<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIP Inspection / ALG in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120282#M17023</link>
    <description>&lt;P&gt;Can you share the doc you have, I want to make sure it is the correct one?&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jun 2021 11:40:04 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-06-03T11:40:04Z</dc:date>
    <item>
      <title>SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120280#M17022</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a formal CheckPoint document showing how to completely disable SIP inspection from both gaia and embedded gaia appliances? or something to completely confirm the status of SIP ALG?&lt;/P&gt;&lt;P&gt;From what was found even from community is that in order to disable SIP inspection, one needs to create a custom port for 5060 with match for any and included it in the rules. However I need to make sure that actually firewall is not doing SIP inspection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 11:31:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120280#M17022</guid>
      <dc:creator>lullejd</dc:creator>
      <dc:date>2021-06-03T11:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120282#M17023</link>
      <description>&lt;P&gt;Can you share the doc you have, I want to make sure it is the correct one?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 11:40:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120282#M17023</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-03T11:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120283#M17024</link>
      <description>&lt;P&gt;Could you please elaborate? Which particular community recommendations are you trying to follow?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 11:49:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120283#M17024</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-06-03T11:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120284#M17025</link>
      <description>&lt;P&gt;I was looking at this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/How-to-disable-SIP-ALG-inspection-in-a-specific-rule-in/td-p/25249" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/How-to-disable-SIP-ALG-inspection-in-a-specific-rule-in/td-p/25249&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Specifically to this:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Define your own UDP or TCP object without a protocol handler. For example: Name it SIP-BARE and use UDP/5600&lt;/LI&gt;&lt;LI&gt;Make sure you enable "Match for Any" on your own service and disable it on the existing service.&lt;/LI&gt;&lt;LI&gt;Make a rule for you own service AND!!!! make sure it is ABOVE any rule that uses the build in SIP services (which contains handlers).&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Apart from that we also did this sk:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157994&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk157994&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To be honest, in my opinion there should be an official SK from CheckPoint what needs to be done in order to disable SIP inspection on both gaia and embedded at this stage.There is also this sk:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65072&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65072&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;&lt;P&gt;which does not exactly specify.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 11:50:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120284#M17025</guid>
      <dc:creator>lullejd</dc:creator>
      <dc:date>2021-06-03T11:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120285#M17026</link>
      <description>&lt;P&gt;Not getting this, what is missing in&amp;nbsp;&lt;SPAN&gt;sk65072, in your opinion?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 11:53:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120285#M17026</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-06-03T11:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120286#M17027</link>
      <description>&lt;P&gt;For example, embedded gaia gateways (running R80.20.x), R80.40 and R81 procedures&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 11:56:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120286#M17027</guid>
      <dc:creator>lullejd</dc:creator>
      <dc:date>2021-06-03T11:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120287#M17028</link>
      <description>&lt;P&gt;Fair enough.&lt;/P&gt;
&lt;P&gt;The SK is describing procedures to disable SIP inspection for performance reasons. If this is your case, and you are running R80.40 or above, you do not need to disable it. If you still want to disable, it is the same procedure for all R8x, just follow the relevant section.&lt;BR /&gt;&lt;BR /&gt;If your R80.20 SMB is centrally managed, the described changes will do too.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Now, let me ask, why do you need to disable it in the first place?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 12:36:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120287#M17028</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-06-03T12:36:50Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120288#M17029</link>
      <description>&lt;P&gt;Hi Val,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SIP inspection needs to be disabled since there are intermittent issue with voice and we need to make sure is not being done by checkpoint. SIP Headers will be modified directly by the PABX rather than the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 12:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120288#M17029</guid>
      <dc:creator>lullejd</dc:creator>
      <dc:date>2021-06-03T12:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120293#M17032</link>
      <description>&lt;P&gt;FW does not modify SIP headers, but once again, follow the procedure mentioned in the above SK.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, and actually before you do that, why wouldn't you ask TAC to help you figuring out the actual issue in hands?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 13:40:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120293#M17032</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-06-03T13:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120295#M17034</link>
      <description>&lt;P&gt;I've already opened a case with TAC around 2 weeks ago but given the reply I got I don't have high hopes to be honest. I asked for SIP inspection and was pointed to HTTPS inspection &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; That's why i'm asking here maybe someone has experienced such issues with SIP and overcome them.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 13:44:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120295#M17034</guid>
      <dc:creator>lullejd</dc:creator>
      <dc:date>2021-06-03T13:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120300#M17038</link>
      <description>&lt;P&gt;Please PM me with your SR number&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 14:43:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120300#M17038</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-06-03T14:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120301#M17039</link>
      <description>&lt;P&gt;Thanks Val. Sent you pm.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 14:48:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120301#M17039</guid>
      <dc:creator>lullejd</dc:creator>
      <dc:date>2021-06-03T14:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120342#M17052</link>
      <description>&lt;P&gt;Strangely enough, I do not see any message from you. would you care to send your SR to vloukine@checkpoint.com?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 07:14:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120342#M17052</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-06-04T07:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120344#M17053</link>
      <description>&lt;P&gt;Thanks Val. Sent it via email.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 07:20:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/120344#M17053</guid>
      <dc:creator>lullejd</dc:creator>
      <dc:date>2021-06-04T07:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/178974#M32793</link>
      <description>&lt;P&gt;Quick question.&amp;nbsp;&lt;BR /&gt;if predefined services are applied in any rule, but in your certain rule you applied your owd defined services, would it work so?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 18:56:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/178974#M32793</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2023-04-24T18:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: SIP Inspection / ALG</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/179104#M32836</link>
      <description>&lt;P&gt;It depends on the precise rules in your rulebase.&lt;BR /&gt;Refer to the following for a detailed explanation of how rulebase matching works:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Management/Unified-Policy-Column-based-Rule-Matching/m-p/9888#M1693" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Unified-Policy-Column-based-Rule-Matching/m-p/9888#M1693&lt;/A&gt;&lt;BR /&gt;Basically, if multiple rules potentially match the same source/destination/service, where service is the specific TCP/UDP ports involved, then you might have issues if you're trying to avoid certain protocol handlers like SIP.&lt;BR /&gt;If you want to ensure that a certain protocol handler isn't used, then focused rules (possibly using inline layers) are key.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 15:48:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SIP-Inspection-ALG/m-p/179104#M32836</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-25T15:48:08Z</dc:date>
    </item>
  </channel>
</rss>

