4G/LTE - Voice in LTE

 

 

 

Voice over LTE/IMS

 

VoLTE literally stands for "Voice over LTE". But when people say "VoLTE" (in abbreviation) it usually mean "Voice over LTE utilizing IMS". (You would need to read the context to figure out what they say. Are they talking about 'general voice technology implementation over LTE' or "Voice over LTE utilizing IMS" ?)

Theoretically you can use the IP/SIP based application for voice call on LTE as you do with your PC and other IP phone. Then what would be the difference between VoLTE and generic IP based voice call. The simple answer is that VoLTE over IMS can be specially optimized for voice traffic not only in terms of core network but also in terms of radio stack, whereas generic IP based voice call is just 'best effort' type of application which can hardly be optimized for voice traffic and no guaranteed quality of service.

When we are thinking about VoLTE, we have to look into two layers. One is about Application Layer (SIP/IMS Layer) and the other one is about Access Network Layer (Radio Layer).

The two layers depend on each other in a fixed order. The UE first needs an EPS bearer to the IMS APN, and only then can it send its first SIP message. The UE also has to tell the network in NAS that it wants IMS voice, and the network has to answer that it supports it. So this page goes from the SIP sequence down to the bearers and the NAS indications, and then follows one complete log from power on to a VoLTE call.

Following is the topics that I will talk about in this page.

The page Get the Test Procedure and Log / Amarisoft TechAcademy has the test procedure and the full log that Example 1 uses.

SIP/IMS Transaction - Overall SIP/IMS Sequence

Let's start at the application layer, because this is where a VoLTE call is actually set up. The UE and the IMS core exchange SIP messages, and the radio network carries them only as IP packets. Before the first INVITE, the UE has to register in IMS, so every VoLTE log starts with a REGISTER.

One common transaction for VoLTE at SIP/IMS layer would be as shown below, but the detailed implementation may vary on the requirement from Carriers.

Following is a very basic SIP sequence from IMS Registration through VoLTE. This log were captured under following conditon. (With VoLTE in real network, you would not see this kind of simplified log since most of live network would enable Authentication and require Precondition)

  • Authentication = OFF
  • Precondition = OFF

The image below is a Wireshark capture of that sequence, with one SIP message per row. The blue rows are requests sent to 10.133.202.47, and the black rows are the responses sent to 10.133.202.46. The bracket on the right groups the rows into Registration and Voice Call. The RTP voice packets between the call setup and the BYE are not shown one by one. A single line stands in for them.

 

Wireshark capture of IMS registration and a VoLTE call, from REGISTER to BYE

A complete VoLTE session in SIP. Six messages register the UE in IMS, seven set up the call, and two release it.

  • REGISTER and 200 OK : the UE registers its contact address in IMS. With Authentication = OFF, the first REGISTER is answered with 200 OK directly. With authentication, the network first answers 401 Unauthorized, and the UE sends a second REGISTER.
  • SUBSCRIBE, NOTIFY and 200 OK : the UE subscribes to its own registration state, and the network sends the state in an XML body. The network can use the same subscription later to tell the UE that its registration has ended.
  • INVITE, 100 Trying and 180 Ringing : the INVITE carries the SDP offer for the voice media. 100 Trying stops INVITE retransmission, and 180 Ringing tells the caller that the called party is alerted.
  • PRACK and 200 OK : the UE acknowledges a reliable provisional response with PRACK, and the network answers it with 200 OK.
  • 200 OK with session description and ACK : the called side answers the call, and the UE confirms with ACK. RTP voice starts after this point.
  • BYE and 200 OK : either side can end the call. Here, the request goes toward 10.133.202.47 like the other requests.

Actually each of the SIP message shown above has a lot of details and desribed acorss multiple specification. If you are interested in more details of each of these messages and parameters, refer to following links

Precondition = OFF also explains a gap in the capture. With precondition, the network answers the INVITE with 183 Session Progress, and the UE sends UPDATE after the voice bearer is ready. Only then does the called side ring. This sequence skips that step, so the phone can ring before the dedicated bearer for voice exists.

  • Registration comes before any call : a VoLTE UE cannot send an INVITE until IMS has accepted its REGISTER.
  • SDP travels inside SIP : the INVITE and the final 200 OK carry the media description of the call.
  • A live network adds messages : authentication adds 401 Unauthorized, and precondition adds 183 Session Progress and UPDATE.

Radio Layer Configuration

SIP signalling and RTP voice both need an EPS bearer. So the radio side of VoLTE comes down to two questions. How many bearers carry the IMS traffic, and which QoS does each of them get? The three cases below give three different answers.

There can be almost inifinite number of variations in terms of radio stack configurations for VoLTE over. Followings would be the most common configuration in very high level view.

Case 1 :

In Case 1, one default EPS bearer carries both SIP/IMS signalling and voice traffic.

 

Case 1, one default EPS bearer for SIP/IMS signaling and voice traffic

Case 1 is the simplest setup, and it works for a first test. But the voice packets then get the QoS of the default bearer, which is a non-GBR bearer. So the eNodeB cannot give voice a guaranteed bit rate, and the voice quality drops as soon as other traffic loads the cell.

Case 2 :

In Case 2, a default EPS bearer carries SIP/IMS signalling, and a dedicated EPS bearer linked to it carries the voice traffic.

 

Case 2, default EPS bearer for SIP/IMS signaling and a linked dedicated EPS bearer for voice traffic

The dedicated bearer is created during the call setup and released after the call. It can be a GBR bearer with its own packet filters, so the network can protect voice without changing the treatment of SIP signalling.

Case 3 :

In Case 3, the UE has two PDN connections. One default EPS bearer carries general packets such as Internet traffic. A second default EPS bearer carries SIP/IMS signalling, and a dedicated EPS bearer linked to it carries the voice traffic.

 

Case 3, separate default EPS bearers for Internet and SIP/IMS signaling, with a dedicated EPS bearer for voice traffic

Case 3 is the setup of Example 1 at the end of this page. There, the Internet APN gets QCI 9, the ims APN gets QCI 5, and the dedicated bearer for voice gets QCI 1. TS 23.203 defines these QCIs as follows. QCI 1 is a GBR QCI for conversational voice, with a packet delay budget of 100 ms and a packet error loss rate of 10-2. QCI 5 is a non-GBR QCI for IMS signalling, with priority level 1, a delay budget of 100 ms and a loss rate of 10-6. QCI 9 is the non-GBR QCI for best effort data, with priority level 9 and a delay budget of 300 ms.

  • Voice needs its own bearer : only a dedicated GBR bearer gives voice a guaranteed bit rate.
  • SIP signalling gets the highest priority : QCI 5 has priority level 1, above the voice bearer at QCI 1.
  • Case 3 is the complete setup : separate PDN connections keep Internet traffic and IMS traffic apart.

NAS Messages - Related to IMS/VoLTE

Before any SIP message, the UE and the network exchange two pieces of information in NAS. The UE tells the MME how it wants to make voice calls. The MME tells the UE whether IMS voice is supported in this tracking area. Both are in the Attach procedure, and both appear in the decodes below.

The first decode is part of an Attach Request. The red lines are the fields that matter for voice. They are the SRVCC capabilities and the Voice domain preference and UE's usage setting IE.

Capture : Attach Request, protocol analyzer decode. The lines come from one recorded session, so they are shown as they were printed.

Attach request ::= DIVISION
  ....
  | +-Octet6 ::= DIVISION
  | | +-spare ::= FIX [0]
  | | +-1xSRVCC ::= CHOICE [SRVCC from E-UTRAN to cdma2000 1xCS not supported]
  | | +-spare ::= FIX [0]
  | +-Octet7-14 ::= DIVISION
  |   +-Spare ::= OCTETARRAY SIZE(0..8) [00]
  ....
  +-MS network capability ::= TLV OPTIONAL:Exist
  ....
  |     +-SRVCC to GERAN/UTRAN capability ::= CHOICE [SRVCC from UTRAN HSPA or E-UTRAN to
          GERAN/UTRAN not supported]
  +-Voice domain preference and UE's usage setting ::= TLV OPTIONAL:Exist
    +-Octet1 ::= DIVISION
    | +-Voice domain preference and UE's usage setting IEI ::= IEI [5D]
    +-Octet2 ::= DIVISION
    | +-Length of Voice domain preference and UE's usage setting contents ::= LEN (0..255) [1]
    +-Octet3 ::= DIVISION
      +-Spare ::= FIX [0]
      +-UE's usage setting ::= CHOICE [Voice centric]
        // This IE has following choices
        //    : Voice Centric, 
                Data Centric,
      +-Voice domain preference for E-UTRAN ::= CHOICE [CS Voice only]
      // This IE has following choices
       //   : CS Voice Only, 
             IMS PS Voice Only, 
             CS Voice Prefered IMS PS Voice as Secondary
              IMS PS Voice Prefered CS Voice as Secondary

