Summary

  • RFC 3331 did not move an SS7 link into an IP endpoint. MTP1 and MTP2 stayed at the Signalling Gateway, while M2UA transported the MTP2-user boundary so that remote MTP3 could operate the link.
  • The architecture made three truths independent: an SCTP association can be up, an ASP can be active, and the physical SS7 link can still be out of service. Interface mapping and explicit audit join those truths; a green connection light does not.

The user was a protocol layer

The title “MTP2 User Adaptation” can sound as if it adapted traffic for a subscriber. RFC 3331 used “user” in the layered-protocol sense. MTP3 is the only user of MTP2. In the backhaul arrangement, the physical SS7 circuit, MTP1 and MTP2 terminate at a Signalling Gateway Process. MTP3 runs in an Application Server Process at a Media Gateway Controller. M2UA carries the primitives that normally cross the local MTP2/MTP3 boundary over an IP network using SCTP.

That distinction is the article’s hinge. A signal unit arrives on a real line at the gateway. MTP2 performs the link functions there. The remote MTP3 does not own another copy of the wire; it receives data and state indications through M2UA and sends boundary requests back. Establish, release, congestion, local processor outage, remote processor outage, retrieval and data transfer become messages across a distributed boundary.

The earlier SIGTRAN framework in RFC 2719 described why such a split existed. A Signalling Gateway met the switched-circuit signalling network at its edge, while a Media Gateway Controller could host higher-layer call-control logic elsewhere in the packet network. RFC 3331 supplied a concrete protocol for one precise cut in that architecture.

It is therefore wrong to describe M2UA as if it simply tunneled an SS7 link end to end. The lower link remains physically and operationally located at the gateway. What moves is access to its upper interface. That choice created flexibility, but it also turned a once-local boundary into a distributed control system.

One identifier joined two different kinds of place

RFC 3331 required the gateway to map an Interface Identifier to a physical interface: perhaps a V.35 line, a T1 line and time slot, or an E1 line and time slot. It also mapped the same identifier to an SCTP association and to a stream within that association. Those two mappings were not equally stable. The physical relationship was provisioned. The association-and-stream relationship could change when an ASP became active, went inactive or failed over to a replacement.

The Interface Identifier was locally significant and coordinated between the Signalling Gateway and the Application Server Process. It was not a global name for a circuit. A packet capture that contains identifier 17 proves that a peer sent that value in a particular context. It does not, without the configuration receipt, prove which copper, optical or time-slot resource the operator intended it to mean.

SCTP streams helped separate traffic and reduce cross-link head-of-line blocking. Yet a stream number could not replace the Interface Identifier. SCTP streams are unidirectional, so an M2UA peer cannot infer the corresponding return stream merely from the stream on which a message arrived. RFC 3331 therefore put the Interface Identifier in the M2UA header. Management traffic used the common stream, while MAUP traffic was expected on the streams associated with its data.

This arrangement created an auditable chain: physical link to Interface Identifier; identifier to Application Server; active Application Server Process to SCTP association and stream. If any edge was absent, stale or ambiguous, the remote MTP3’s view of the link could diverge from the gateway’s reality.

Three green lights could not be treated as one

The IP transport, the application process and the SS7 link each had its own state. SCTP could report an established association. The M2UA control plane could place an ASP in DOWN, INACTIVE or ACTIVE state for an Application Server. The MTP2 link could independently be in service, out of service, congested or experiencing remote processor outage.

An association that was up said the two SCTP endpoints could communicate. It did not say that this ASP had been activated for a particular Interface Identifier. ASP ACTIVE said the process was selected to receive application traffic under a traffic mode. It did not say that the physical link was in service. Conversely, a sound SS7 link at the gateway did not guarantee that any remote ASP was ready to consume its traffic.

RFC 3331 also modelled Application Server states and a pending interval during recovery. Override, Loadshare and Broadcast modes changed how active processes received traffic. The gateway had to keep current AS and ASP state when routing each message because a dynamic mapping could become temporarily invalid during failover. The specification advised that only one Signalling Gateway Process provide link-terminal service to one SS7 link, preventing two active owners from pretending to terminate the same physical resource.

These are not bureaucratic distinctions. If an operator equates transport liveness with service health, a failover can direct signalling toward an ASP that has not reconstructed the link state. If application activity is equated with physical readiness, messages may queue behind a dead circuit. If link health is equated with remote readiness, a gateway may keep accepting traffic that no controller can process.

Audit repaired uncertainty, not history

RFC 3331 included a STATUS_AUDIT operation so an ASP could ask the gateway for the current state of an SS7 link. The response could indicate out of service, in service, congestion or remote processor outage. This mattered after activation, association restart or a gap in event delivery: a remote MTP3 needed a current baseline rather than assuming that the last state it remembered still applied.

An audit is a reconciliation receipt. It is not proof that no state transition occurred a moment later, nor does it reconstruct every missed event. A defensible incident record pairs the audit request and response with timestamps, Interface Identifier, association identity, ASP state and subsequent indications. “The audit said in service” is bounded by the time and observation point of that exchange.

Dynamic registration added another boundary. A Link Key could be authorized and mapped to an Interface Identifier. Successful registration showed that the gateway accepted that control mapping. It did not prove the physical link was healthy, the ASP was active, or traffic was flowing. Authorization and availability remained different receipts.

Backhaul was not peer-to-peer replacement

RFC 4165 later made the contrast with M2PA explicit. Both protocols can carry MTP3-related information over SCTP, but their architecture is different. In M2PA, each peer has MTP3 and M2PA replaces MTP2 between those peers. In M2UA, the Media Gateway Controller’s MTP3 uses the Signalling Gateway’s real MTP2 through transported boundary primitives. Calling both “SS7 over IP” hides the ownership question that determines every failure mode.

The same care applies across the wider SIGTRAN family. RFC 4666’s M3UA and RFC 4233’s IUA share common ASP state and message-class machinery, but their adapted boundaries are not interchangeable. Shared headers do not prove shared semantics.

RFC 3331 referenced the SCTP specification current in 2002. RFC 9260 is today’s SCTP protocol specification. That succession helps an implementer read current transport behavior, but it does not prove that a particular M2UA network was upgraded or operates today. Likewise, IANA still assigns M2UA SCTP payload protocol identifier 2 and maintains MAUP and Interface Identifier Management message classes. A registry entry proves a code point and reference, not deployment, traffic volume or conformance.

Security has the same boundary. SCTP supplies transport mechanisms; it does not make a locally coordinated Interface Identifier an authenticated statement about a physical line. RFC 3788 addressed SIGTRAN security considerations and mechanisms. Operators still needed a security policy, peer authorization and protection appropriate to the network. A working association is not evidence that the peer is entitled to operate the link behind an identifier.

The durable lesson is evidence separation

M2UA distributed a previously local interface without erasing its physical anchor. That is why its most useful historical lesson is not a message catalogue. It is a method for reading distributed infrastructure claims.

Keep five receipts: the SCTP association and stream; the ASP and AS control states; the provisioned Interface-Identifier mapping; the physical MTP2 link state; and the boundary message that carried an observation or command. Add the security and authorization context when the question is who was permitted to act. Only then can a green application process be related to a particular link.

RFC 3331 made remote control possible by being precise about what stayed, what moved and what had to be named between them. When those distinctions are collapsed, an IP connection becomes false proof of telephony service. When they are preserved, failover and audit can be explained without pretending that a packet network moved the wire itself.

Sources