Hello colleague @TomYoung
Thanks for your time and great response. A few months ago I experienced a similar issue, where from version 8.0, we upgraded the firewalls to 9.1.14. And of course after this, this began to occur problems with SIP with TCP, especially with the registration of IP phones and one-way calls.
Yes, the first thing we proceeded to do was to disable the ALG of the SIP app, after that there was some improvement, but the problem kept repeating, so we had to create an app override, for all SIP flows in TCP and UDP.
You know, and I discussed this with TAC and their answer was super ambiguous, where for example if you check the known issues, from all versions 9.1.X to 9.1.14 there is nothing about SIP with TCP. Now if you look at the Addresses Issues, from version 9.1.14h1, 9.1.14h4 and 9.1.15 there are several address Issues, such as:
"Fixed an issue where Session Initiation Protocol (SIP) REGISTER packets did not get transmitted when application-level gateway (ALG) and SIP Proxy were enabled, which caused a SIP-registration issue in environments where TCP retransmission occurred.". But if you check the Known Issues and the consolidated, they don't point out anything about SIP, but then they are pointed out as Addresss Issues.
-https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-addressed-issues/pan-os-9-1-14-h1-addressed-issues#panos-addressed-issues-9.1.14
-https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-release-information/known-issues/known-issues-related-to-pan-os-9-1-releases
I contacted TAC, and they first did not give me an answer to the issue, and then just said that this came from version 9.0, but had not been published in 9.1 because they could not be detailing the issues cumulatively ... but this if they do in other cases, with other issues, but with these SIP issues, they acted differently and to me it seemed a little negligent and somewhat terse response.
I still have not been able to update those FWs due to operation issues to 9.1.14H4 or 9.1.15, although at this point we should be at least in 10.1.X with this partner, but it has been complicated by the operation issues and that they give dates for maintenance windows.
For the same reason I was asking about these options, normally nobody modifies them, nor touches them, there are not many comments, nor is there much documentation or detail about these options, therefore I was asking, if someone has made you feel these options or if you have had to deal with scenarios where you have to modify the parameters of SIP TCP cleartext, in scenarios with SIP with TCP.
Thanks for your time, comments, details and advice.
Best regards
High Sticker