Look at the values this UE sends. It does not support SRVCC to GERAN/UTRAN or to cdma2000 1xCS. Its UE's usage setting is Voice centric, and its Voice domain preference for E-UTRAN is CS Voice only. TS 24.008 says that a UE not supporting IMS voice shall indicate CS Voice only. So this particular Attach Request comes from a UE with IMS voice disabled. A VoLTE UE sends IMS PS Voice only, or one of the two combinations with IMS PS voice. A voice centric UE also has one more rule in TS 24.301. If it cannot get voice in E-UTRAN, it disables its E-UTRA capability and moves to another RAT.

The second decode is part of an Attach Accept. Here the MME answers with the EPS network feature support IE.

Capture : Attach Accept, protocol analyzer decode. The lines come from one recorded session, so they are shown as they were printed.

Attach accept ::= DIVISION
  .....
  +-EPS network feature support ::= TLV OPTIONAL:Exist
  | +-Octet1 ::= DIVISION
  | | +-EPS network feature support IEI ::= IEI [64]
  | +-Octet2 ::= DIVISION
  | | +-Length of EPS network feature support contents ::= LEN (0..255) [1]
  | +-Octet3 ::= DIVISION
  |   +-Spare ::= FIX [0]
  |   +-IMS VoPS ::= CHOICE [IMS voice over PS session in S1 mode supported]
                     // This IE has following choices
                     // IMS voice over PS session in S1 mode supported
                     // IMS voice over PS session in S1 mode not supported
  +-Additional update result ::= TV OPTIONAL:Omit
    +-Octet1 ::= DIVISION
      +-Additional update result IEI ::= IEI [F-]
      +-Spare ::= FIX [0]
      +-Additional update result value ::= CHOICE [no additional information]

The IMS VoPS bit tells the UE that IMS voice over PS session in S1 mode is supported. The UE passes this bit to its upper layers, which use it to select the domain for voice. If the bit is 0, a VoLTE UE does not start an IMS voice call in this network. It uses CSFB, or it selects another RAT. In the current TS 24.301, the IE can have up to 3 octets of flags after the length. Octet 3 also carries EMC BS, EPC-LCS, CS-LCS, ESRPS, ERw/oPDN and CP CIoT. The Additional update result IE is omitted in this Attach Accept. In a combined attach, it could say CS Fallback not preferred or SMS only.

  • The UE states its voice preference : Voice domain preference and UE's usage setting is in the Attach Request.
  • CS Voice only means no IMS voice : a VoLTE UE indicates IMS PS voice in one of the other three values.
  • The MME states IMS VoPS : the UE starts an IMS voice call only when the IMS VoPS bit is 1.

Example 1 : Overal Procedure for VoLTE - Both Radio Signaling and IMS Signaling

The sections above show the parts of VoLTE one at a time. This example puts them in the order they happen in one log, from UE power on to RTP traffic. The captures below are the steps that carry the bearer setup. The SIP steps link to separate pages.

Following is the very simplified procedure of protocol sequence from UE Power On to VoLTE Call Setup. You may click the link if you want to get the detailed sequence.

NOTE : If you want to see the contents of full log with Amarisoft Log viewer, go to LogAnalysis section and click on 'Sample Log' in this tutorial of Amarisoft TechAcademy.

Step 2 - RRC Connection Reconfiguration : Attach Accept, Default EPS Bearer for Internet APN

This message completes the attach. The RRC Connection Reconfiguration carries the Attach Accept and the request for the first default EPS bearer. The UE answers with Attach Complete in an ULInformationTransfer, which is the second message in the capture.

