SIP-ALG and You

Status
Not open for further replies.

DrainBamaged

Forum User
Advanced Certified
Joined
Feb 21, 2019
Messages
168
Reaction score
41
A cautionary tale about turning off SIP-ALG on your firewall. We lost access to one of our branch offices for half a day. Turns out one of our techs disabled SIP-ALG on the firewall and after that no SIP calls were able to be made in or out. Even the denials were no longer logged by the firewall. It was like dropping the entire office into a SIP blackhole. The site-to-site bridges still worked, but that was all. We re-enabled SIP-ALG and calls began flowing immediately.

We've turned SIP-ALG off on several sites successfully in the past, but doing it over this connection bit us in the backside.
 
A cautionary tale about turning off SIP-ALG on your firewall. We lost access to one of our branch offices for half a day. Turns out one of our techs disabled SIP-ALG on the firewall and after that no SIP calls were able to be made in or out. Even the denials were no longer logged by the firewall. It was like dropping the entire office into a SIP blackhole. The site-to-site bridges still worked, but that was all. We re-enabled SIP-ALG and calls began flowing immediately.

We've turned SIP-ALG off on several sites successfully in the past, but doing it over this connection bit us in the backside.

SIP ALG should be off. Then add a firewall rules for the 5060 port.

This might be a specific feature of their router. Do you know what it is?
 
We had a specific 5060 rule on the firewall. Turning off the SIP-ALG stopped traffic from being seen on the firewall logs. Was like a stealth mode being applied. Test calls were seen leaving the ISP on Wireshark, but were never seen on our firewall through internal logs or Wireshark. It was like the traffic vanished on the wire.
 
You have a very sketchy firewall there, or a very sketchy config on that firewall then....
 
  • Like
Reactions: Evolute IT
You have a very sketchy firewall there, or a very sketchy config on that firewall then....

Yup, a REALLY sketchy one. Never seen that before!
 
Gents,

I posted this just in case someone else runs into it. Assumption based on zero knowledge is no way to form an opinion.

Just because you've never seen it before, does not invalidate it.
 
Gents,

I posted this just in case someone else runs into it. Assumption based on zero knowledge is no way to form an opinion.

Just because you've never seen it before, does not invalidate it.

Your assuming we are saying it didnt happen, but on the contrary, it is entirely possible you experienced this scenario, however, If you did, then your firewalls configuration, or its firmware is very sketchy.

I have worked with pretty much every firewall vendor in existence in my line of work, and not just for VoIP stuff, VoIP is actually perhaps 1/4 of my workload over the last 3 years, prior to which it was 1/8th. My prior role was as the Senior Network Engineer of 10 years for an IT company that was multinational, so all over the world. So ive worked with SonicWalls, Cisco, PIX(pre and post buyout), microtik, watchguard, fortinet, juniper, barracuda, sophos, pfsense, opnsense, smoothwall, IPFIre, Untangle, ClearOS, Checkpoint, Palo Alto, D-Link, Netgear, and probably more, but those are the ones i have not forgotten.
 
Last edited:
Mods, you can close this thread. It was for info only. Thanks.
 
Status
Not open for further replies.

Forum statistics

Threads
111,928
Messages
589,774
Members
164,799
Latest member
RicoDinero