Hi
Today, I received notification from a customer that the Source Port of the SIP protocol will be automatically changed.
It appears to be connecting to a new server, not the previously used service.
Looking at tcpdump, it looks like this:
Inbound - Source Port 5060 / Destination Port 5060
Outbound - Source Port high-num port / Destionation Port 5060
It is not determined whether this is the normal logic of the checkpoint.
And I have checked the below things to resolve the current situation:
1. NAT configuration
- The customer's firewall is not using NAT rules.
2. SIP Rule
- Uses SIP protocol provided by Check Point
- Manually create TCP and UDP 5060 and apply them to policy --> the result is the same
3. Inspection Setting
- SIP - General Settings - Advanced - NAT Configuraion (unchecked)
Can you give me some advice on my current situation?
Thank you in advance for those who responded