Hi
Today, I received notification from a customer that the Source Port of the SIP protocol will be automatically changed.
It appears to be connecting to a new server, not the previously used service.
Looking at tcpdump, it looks like this:
Inbound - Source Port 5060 / Destination Port 5060
Outbound - Source Port high-num port / Destionation Port 5060
![SIP.png SIP.png](https://community.checkpoint.com/t5/image/serverpage/image-id/22863i9D57085D5F87EA5F/image-size/large?v=v2&px=999)
It is not determined whether this is the normal logic of the checkpoint.
And I have checked the below things to resolve the current situation:
1. NAT configuration
- The customer's firewall is not using NAT rules.
2. SIP Rule
- Uses SIP protocol provided by Check Point
- Manually create TCP and UDP 5060 and apply them to policy --> the result is the same
3. Inspection Setting
- SIP - General Settings - Advanced - NAT Configuraion (unchecked)
![2023-10-19_11-01-48.png 2023-10-19_11-01-48.png](https://community.checkpoint.com/t5/image/serverpage/image-id/22862i14371DAB7061EE87/image-size/large?v=v2&px=999)
Can you give me some advice on my current situation?
Thank you in advance for those who responded