == MY_WS_PORT || $Rp == MY_WSS_PORT)
        && !(proto == WS || proto == WSS)) || $Rp == MY_MSRP_PORT) {
        xlog("L_WARN", "SIP response received on $Rp\n");
        drop;
        exit;
    }

    if (nat_uac_test(64)) {
        # Do NAT traversal stuff for replies to a WebSocket connection
        # - even if it is not behind a NAT!
        # This won't be needed in the future if Kamailio and the
        # WebSocket client support Outbound and Path.
        add_contact_alias();
    }
}

event_route[xhttp:request] {
    set_reply_close();
    set_reply_no_connect();

    if ($Rp != MY_WS_PORT
#!ifdef WITH_TLS
        && $Rp != MY_WSS_PORT
#!endif
    ) {
        xlog("L_WARN", "HTTP request received on $Rp\n");
        xhttp_reply("403", "Forbidden", "", "");
        exit;
    }

    xlog("L_DBG", "HTTP Request Received\n");

    if ($hdr(Upgrade)=~"websocket" 
            && $hdr(Connection)=~"Upgrade" 
            && $rm=~"GET") {

        # Validate Host - make sure the client is using the correct
        # alias for WebSockets
        # Sasa: commented out, see http://sip-router.1086192.n5.nabble.com/Testing-the-Websocket-module-with-sipml5-org-td65069.html
        #if ($hdr(Host) == $null || !is_myself("sip:" + $hdr(Host))) {
        #    xlog("L_WARN", "Bad host $hdr(Host)\n");
        #    xhttp_reply("403", "Forbidden", "", "");
        #    exit;
        #}

        # Optional... validate Origin - make sure the client is from an
        # authorised website.  For example,
        #
        # if ($hdr(Origin) != "http://communicator.MY_DOMAIN" 
        #     && $hdr(Origin) != "https://communicator.MY_DOMAIN") {
        #    xlog("L_WARN", "Unauthorised client $hdr(Origin)\n");
        #    xhttp_reply("403", "Forbidden", "", "");
        #    exit;
        # }

        # Optional... perform HTTP authentication

        # ws_handle_handshake() exits (no further configuration file
        # processing of the request) when complete.
        if (ws_handle_handshake())
        {
            # Optional... cache some information about the
            # successful connection
            exit;
        }
    }

    xhttp_reply("404", "Not Found", "", "");
}

event_route[websocket:closed] {
    xlog("L_INFO", "WebSocket connection from $si:$sp has closed\n");
}

failure_route[UA_FAILURE] {
    xlog("L_INFO", "Triggered UA_FAILURE\n");
    if (t_check_status("488") && sdp_content()) {
        if (sdp_get_line_startswith("$avp(mline)", "m=")) {
            if ($avp(mline) =~ "SAVPF") {
                $avp(rtpengine_offer_flags) = "froc-sp";
                $avp(rtpengine_answer_flags) = "froc+SP";
            } else {
                $avp(rtpengine_offer_flags) = "froc+SP";
                $avp(rtpengine_answer_flags) = "froc-sp";
            }
        }
        append_branch();
        rtpengine_offer($avp(rtpengine_offer_flags));
        t_on_reply("RTPPROXY_REPLY");
        route(RELAY);
    }
}

onreply_route[RTPPROXY_REPLY] {
    xlog("L_INFO", "Triggered RTPPROXY_REPLY\n");
    if (status =~ "18[03]") {
        change_reply_status(180, "Ringing");
        remove_body();
    } else if (status =~ "2[0-9][0-9]" && sdp_content()) {
        rtpengine_answer($avp(rtpengine_answer_flags));
    }
}
#!endif

