PCNSE · Question #786
After implementing a new NGFW, a firewall engineer is alerted to a VoIP traffic issue. After troubleshooting, the engineer confirms that the firewall is alerting the voice packets payload. What can…
The correct answer is B. Disable ALG under SIP application. The SIP Application Layer Gateway (ALG) is designed to assist SIP traffic traversing NAT by rewriting IP addresses embedded in SIP headers and SDP payloads. While helpful for NAT traversal in some scenarios, ALG can break VoIP when the SIP infrastructure already handles NAT…
Question
After implementing a new NGFW, a firewall engineer is alerted to a VoIP traffic issue. After troubleshooting, the engineer confirms that the firewall is alerting the voice packets payload. What can the engineer do to solve the VoIP traffic issue?
Options
- AIncrease the TCP timeout under SIP application
- BDisable ALG under SIP application
- CDisable ALG under H.323 application
- DIncrease the TCP timeout under H.323 application
How the community answered
(56 responses)- A7% (4)
- B71% (40)
- C4% (2)
- D18% (10)
Explanation
The SIP Application Layer Gateway (ALG) is designed to assist SIP traffic traversing NAT by rewriting IP addresses embedded in SIP headers and SDP payloads. While helpful for NAT traversal in some scenarios, ALG can break VoIP when the SIP infrastructure already handles NAT (e.g., via STUN or a Session Border Controller), because the firewall's rewriting corrupts the payload. Disabling SIP ALG (Device > Setup > Session > Application Layer Gateway) stops the firewall from modifying SIP packets, resolving the payload alteration issue.
Topics
Community Discussion
No community discussion yet for this question.