Capture : RRC Connection Reconfiguration and ULInformationTransfer, protocol analyzer decode. The lines come from one recorded session, so they are shown as they were printed.

rrcConnectionReconfiguration-r8
    dedicatedInfoNASList: 1 item
        Item 0
            DedicatedInfoNAS: 2732c69fbd02074202e0060000f110000000365226c10109...
                Non-Access-Stratum (NAS)PDU
                    ...
                    ESM message container
                        Length: 54
                        ESM message container contents: ...
                            0101 .... = EPS bearer identity: EPS bearer identity value 5 (5)
                            .... 0010 = Protocol discriminator:
                                         EPS session management messages (0x02)
                            Procedure transaction identity: 38
                            NAS EPS session management messages:
                                         Activate default EPS bearer context request (0xc1)
                            EPS quality of service
                                Length: 1
                                Quality of Service Class Identifier (QCI): QCI 9 (9)
                            Access Point Name
                                Length: 8
                                APN: internet
                            PDN address
                                Length: 5
                                0000 0... = Spare bit(s): 0x00
                                PDN type: IPv4 (1)
                                PDN IPv4: 192.168.1.1 (192.168.1.1)
                            Protocol Configuration Options
                                Element ID: 0x27
                                Length: 27
                                [Link direction: Network to MS (1)]
                                1... .... = Extension: True
                                Configuration Protocol: ...
                                Protocol or Container ID:
                                                   Internet Protocol Control Protocol (0x8021)
                                    Length: 0x10 (16)
                                    PPP IP Control Protocol
                                        Code: Configuration Nak (3)
                                        Identifier: 0 (0x00)
                                        Length: 16
                                        Options: (12 bytes), ...
                                            Primary DNS Server IP Address: 192.168.1.2
                                                Type: Primary DNS Server IP Address (129)
                                                Length: 6
                                                Primary DNS Address: 192.168.1.2 (192.168.1.2)
                                            Secondary DNS Server IP Address: 192.168.1.3
                                                Type: Secondary DNS Server IP Address (131)
                                                Length: 6
                                                Secondary DNS Address: 192.168.1.3 (192.168.1.3)
                                Protocol or Container ID: DNS Server IPv4 Address (0x000d)
                                    Length: 0x04 (4)
                                    IPv4: 192.168.1.2
                    EPS mobile identity - GUTI
                        ...
                    Location area identification
                        ...
                    Mobile identity - MS identity - TMSI/P-TMSI (0x0001)
                        ...
                    GPRS Timer - T3402 value
                        ...
                    GPRS Timer - T3423 value
                        ...
                    EPS network feature support
                        Element ID: 0x64
                        Length: 1
                        00.. .... = Spare bit(s): 0x00
                        ..0. .... = ESRPS: ...
                        ...0 0... = CS-LCS: ...
                        .... .0.. = EPC-LCS: location services via EPC not supported
                        .... ..1. = EMC BS: emergency bearer services in S1 mode supported
                        .... ...1 = IMS VoPS: IMS voice over PS session in S1 mode supported
    radioResourceConfigDedicated
        srb-ToAddModList: 1 item
            ...
        drb-ToAddModList: 1 item
            Item 0
                DRB-ToAddMod
                    eps-BearerIdentity: 5
                    drb-Identity: 1
                    pdcp-Config
                        ...
                    rlc-Config: am (0)
                        ...
                    logicalChannelIdentity: 3
                    logicalChannelConfig
                        ul-SpecificParameters
                            priority: 13
                            prioritisedBitRate: kBps8 (1)
                            bucketSizeDuration: ms100 (1)
                            logicalChannelGroup: 2
        mac-MainConfig: explicitValue (0)
            explicitValue
                ul-SCH-Config
                    ...
                drx-Config: setup (1)
                    ...
                timeAlignmentTimerDedicated: infinity (7)
                phr-Config: setup (1)
                    ...
                mac-MainConfig-v1020
        physicalConfigDedicated
            tpc-PDCCH-ConfigPUCCH: setup (1)
                setup
                    ...
            tpc-PDCCH-ConfigPUSCH: setup (1)
                setup
                    ...
            antennaInfo: defaultValue (1)


ulInformationTransfer-r8
    dedicatedInfoType: dedicatedInfoNAS (0)
        dedicatedInfoNAS: 279489aabb02074300035200c2
            Non-Access-Stratum (NAS)PDU
                0010 .... = Security header type: Integrity protected and ciphered (2)
                .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                Message authentication code: 0x9489aabb
                Sequence number: 2
                0000 .... = Security header type: Plain NAS message, not security protected (0)
                .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                NAS EPS Mobility Management Message Type: Attach complete (0x43)
                ESM message container
                    Length: 3
                    ESM message container contents: 5200c2
                        0101 .... = EPS bearer identity: EPS bearer identity value 5 (5)
                        .... 0010 = Protocol discriminator: EPS session management messages (0x02)
                        Procedure transaction identity: 0
                        NAS EPS session management messages:
                                          Activate default EPS bearer context accept (0xc2)
                                       defaultValue: NULL

