Packet capture on a laptop running a SIP client shows that packets are being received on the external unit, but packets are hitting the NAT and being dropped when trying to re-enter the network. PBX has a static NAT to an external IP. External unit registers via PBX external. External unit makes call. PBX connects to internal phone and sets up the call. Internal phone takes the call and tries to communicate with external unit via default dynamic-port-and-ip NAT (different IP than PBX external). Traffic flows from internal to external via default NAT, but not vice versa. The issue is that the traffic cannot re-enter the network via the dynamic-port-and-ip NAT. Our old Juniper SRX-240B did not have this issue, as it would route all SIP traffic back out the PBX external IP in it's default behavior (from what I've been told). This would utilize the static NAT and not the dynamic NAT. Still working with someone from Palo Alto..
... View more