#!ifdef WITH_MSRP
event_route[msrp:frame-in] {
    msrp_reply_flags("1");

    if ((($Rp == MY_WS_PORT || $Rp == MY_WSS_PORT)
        && !(proto == WS || proto == WSS)) && $Rp != MY_MSRP_PORT) {
        xlog("L_WARN", "MSRP request received on $Rp\n");
        msrp_reply("403", "Action-not-allowed");
        exit;
    }

    if (msrp_is_reply()) {
        msrp_relay();
    } else if($msrp(method)=="AUTH") {
        if($msrp(nexthops)>0) {
            msrp_relay();
            exit;
        }

        if (!www_authenticate("MY_DOMAIN", "subscriber",
                    "$msrp(method)")) {
            if (auth_get_www_authenticate("MY_DOMAIN", "1",
                            "$var(wauth)")) {
                msrp_reply("401", "Unauthorized",
                            "$var(wauth)");
            } else {
                msrp_reply("500", "Server Error");
            }
            exit;
        }

        if ($hdr(Expires) != $null) {
            $var(expires) = (int) $hdr(Expires);
            if ($var(expires) < MSRP_MIN_EXPIRES) {
                msrp_reply("423", "Interval Out-of-Bounds",
                    "Min-Expires: MSRP_MIN_EXPIRES\r\n");
                exit;
            } else if ($var(expires) > MSRP_MAX_EXPIRES) {
                msrp_reply("423", "Interval Out-of-Bounds",
                    "Max-Expires: MSRP_MAX_EXPIRES\r\n");
                exit;
            }
        } else {
            $var(expires) = MSRP_MAX_EXPIRES;
        }

        $var(cnt) = $var(cnt) + 1;
        pv_printf("$var(sessid)", "s.$(pp).$(var(cnt)).$(RANDOM)");
        $sht(msrp=>$var(sessid)::srcaddr) = $msrp(srcaddr);
        $sht(msrp=>$var(sessid)::srcsock) = $msrp(srcsock);
        $shtex(msrp=>$var(sessid)) = $var(expires) + 5;
        # - Use-Path: the MSRP address for server + session id
        $var(hdrs) = "Use-Path: msrps://MY_IP_ADDR:MY_MSRP_PORT/" 
                    + $var(sessid) + ";tcp\r\n" 
                    + "Expires: " + $var(expires) + "\r\n";
        msrp_reply("200", "OK", "$var(hdrs)");
    } else if ($msrp(method)=="SEND" || $msrp(method)=="REPORT") {
        if ($msrp(nexthops)>1) {
            if ($msrp(method)!="REPORT") {
                msrp_reply("200", "OK");
            }
            msrp_relay();
            exit;
        }
        $var(sessid) = $msrp(sessid);
        if ($sht(msrp=>$var(sessid)::srcaddr) == $null) {
            # one more hop, but we don't have address in htable
            msrp_reply("481", "Session-does-not-exist");
            exit;
        } else if ($msrp(method)!="REPORT") {
            msrp_reply("200", "OK");
        }
        msrp_relay_flags("1");
        msrp_set_dst("$sht(msrp=>$var(sessid)::srcaddr)",
                "$sht(msrp=>$var(sessid)::srcsock)");
        msrp_relay();
    } else {
        msrp_reply("501", "Request-method-not-understood");
    }
}
#!endif

#
# $Id$
#
# Example Kamailio TLS Configuration File
#

# This is the default server domain, settings
# in this domain will be used for all incoming
# connections that do not match any other server
# domain in this configuration file.
#
# We do not enable anything else than TLSv1
# over the public internet. Clients do not have
# to present client certificates by default.
#
[server:default]
method = TLSv1 
verify_certificate = no  
require_certificate = no
private_key = /etc/letsencrypt/live/callcenter.siarum.com/privkey.pem
certificate = /etc/letsencrypt/live/callcenter.siarum.com/fullchain.pem
#ca_list = /etc/letsencrypt/live/callcenter.siarum.com/fullchain.pem
#ca_list = /etc/ssl/certs/ca-bundle.crt
#crl = ./modules/tls/crl.pem

# This is the default client domain, settings
# in this domain will be used for all outgoing
# TLS connections that do not match any other
# client domain in this configuration file.
# We require that servers present valid certificate.
#
[client:default]
verify_certificate = no 
require_certificate = no 

# This is an example server domain for TLS connections
# received from the loopback interface. We allow
# the use of SSLv2 and SSLv3 protocols here, we do
# not require that clients present client certificates
# but if they present it it must be valid. We also use
# a special certificate and CA list for loopback
# interface.
#
#[server:127.0.0.1:5061]
#method = SSLv23
#verify_certificate = yes
#require_certificate = no
#private_key = ./modules/tls/local_key.pem
#certificate = ./modules/tls/local_cert.pem
#verify_depth = 3
#ca_list = local_ca.pem
#crl = local_crl.pem

