Skip to content
5G/6G Academy
Back to PCAP Labs
PCAP Lab intermediate 20 min4 graded questions

IMS VoNR Registration Failure — Debugging a SIP 401 Loop

A specific device model cannot place VoNR calls. The 5G attach and IMS PDU session come up cleanly, but IMS registration bounces forever with 401 Unauthorized. Walk through the SIP trace between the UE, P-CSCF, I-CSCF, S-CSCF and HSS, and find the IMS AKA algorithm mismatch (RFC 3310 vs RFC 4169).

Scenario
Users report that VoNR calls don't work on a specific device model. Everything below IMS looks healthy: the UE attaches to 5G successfully, the IMS APN PDU session comes up, P-CSCF discovery works — but the UE never completes IMS registration. The SIP trace between the UE (behind CPE NAT, reaching the IMS via P-CSCF 10.45.1.5), the I-CSCF (10.45.1.6), the S-CSCF (10.45.1.7) and the HSS (10.45.0.4) has been captured. The UE IMPI is `user1@ims.operator.com` and its IMPU is `tel:+4930901234567` (sip:+4930901234567@ims.operator.com). The SIP REGISTER keeps bouncing back with 401 Unauthorized — the UE responds with a new Authorization header each time, but the S-CSCF rejects it again and again until, after three retries, it gives up with 403 Forbidden. The UE then de-registers and falls back to EPS/CSFB for voice. Your job: open the trace, walk through the IMS AKA challenge/response exchange (TS 33.203, RFC 3310, RFC 4169), understand the Cx MAR/MAA between S-CSCF and HSS (TS 29.229), and pin down exactly why the challenge/response loop is broken. Is this a UE fix, an HSS fix, or an S-CSCF fix?

Hands-on labs are a Pro feature

Engineer-grade PCAP labs, protocol dissection and TelcoMentor assistance are included with 5G/6G Academy Pro.

See Pro plans

7-day money-back guarantee · cancel anytime.