The first default bearer has EPS bearer identity 5, QCI 9 and the APN internet. It gets the IPv4 address 192.168.1.1 and the DNS servers 192.168.1.2 and 192.168.1.3. The EPS network feature support IE has IMS VoPS set to 1, so the network supports IMS voice. On the radio side, the bearer maps to DRB 1 on logical channel 3, with RLC AM and logical channel priority 13. The Attach Complete carries the Activate default EPS bearer context accept for the same bearer.

Step 3 - PDN Connectivity Request : for ims APN

After the attach, the UE opens a second PDN connection for IMS. This is Case 3 of the radio layer section. The UE sends the request itself, in an ULInformationTransfer.

Capture : ULInformationTransfer with PDN Connectivity Request, protocol analyzer decode. The lines come from one recorded session, so they are shown as they were printed.

ulInformationTransfer-r8
    dedicatedInfoType: dedicatedInfoNAS (0)
        dedicatedInfoNAS: 27ff2b2869030227d021280403696d732710800003000001...
            Non-Access-Stratum (NAS)PDU
                0010 .... = Security header type: Integrity protected and ciphered (2)
                .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                Message authentication code: 0xff2b2869
                Sequence number: 3
                0000 .... = EPS bearer identity: No EPS bearer identity assigned (0)
                .... 0010 = Protocol discriminator: EPS session management messages (0x02)
                Procedure transaction identity: 39
                NAS EPS session management messages: PDN connectivity request (0xd0)
                0010 .... = PDN type: IPv6 (2)
                .... 0001 = Request type: initial request (1)
                Access Point Name
                    Element ID: 0x28
                    Length: 4
                    APN: ims
                Protocol Configuration Options
                    Element ID: 0x27
                    Length: 16
                    [Link direction: MS to network (0)]
                    1... .... = Extension: True
                    Configuration Protocol: PPP for use with IP PDP type or IP PDN type (0)
                    Protocol or Container ID: DNS Server IPv6 Address Request (0x0003)
                        Length: 0x00 (0)
                    Protocol or Container ID: P-CSCF IPv6 Address Request (0x0001)
                        Length: 0x00 (0)
                    Protocol or Container ID: IP address allocation via NAS signalling (0x000a)
                        Length: 0x00 (0)
                    Protocol or Container ID:
                               MS Support of Network Requested Bearer Control indicator (0x0005)
                        Length: 0x00 (0)
                    Protocol or Container ID: IPv4 Link MTU Request (0x0010)
                                                Length: 0x00 (0)

The APN is ims. The Protocol Configuration Options are the important part here. The UE asks for a DNS server IPv6 address and a P-CSCF IPv6 address, and it asks for the IP address to be allocated through NAS signalling. Without the P-CSCF address, the UE does not know where to send its REGISTER.

Step 4 - RRC Connection Reconfiguration : Default EPS Bearer for ims APN

The network answers the request with a second default EPS bearer. The Activate default EPS bearer context request reaches the UE inside an RRC Connection Reconfiguration, together with the new DRB.

Capture : RRC Connection Reconfiguration, protocol analyzer decode. The lines come from one recorded session, so they are shown as they were printed.