# Special settings for the iptel.org public SIP
# server. We do not verify the certificate of the
# server because it can be expired. The server
# implements authentication using SSL client
# certificates so configure the client certificate
# that was given to use by iptel.org staff here.
#
#[client:195.37.77.101:5061]
#verify_certificate = no
#certificate = ./modules/tls/iptel_client.pem
#private_key = ./modules/tls/iptel_key.pem
#ca_list = ./modules/tls/iptel_ca.pem
#crl = ./modules/tls/iptel_crl.pem

sip-goautodial.conf

[kamailio]
encryption=yes 
disallow=all
allow=opus
allow=ulaw
type=friend
dtmfmode=rfc2833
context=default
qualify=yes
nat=force_rport,comedia
host=callcenter.siarum.com 
insecure=port,invite

kamctlrc

# The Kamailio configuration file for the control tools.
#
# Here you can set variables used in the kamctl and kamdbctl setup
# scripts. Per default all variables here are commented out, the control tools
# will use their internal default values.

## your SIP domain
SIP_DOMAIN=callcenter.siarum.com

## chrooted directory
# $CHROOT_DIR="/path/to/chrooted/directory"

## database type: MYSQL, PGSQL, ORACLE, DB_BERKELEY, DBTEXT, or SQLITE
# by default none is loaded
#
# If you want to setup a database with kamdbctl, you must at least specify
# this parameter.
DBENGINE=MYSQL

## database host
DBHOST=localhost

## database host
DBPORT=3306

## database name (for ORACLE this is TNS name)
DBNAME=kamailio

# database path used by dbtext, db_berkeley or sqlite
# DB_PATH="/usr/local/etc/kamailio/dbtext"

## database read/write user
DBRWUSER="kamailio"

## password for database read/write user
DBRWPW="kamailiorw"

## database read only user
DBROUSER="kamailioro"

## password for database read only user
DBROPW="kamailioro"

## database access host (from where is kamctl used)
# DBACCESSHOST=192.168.0.1

## database super user (for ORACLE this is 'scheme-creator' user)
DBROOTUSER="root"

## password for database super user
## - important: this is insecure, targeting the use only for automatic testing
## - known to work for: mysql
# DBROOTPW="dbrootpw"

## database character set (used by MySQL when creating database)
#CHARSET="latin1"

## user name column
# USERCOL="username"


# SQL definitions
# If you change this definitions here, then you must change them
# in db/schema/entities.xml too.
# FIXME

# FOREVER="2030-05-28 21:32:15"
# DEFAULT_Q="1.0"


# Program to calculate a message-digest fingerprint
# MD5="md5sum"

# awk tool
# AWK="awk"

# gdb tool
# GDB="gdb"

# If you use a system with a grep and egrep that is not 100% gnu grep compatible,
# e.g. solaris, install the gnu grep (ggrep) and specify this below.
#
# grep tool
# GREP="grep"

# egrep tool
# EGREP="egrep"

# sed tool
# SED="sed"

# tail tool
# LAST_LINE="tail -n 1"

# expr tool
# EXPR="expr"


# Describe what additional tables to install. Valid values for the variables
# below are yes/no/ask. With ask (default) it will interactively ask the user
# for an answer, while yes/no allow for automated, unassisted installs.
#

# If to install tables for the modules in the EXTRA_MODULES variable.
# INSTALL_EXTRA_TABLES=ask

# If to install presence related tables.
# INSTALL_PRESENCE_TABLES=ask

# If to install uid modules related tables.
# INSTALL_DBUID_TABLES=ask

# Define what module tables should be installed.
# If you use the postgres database and want to change the installed tables, then you
# must also adjust the STANDARD_TABLES or EXTRA_TABLES variable accordingly in the
# kamdbctl.base script.

