nerdexam
Palo_Alto_Networks

PCNSE · Question #786

After implementing a new NGFW, a firewall engineer is alerted to a VoIP traffic issue. After troubleshooting, the engineer confirms that the firewall is alerting the voice packets payload. What can…

The correct answer is B. Disable ALG under SIP application. The SIP Application Layer Gateway (ALG) is designed to assist SIP traffic traversing NAT by rewriting IP addresses embedded in SIP headers and SDP payloads. While helpful for NAT traversal in some scenarios, ALG can break VoIP when the SIP infrastructure already handles NAT…

Submitted by yuriko_h· Apr 18, 2026Configuration Troubleshooting

Question

After implementing a new NGFW, a firewall engineer is alerted to a VoIP traffic issue. After troubleshooting, the engineer confirms that the firewall is alerting the voice packets payload. What can the engineer do to solve the VoIP traffic issue?

Options

  • AIncrease the TCP timeout under SIP application
  • BDisable ALG under SIP application
  • CDisable ALG under H.323 application
  • DIncrease the TCP timeout under H.323 application

How the community answered

(56 responses)
  • A
    7% (4)
  • B
    71% (40)
  • C
    4% (2)
  • D
    18% (10)

Explanation

The SIP Application Layer Gateway (ALG) is designed to assist SIP traffic traversing NAT by rewriting IP addresses embedded in SIP headers and SDP payloads. While helpful for NAT traversal in some scenarios, ALG can break VoIP when the SIP infrastructure already handles NAT (e.g., via STUN or a Session Border Controller), because the firewall's rewriting corrupts the payload. Disabling SIP ALG (Device > Setup > Session > Application Layer Gateway) stops the firewall from modifying SIP packets, resolving the payload alteration issue.

Topics

#VoIP Troubleshooting#Application Layer Gateway (ALG)#SIP Protocol#Firewall Configuration

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice