<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Handling voip behind ION 1200S in Prisma SD-WAN Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/handling-voip-behind-ion-1200s/m-p/1249914#M341</link>
    <description>&lt;P&gt;HI Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am new to Palo Community, and having difficulty in getting sip trunk up and running behind the ION 1200S&lt;/P&gt;
&lt;P&gt;We have a NEC PABX behind ION 1200S&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SIP ALG is disabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The carrier wants to receive the Public IP address as contact address but NEC is sending the local ip address&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thats the reason carrier is sending 403&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should I set a DNAT for the PABX to make it work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL class="marker:text-quiet list-disc"&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Create&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Static NAT&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rule (Policies &amp;gt; NAT):&lt;/P&gt;
&lt;UL class="marker:text-quiet list-disc"&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Original Packet: Source zone untrust → trust; Source any (or SV9100 subnet); Destination ITSP IPs/FQDN (use FQDN objects); Service sip + RTP range (UDP 5060, 10020-10533).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Translated Packet:&lt;/P&gt;
&lt;UL class="marker:text-quiet list-disc"&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Destination: SV9100 IP A (SIP) on inbound.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Source: Static IP = your public IP (bidirectional checked).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Security policy: Allow sip/sip-trunk app-id, service UDP/TCP 5060 + RTP; log all sessions.&lt;SPAN class="inline-flex" data-state="closed" aria-label="How to Configure the 'sip-trunk' App-ID - Clear"&gt;​&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;&lt;STRONG&gt;Critical&lt;/STRONG&gt;: Disable SIP ALG (Device &amp;gt; Setup &amp;gt; Session &amp;gt; SIP ALG off) to prevent mangling of SDP/register headers.&lt;BR /&gt;&lt;BR /&gt;Please help me to understand how i can make it work&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;
&lt;P&gt;Tushar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Mar 2026 06:13:46 GMT</pubDate>
    <dc:creator>T.Jain081923</dc:creator>
    <dc:date>2026-03-11T06:13:46Z</dc:date>
    <item>
      <title>Handling voip behind ION 1200S</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/handling-voip-behind-ion-1200s/m-p/1249914#M341</link>
      <description>&lt;P&gt;HI Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am new to Palo Community, and having difficulty in getting sip trunk up and running behind the ION 1200S&lt;/P&gt;
&lt;P&gt;We have a NEC PABX behind ION 1200S&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SIP ALG is disabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The carrier wants to receive the Public IP address as contact address but NEC is sending the local ip address&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thats the reason carrier is sending 403&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should I set a DNAT for the PABX to make it work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL class="marker:text-quiet list-disc"&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Create&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Static NAT&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rule (Policies &amp;gt; NAT):&lt;/P&gt;
&lt;UL class="marker:text-quiet list-disc"&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Original Packet: Source zone untrust → trust; Source any (or SV9100 subnet); Destination ITSP IPs/FQDN (use FQDN objects); Service sip + RTP range (UDP 5060, 10020-10533).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Translated Packet:&lt;/P&gt;
&lt;UL class="marker:text-quiet list-disc"&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Destination: SV9100 IP A (SIP) on inbound.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Source: Static IP = your public IP (bidirectional checked).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;Security policy: Allow sip/sip-trunk app-id, service UDP/TCP 5060 + RTP; log all sessions.&lt;SPAN class="inline-flex" data-state="closed" aria-label="How to Configure the 'sip-trunk' App-ID - Clear"&gt;​&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="py-0 my-0 prose-p:pt-0 prose-p:mb-2 prose-p:my-0 [&amp;amp;&amp;gt;p]:pt-0 [&amp;amp;&amp;gt;p]:mb-2 [&amp;amp;&amp;gt;p]:my-0"&gt;
&lt;P class="my-2 [&amp;amp;+p]:mt-4 [&amp;amp;_strong:has(+br)]:inline-block [&amp;amp;_strong:has(+br)]:pb-2"&gt;&lt;STRONG&gt;Critical&lt;/STRONG&gt;: Disable SIP ALG (Device &amp;gt; Setup &amp;gt; Session &amp;gt; SIP ALG off) to prevent mangling of SDP/register headers.&lt;BR /&gt;&lt;BR /&gt;Please help me to understand how i can make it work&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;
&lt;P&gt;Tushar&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 06:13:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/handling-voip-behind-ion-1200s/m-p/1249914#M341</guid>
      <dc:creator>T.Jain081923</dc:creator>
      <dc:date>2026-03-11T06:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Handling voip behind ION 1200S</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/handling-voip-behind-ion-1200s/m-p/1249968#M342</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/683573585"&gt;@T.Jain081923&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SIP ALG on the NGFW inspects the SIP header to perform 2 functions:&amp;nbsp; (1) open pinholes for the media traffic based upon the endpoint IP addresses and ports specified in the SIP packets, and (2) performs a NAT rewrite of SIP fields to change the private IP address to the public IP address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/ngfw/administration/app-id/application-level-gateways" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/ngfw/administration/app-id/application-level-gateways&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Most VoIP vendors recommend disabling SIP ALG on ALL vendor's firewalls because it has repeatedly broken voice traffic.&amp;nbsp; My own experience confirms this behavior.&amp;nbsp; It is not necessarily the firewall vendors' fault.&amp;nbsp; Many VoIP vendors implementations are different, and they change it whenever they want.&amp;nbsp; Keeping SIP ALG up-to-date with the many vendors then becomes an administrative burden.&amp;nbsp; PANW probably implemented their SIP ALG based upon RFC 3665 and has no desire to keep up with proprietary changes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can try to enable SIP ALG and see if it fixes your issue.&amp;nbsp; If not, you will need to manually configure the 2 functions listed above:&amp;nbsp; (1) manually configure rules to allow the media traffic, and (2) manually configure the PBX to rewrite the SIP information.&amp;nbsp; The rewrite usually involves some combination of the&amp;nbsp;&lt;SPAN&gt;SIP header From, Contact, and Via fields, and SDP header (inside the SIP packet) Audio-Connection-Info and Connection-Info fields.&amp;nbsp; You will need a NEC PBX manual to configure it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A far easier solution would be to put the PBX on a DMZ where it can have a public IP address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tom&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 23:26:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-sd-wan-discussions/handling-voip-behind-ion-1200s/m-p/1249968#M342</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-03-11T23:26:46Z</dc:date>
    </item>
  </channel>
</rss>