# Kamailio standard modules
# STANDARD_MODULES="standard acc lcr domain group permissions registrar usrloc msilo
#                   alias_db uri_db speeddial avpops auth_db pdt dialog dispatcher
#                   dialplan"

# Kamailio extra modules
# EXTRA_MODULES="imc cpl siptrace domainpolicy carrierroute userblacklist htable purple sca"


## type of aliases used: DB - database aliases; UL - usrloc aliases
## - default: none
# ALIASES_TYPE="DB"

## control engine: RPCFIFO
## - default RPCFIFO
CTLENGINE="RPCFIFO"

## path to FIFO file for engine RPCFIFO
RPCFIFOPATH="/var/run/kamailio/kamailio_rpc.fifo"

## check ACL names; default on (1); off (0)
# VERIFY_ACL=1

## ACL names - if VERIFY_ACL is set, only the ACL names from below list
## are accepted
# ACL_GROUPS="local ld int voicemail free-pstn"

## verbose - debug purposes - default '0'
VERBOSE=1

## do (1) or don't (0) store plaintext passwords
## in the subscriber table - default '1'
STORE_PLAINTEXT_PW=0

## Kamailio START Options
## PID file path - default is: /var/run/kamailio/kamailio.pid
PID_FILE=/var/run/kamailio/kamailio.pid

## Extra start options - default is: not set
# example: start Kamailio with 64MB share memory: STARTOPTIONS="-m 64"
# STARTOPTIONS=



Terminal With this Tests (Kamailio seems to start then crash)
systemctl status php-fpm 
systemctl status httpd
systemctl status mariadb
systemctl status mysqld 
systemctl status ngcp-rtpengine
systemctl status asterisk
systemctl status kamailio
systemctl restart kamailio
systemctl disable kamailio
systemctl enable kamailio
systemctl start kamailio
systemctl status kamailio -l
kamailio -c


[root@centos-s-2vcpu-4gb-nyc1-01 ~]# clear
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl status php-fpm
● php-fpm.service - The PHP FastCGI Process Manager
   Loaded: loaded (/usr/lib/systemd/system/php-fpm.service; enabled; vendor preset: disabled)
   Active: active (running) since Sun 2019-06-16 02:32:50 UTC; 9h ago
 Main PID: 3061 (php-fpm)
   Status: "Processes active: 0, idle: 17, Requests: 2275, slow: 0, Traffic: 0req/sec"
   CGroup: /system.slice/php-fpm.service
           ├─ 3061 php-fpm: master process (/etc/php-fpm.conf)
           ├─ 3136 php-fpm: pool www
           ├─ 3138 php-fpm: pool www
           ├─ 3139 php-fpm: pool www
           ├─ 3140 php-fpm: pool www
           ├─ 3141 php-fpm: pool www
           ├─ 3692 php-fpm: pool www
           ├─30243 php-fpm: pool www
           ├─30272 php-fpm: pool www
           ├─30281 php-fpm: pool www
           ├─30282 php-fpm: pool www
           ├─30299 php-fpm: pool www
           ├─30300 php-fpm: pool www
           ├─30301 php-fpm: pool www
           ├─30302 php-fpm: pool www
           ├─30313 php-fpm: pool www
           ├─30314 php-fpm: pool www
           └─30572 php-fpm: pool www

Jun 16 02:32:49 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Starting The PHP FastCGI Process Manager...
Jun 16 02:32:50 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Started The PHP FastCGI Process Manager.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl status httpd
● httpd.service - The Apache HTTP Server
   Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; vendor preset: disabled)
   Active: active (running) since Sun 2019-06-16 02:32:50 UTC; 9h ago
     Docs: man:httpd(8)
           man:apachectl(8)
 Main PID: 3065 (httpd)
   Status: "Total requests: 0; Current requests/sec: 0; Current traffic:   0 B/sec"
   CGroup: /system.slice/httpd.service
           ├─ 3065 /usr/sbin/httpd -DFOREGROUND
           ├─31423 /usr/sbin/httpd -DFOREGROUND
           ├─31556 /usr/sbin/httpd -DFOREGROUND
           ├─31681 /usr/sbin/httpd -DFOREGROUND
           ├─31735 /usr/sbin/httpd -DFOREGROUND
           ├─31809 /usr/sbin/httpd -DFOREGROUND
           ├─31878 /usr/sbin/httpd -DFOREGROUND
           ├─32056 /usr/sbin/httpd -DFOREGROUND
           ├─32064 /usr/sbin/httpd -DFOREGROUND
           ├─32171 /usr/sbin/httpd -DFOREGROUND
           └─32228 /usr/sbin/httpd -DFOREGROUND

Jun 16 02:32:49 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Starting The Apache HTTP Server...
Jun 16 02:32:50 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Started The Apache HTTP Server.
Jun 16 03:21:02 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Reloading The Apache HTTP Server.
Jun 16 03:21:02 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Reloaded The Apache HTTP Server.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl status mariadb
● mariadb.service - MariaDB 10.1.36 database server
   Loaded: loaded (/usr/lib/systemd/system/mariadb.service; enabled; vendor preset: disabled)
  Drop-In: /etc/systemd/system/mariadb.service.d
           └─migrated-from-my.cnf-settings.conf
   Active: active (running) since Sun 2019-06-16 02:32:52 UTC; 9h ago
     Docs: man:mysqld(8)
           https://mariadb.com/kb/en/library/systemd/
 Main PID: 3244 (mysqld)
   Status: "Taking your SQL requests now..."
   CGroup: /system.slice/mariadb.service
           └─3244 /usr/sbin/mysqld

Jun 16 02:32:49 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Starting MariaDB 10.1.36 database server...
Jun 16 02:32:51 centos-s-2vcpu-4gb-nyc1-01 mysqld[3244]: 2019-06-16  2:32:51 139919916591360 [Note] Using unique option prefix 'max_heap_table' is error-prone and can break in the future. Please use the full name 'max_h..._size' instead.
Jun 16 02:32:51 centos-s-2vcpu-4gb-nyc1-01 mysqld[3244]: 2019-06-16  2:32:51 139919916591360 [Note] /usr/sbin/mysqld (mysqld 10.1.36-MariaDB) starting as process 3244 ...
Jun 16 02:32:52 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Started MariaDB 10.1.36 database server.
Hint: Some lines were ellipsized, use -l to show in full.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl status mysqld
● mariadb.service - MariaDB 10.1.36 database server
   Loaded: loaded (/usr/lib/systemd/system/mariadb.service; enabled; vendor preset: disabled)
  Drop-In: /etc/systemd/system/mariadb.service.d
           └─migrated-from-my.cnf-settings.conf
   Active: active (running) since Sun 2019-06-16 02:32:52 UTC; 9h ago
     Docs: man:mysqld(8)
           https://mariadb.com/kb/en/library/systemd/
 Main PID: 3244 (mysqld)
   Status: "Taking your SQL requests now..."
   CGroup: /system.slice/mariadb.service
           └─3244 /usr/sbin/mysqld

Jun 16 02:32:49 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Starting MariaDB 10.1.36 database server...
Jun 16 02:32:51 centos-s-2vcpu-4gb-nyc1-01 mysqld[3244]: 2019-06-16  2:32:51 139919916591360 [Note] Using unique option prefix 'max_heap_table' is error-prone and can break in the future. Please use the full name 'max_h..._size' instead.
Jun 16 02:32:51 centos-s-2vcpu-4gb-nyc1-01 mysqld[3244]: 2019-06-16  2:32:51 139919916591360 [Note] /usr/sbin/mysqld (mysqld 10.1.36-MariaDB) starting as process 3244 ...
Jun 16 02:32:52 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Started MariaDB 10.1.36 database server.
Hint: Some lines were ellipsized, use -l to show in full.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl status ngcp-rtpengine
● ngcp-rtpengine.service - LSB: NGCP rtpengine
   Loaded: loaded (/etc/rc.d/init.d/ngcp-rtpengine; bad; vendor preset: disabled)
   Active: active (running) since Sun 2019-06-16 02:32:53 UTC; 9h ago
     Docs: man:systemd-sysv-generator(8)
 Main PID: 3595 (rtpengine)
   CGroup: /system.slice/ngcp-rtpengine.service
           └─3595 /usr/sbin/rtpengine --no-fallback --config-file=/etc/rtpengine/rtpengine.conf --pidfile=/var/run/rtpengine.pid