rrcConnectionReconfiguration-r8
    dedicatedInfoNASList: 1 item
        Item 0
            DedicatedInfoNAS: 279e2205e3046227c101090403696d730902000000000000...
                Non-Access-Stratum (NAS)PDU
                    0010 .... = Security header type: Integrity protected and ciphered (2)
                    .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                    Message authentication code: 0x9e2205e3
                    Sequence number: 4
                    0110 .... = EPS bearer identity: EPS bearer identity value 6 (6)
                    .... 0010 = Protocol discriminator: EPS session management messages (0x02)
                    Procedure transaction identity: 39
                    NAS EPS session management messages:
                               Activate default EPS bearer context request (0xc1)
                    EPS quality of service
                        Length: 1
                        Quality of Service Class Identifier (QCI): QCI 5 (5)
                    Access Point Name
                        Length: 4
                        APN: ims
                    PDN address
                        Length: 9
                        0000 0... = Spare bit(s): 0x00
                        PDN type: IPv6 (2)
                        PDN IPv6 if id: 0000000000000011
                    Protocol Configuration Options
                        Element ID: 0x27
                        Length: 39
                        [Link direction: Network to MS (1)]
                        1... .... = Extension: True
                        Configuration Protocol: PPP for use with IP PDP type or IP PDN type (0)
                        Protocol or Container ID: DNS Server IPv6 Address (0x0003)
                            Length: 0x10 (16)
                            IPv6: 2001:0:0:1::2
                        Protocol or Container ID: P-CSCF IPv6 Address (0x0001)
                            Length: 0x10 (16)
                            IPv6: 2001:0:0:1::2
    radioResourceConfigDedicated
        drb-ToAddModList: 1 item
            ...
                    logicalChannelIdentity: 4
                    logicalChannelConfig
                        ul-SpecificParameters
                            priority: 13
                            prioritisedBitRate: kBps8 (1)
                            bucketSizeDuration: ms100 (1)
                            logicalChannelGroup: 2
        mac-MainConfig: explicitValue (0)
            explicitValue
                ul-SCH-Config
                    ...
                drx-Config: setup (1)
                    ...
                timeAlignmentTimerDedicated: infinity (7)
                phr-Config: setup (1)
                    ...
                mac-MainConfig-v1020
        physicalConfigDedicated
            tpc-PDCCH-ConfigPUCCH: setup (1)
                ...
            tpc-PDCCH-ConfigPUSCH: setup (1)
                ...
            antennaInfo: defaultValue (1)

This bearer has QCI 5, which is the IMS signalling QCI. The PDN type is IPv6, and the network gives the P-CSCF address 2001:0:0:1::2 in the Protocol Configuration Options. The same address is also the DNS server in this test setup. The new DRB uses logical channel 4. With this bearer, the UE can register in IMS, which is step 5.

Step 8 - RRC Connection Reconfiguration : Dedicated EPS Bearer for ims APN

Steps 5 to 7 are SIP signalling on the QCI 5 bearer. When the call is set up in SIP, the network creates the bearer for voice. It sends an Activate dedicated EPS bearer context request, and the RRC Connection Reconfiguration sets up the DRB for it.

Capture : RRC Connection Reconfiguration, protocol analyzer decode. The lines come from one recorded session, so they are shown as they were printed.

rrcConnectionReconfiguration-r8
    dedicatedInfoNASList: 1 item
        Item 0
            DedicatedInfoNAS: 27b6fac978057200c506050131313131172230100840c35a...
                Non-Access-Stratum (NAS)PDU
                    0010 .... = Security header type: Integrity protected and ciphered (2)
                    .... 0111 = Protocol discriminator: EPS mobility management messages (0x07)
                    Message authentication code: 0xb6fac978
                    Sequence number: 5
                    0111 .... = EPS bearer identity: EPS bearer identity value 7 (7)
                    .... 0010 = Protocol discriminator: EPS session management messages (0x02)
                    Procedure transaction identity: 0
                    NAS EPS session management messages:
                                  Activate dedicated EPS bearer context request (0xc5)
                    0000 .... = Spare half octet: 0
                    .... 0110 = Linked EPS bearer identity: EPS bearer identity value 6 (6)
                    EPS quality of service
                        Length: 5
                        Quality of Service Class Identifier (QCI): QCI 1 (1)
                        Maximum bit rate for uplink: 49 kbps
                        Maximum bit rate for downlink: 49 kbps
                        Guaranteed bit rate for uplink: 49 kbps
                        Guaranteed bit rate for downlink: 49 kbps
                    Traffic Flow Template
                        Length: 23
                        001. .... = TFT operation code: Create new TFT (1)
                        ...0 .... = E bit: Parameters list is not included
                        .... 0010 = Number of packet filters: 2
                        Packet filter 0
                            00.. .... = Spare bit(s): 0
                            ..11 .... = Packet filter direction: Bidirectional (3)
                            .... 0000 = Packet filter identifier: 1 (0)
                            Packet evaluation precedence: 0x10 (16)
                            Packet filter length: 0x08 (8)
                            Packet filter component type identifier: Single local port type (64)
                                Port: 50010
                            Packet filter component type identifier: Single remote port type (80)
                                Port: 60000
                            Packet filter component type identifier:
                                                        Protocol identifier/Next header type (48)
                                Protocol/header: UDP (0x11)
                        Packet filter 1
                            00.. .... = Spare bit(s): 0
                            ..11 .... = Packet filter direction: Bidirectional (3)
                            .... 0001 = Packet filter identifier: 2 (1)
                            Packet evaluation precedence: 0x11 (17)
                            Packet filter length: 0x08 (8)
                            Packet filter component type identifier: Single local port type (64)
                                Port: 50011
                            Packet filter component type identifier: Single remote port type (80)
                                Port: 60001
                            Packet filter component type identifier:
                                            Protocol identifier/Next header type (48)
                                Protocol/header: UDP (0x11)
    radioResourceConfigDedicated
        drb-ToAddModList: 1 item
            Item 0
                DRB-ToAddMod
                    eps-BearerIdentity: 7
                    drb-Identity: 3
                    pdcp-Config
                        discardTimer: ms100 (1)
                        rlc-UM
                            pdcp-SN-Size: len12bits (1)
                        headerCompression: rohc (1)
                            rohc
                                maxCID: 15
                                profiles
                                    1... .... profile0x0001: True
                                    .1.. .... profile0x0002: True
                                    ..0. .... profile0x0003: False
                                    ...0 .... profile0x0004: False
                                    .... 0... profile0x0006: False
                                    .... .0.. profile0x0101: False
                                    .... ..0. profile0x0102: False
                                    .... ...0 profile0x0103: False
                                    0... .... profile0x0104: False
                    rlc-Config: um-Bi-Directional (1)
                        um-Bi-Directional
                            ul-UM-RLC
                                sn-FieldLength: size10 (1)
                            dl-UM-RLC
                                sn-FieldLength: size10 (1)
                                t-Reordering: ms50 (10)
                    logicalChannelIdentity: 5
                    logicalChannelConfig
                        ul-SpecificParameters
                            priority: 6
                            prioritisedBitRate: kBps8 (1)
                            bucketSizeDuration: ms100 (1)
                            logicalChannelGroup: 1
        mac-MainConfig: explicitValue (0)
            explicitValue
                ul-SCH-Config
                    ...
                drx-Config: setup (1)
                    ...
                timeAlignmentTimerDedicated: infinity (7)
                phr-Config: setup (1)
                    ...
                mac-MainConfig-v1020
        physicalConfigDedicated
            tpc-PDCCH-ConfigPUCCH: setup (1)
                ...
            tpc-PDCCH-ConfigPUSCH: setup (1)
                ...
            antennaInfo: defaultValue (1)
                defaultValue: NULL

The dedicated bearer has EPS bearer identity 7 and QCI 1. Its maximum and guaranteed bit rates are 49 kbps in both directions. The Traffic Flow Template has two packet filters for UDP. The first maps local port 50010 and remote port 60000, and the second maps ports 50011 and 60001. These are the RTP and RTCP ports of the call, taken from the SDP.

The DRB for this bearer is set up for voice in every layer. PDCP uses ROHC with maxCID 15 and profiles 0x0001 and 0x0002. Profile 0x0001 compresses RTP/UDP/IP headers, and profile 0x0002 compresses UDP/IP headers. The PDCP discardTimer is 100 ms, which matches the 100 ms delay budget of QCI 1. RLC uses UM with a 10-bit sequence number and t-Reordering of 50 ms, because a voice packet cannot wait for RLC retransmissions. The logical channel priority is 6 in logical channel group 1, so voice gets ahead of the two default bearers at priority 13.

  • Three bearers make one VoLTE call : QCI 9 for Internet, QCI 5 for SIP signalling and QCI 1 for voice.
  • The P-CSCF address comes from PCO : the UE asks for it in the PDN Connectivity Request and gets it in the default bearer for the ims APN.
  • The TFT follows the SDP : the packet filters carry the RTP and RTCP ports of the call.
  • The voice DRB is tuned for delay : ROHC, RLC UM, a short discard timer and a higher logical channel priority.

Reference

[1] 3GPP TS 24.301 v20.0.0 - NAS protocol for EPS, clauses 4.3 and 9.9.3.12A

[2] 3GPP TS 24.008 v20.0.0 - Mobile radio interface Layer 3 specification, clause 10.5.5.28

[3] 3GPP TS 23.203 v20.0.0 - Policy and charging control architecture, Table 6.1.7-A

[4] 3GPP TS 36.323 v19.0.0 - E-UTRA, PDCP specification, clause 5.5