- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- ALG in Checkpoint R80.10
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ALG in Checkpoint R80.10
Hello,
I have been asked by the voice team to check whether ALG is disabled or enabled in my CP GW. I went through a few post in the forums but i am unable to completely understand the concept of ALG. What exactly ALG used for ? How can i disable or enable ALG..steps to do so.If it is disabled what other functions or services can it impact ?
- Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
(ALG is "Application Layer Gateway" for those who don't know)
So the answer is "yes."
If you want to disable it, then you need to replace the pre-defined SIP service with manual rules to allow the specific traffic.
Note if you're using a significant amount of SIP across your gateway, the use of R80.40 is recommended.
This is because our inspection of SIP will now utilize all the cores in your Security Gateway (in previous releases it uses only one core, which can create performance issues).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In any case, it's worth a TAC case to troubleshoot it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We do not do that for SIP traffic currently, which means we cannot see (or translate) the SIP negotiations when NAT is involved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just wanted to pop in and say thank for for this!
we use Jive's hosted voice and their network test was stating that 3 of our sites had SIP ALG enabled.
turns out we had a rule that was using the built in SIP service. disabling that and it appears to have resolved this issue.
thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am agree with you, and I have used this solutions. I have created a new service UDP 5060 withoutu protocol and selected match for any and works in the rules
However, I was reading another article and I would like to know what is the risk for disable SIP ALG by creating an exception for Block SIP Early Media on this inspection setting?