Jun 16 02:32:52 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Starting LSB: NGCP rtpengine...
Jun 16 02:32:52 centos-s-2vcpu-4gb-nyc1-01 ngcp-rtpengine[3482]: Loading module for in-kernel packet forwarding
Jun 16 02:32:53 centos-s-2vcpu-4gb-nyc1-01 rtpengine[3581]: INFO: Generating new DTLS certificate
Jun 16 02:32:53 centos-s-2vcpu-4gb-nyc1-01 ngcp-rtpengine[3482]: Starting rtpengine: [  OK  ]
Jun 16 02:32:53 centos-s-2vcpu-4gb-nyc1-01 rtpengine[3595]: INFO: Startup complete, version 6.4.0.0-1.el7
Jun 16 02:32:53 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Started LSB: NGCP rtpengine.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl status asterisk
● asterisk.service - Asterisk PBX and telephony daemon.
   Loaded: loaded (/usr/lib/systemd/system/asterisk.service; enabled; vendor preset: disabled)
   Active: active (running) since Sun 2019-06-16 02:32:49 UTC; 9h ago
 Main PID: 3068 (asterisk)
   CGroup: /system.slice/asterisk.service
           └─3068 /usr/sbin/asterisk -f -C /etc/asterisk/asterisk.conf

Jun 16 12:28:21 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: [Jun 16 12:28:21] NOTICE[5488]: manager.c:3399 authenticate: 209.126.73.112 failed to authenticate as 'admin'
Jun 16 12:29:08 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: [Jun 16 12:29:08] NOTICE[5578]: manager.c:3362 authenticate: 209.126.73.112 tried to authenticate with nonexistent user 'admin'
Jun 16 12:29:08 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: [Jun 16 12:29:08] NOTICE[5578]: manager.c:3399 authenticate: 209.126.73.112 failed to authenticate as 'admin'
Jun 16 12:29:11 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: [Jun 16 12:29:11] NOTICE[3477][C-0000005e]: chan_sip.c:26307 handle_request_invite: Failed to authenticate device ;tag=1834104104
Jun 16 12:29:43 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: [Jun 16 12:29:43] WARNING[3477]: chan_sip.c:4072 retrans_pkt: Retransmission timeout reached on transmission 638053857-1119118654-564395875 for seqno 2 (Critica...Retransmissions
Jun 16 12:29:43 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: Packet timed out after 32000ms with no response
Jun 16 12:29:53 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: [Jun 16 12:29:53] NOTICE[5635]: manager.c:3362 authenticate: 209.126.73.112 tried to authenticate with nonexistent user 'admin'
Jun 16 12:29:53 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: [Jun 16 12:29:53] NOTICE[5635]: manager.c:3399 authenticate: 209.126.73.112 failed to authenticate as 'admin'
Jun 16 12:30:38 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: [Jun 16 12:30:38] NOTICE[5733]: manager.c:3362 authenticate: 209.126.73.112 tried to authenticate with nonexistent user 'admin'
Jun 16 12:30:38 centos-s-2vcpu-4gb-nyc1-01 asterisk[3068]: [Jun 16 12:30:38] NOTICE[5733]: manager.c:3399 authenticate: 209.126.73.112 failed to authenticate as 'admin'
Hint: Some lines were ellipsized, use -l to show in full.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl status kamailio
● kamailio.service - Kamailio (OpenSER) - the Open Source SIP Server
   Loaded: loaded (/usr/lib/systemd/system/kamailio.service; enabled; vendor preset: disabled)
   Active: failed (Result: start-limit) since Sun 2019-06-16 12:22:33 UTC; 8min ago
  Process: 4872 ExecStart=/usr/sbin/kamailio -DD -P /var/run/kamailio/kamailio.pid -f $CFGFILE -m $SHM_MEMORY -M $PKG_MEMORY (code=exited, status=255)
 Main PID: 4872 (code=exited, status=255)

