cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

Who Me Too'd this topic

SIP traffic being dropped in drop.pcap on the PA with PAN OS version 10.2.4-h2

L1 Bithead

SIP traffic is not working properly, we recently upgraded to PAN OS version 10.2.4-h2 and seeing issues with multiline calls

 

Steps taken:

ALG is disabled, we have already created SIP-override and RTP override but no luck.

@Param_Upadhyay @UtkarshKumar 

We then did a packet capture and found that SIP traffic flow completes fine and call works fine but when user tries to add any other user, we see a Re-invite from CUCM IP to the device IP generating the call and that traffic is being dropped in the firewall drop.pcap.

 

Didar_Bajwa_1-1690500469057.png

 

Now, as per the wireshark logs, we suspect this to be a MTU issue as payload is around 1511. As a workaround, we have removed information from the SIP profile to reduce it's size and as expected that has resolved the issue. The info I removed is display/party information so effectively I've disabled caller ID.While technically leaving it disabled is not a solution

 

But this was working fine without any issues on the previous version , so why it is being dropped in drop.pcap now on a higher version.

 

So, looking for some suggestions or insights if anyone else is facing the same issue.

 

Who Me Too'd this topic