everything from FS to Kam shows TLS and good. It's just the leg between Kam and the carrier. The invite goes from Kam to the carrier (the one I pasted above), the carrier 200ok's it, also good, then Kam sends the ACK over UDP, so the carrier never actually sees it - because they aren't listening on 5060 for this connection and the carrier retransmits the 200 until the call terminates. When Kam initiates the Bye, it is also over UDP. When Kam responds to the carrier Bye that eventually comes, it sends that over TLS.