Jun 16 12:22:33 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: kamailio.service: main process exited, code=exited, status=255/n/a
Jun 16 12:22:33 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Unit kamailio.service entered failed state.
Jun 16 12:22:33 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: kamailio.service failed.
Jun 16 12:22:33 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: kamailio.service holdoff time over, scheduling restart.
Jun 16 12:22:33 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Stopped Kamailio (OpenSER) - the Open Source SIP Server.
Jun 16 12:22:33 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: start request repeated too quickly for kamailio.service
Jun 16 12:22:33 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Failed to start Kamailio (OpenSER) - the Open Source SIP Server.
Jun 16 12:22:33 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Unit kamailio.service entered failed state.
Jun 16 12:22:33 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: kamailio.service failed.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl restart kamailio
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl disable kamailio
Removed symlink /etc/systemd/system/multi-user.target.wants/kamailio.service.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl enable kamailio
Created symlink from /etc/systemd/system/multi-user.target.wants/kamailio.service to /usr/lib/systemd/system/kamailio.service.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl start kamailio
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl status kamailio -l
● kamailio.service - Kamailio (OpenSER) - the Open Source SIP Server
   Loaded: loaded (/usr/lib/systemd/system/kamailio.service; enabled; vendor preset: disabled)
   Active: active (running) since Sun 2019-06-16 12:30:52 UTC; 86ms ago
 Main PID: 5808 (kamailio)
   CGroup: /system.slice/kamailio.service
           └─5808 /usr/sbin/kamailio -DD -P /var/run/kamailio/kamailio.pid -f /etc/kamailio/kamailio.cfg -m 64 -M 4

Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: tcp: 165.22.15.111:5060
Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: tcp: 165.22.15.111:8081
Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: tls: 165.22.15.111:5061
Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: tls: 165.22.15.111:4443
Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: tls: 165.22.15.111:9080
Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: Aliases:
Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: *: 165.22.15.111:*
Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: *: callcenter.siarum.com:*
Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: INFO:  [core/sctp_core.c:75]: sctp_core_check_support(): SCTP API not enabled - if you want to use it, load sctp module
Jun 16 12:30:52 centos-s-2vcpu-4gb-nyc1-01 kamailio[5808]: INFO:  [core/tcp_main.c:4671]: init_tcp(): using epoll_lt as the io watch method (auto detected)
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# kamailio -c
loading modules under config path: /usr/lib64/kamailio/modules/
 0(5813) INFO: tls [tls_init.c:497]: init_tls_compression(): tls: init_tls: disabling compression...
 0(5813) WARNING:  [core/ppcfg.c:221]: pp_ifdef_level_check(): different number of preprocessor directives: N(#!IF[N]DEF) - N(#!ENDIF) = 1
 0(5813) INFO:  [core/sctp_core.c:75]: sctp_core_check_support(): SCTP API not enabled - if you want to use it, load sctp module
!endifListening on
             udp: 165.22.15.111:5060
             udp: callcenter.siarum.com [127.0.0.1]:5060
             tcp: 165.22.15.111:5060
             tcp: 165.22.15.111:8081
             tls: 165.22.15.111:5061
             tls: 165.22.15.111:4443
             tls: 165.22.15.111:9080
Aliases:
             *: 165.22.15.111:*
             *: callcenter.siarum.com:*

config file ok, exiting...
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl start kamailio
[root@centos-s-2vcpu-4gb-nyc1-01 ~]# systemctl status kamailio -l
● kamailio.service - Kamailio (OpenSER) - the Open Source SIP Server
   Loaded: loaded (/usr/lib/systemd/system/kamailio.service; enabled; vendor preset: disabled)
   Active: failed (Result: start-limit) since Sun 2019-06-16 12:31:06 UTC; 1s ago
  Process: 5876 ExecStart=/usr/sbin/kamailio -DD -P /var/run/kamailio/kamailio.pid -f $CFGFILE -m $SHM_MEMORY -M $PKG_MEMORY (code=exited, status=255)
 Main PID: 5876 (code=exited, status=255)

Jun 16 12:31:06 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: kamailio.service: main process exited, code=exited, status=255/n/a
Jun 16 12:31:06 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Unit kamailio.service entered failed state.
Jun 16 12:31:06 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: kamailio.service failed.
Jun 16 12:31:06 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: kamailio.service holdoff time over, scheduling restart.
Jun 16 12:31:06 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Stopped Kamailio (OpenSER) - the Open Source SIP Server.
Jun 16 12:31:06 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: start request repeated too quickly for kamailio.service
Jun 16 12:31:06 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Failed to start Kamailio (OpenSER) - the Open Source SIP Server.
Jun 16 12:31:06 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: Unit kamailio.service entered failed state.
Jun 16 12:31:06 centos-s-2vcpu-4gb-nyc1-01 systemd[1]: kamailio.service failed.
[root@centos-s-2vcpu-4gb-nyc1-01 ~]#