Source note · SIP ALG problems on firewalls and routers
With PAT on the ASA, a SIP header field that contains an internal IP address without a port might not be translated, leaking the internal address outside. Cisco suggests NAT instead of PAT to avoid this.
Checked 2026-09-25
- Vendor
- Cisco
- Product
- Cisco Secure Firewall ASA
- Subsystem
- application inspection
- Deployment
- on-premises
- Region
- not restricted
- Release range
- ASA 9.23
- Checked
- 2026-09-25
Sources
- CLI Book 2: Cisco Secure Firewall ASA Firewall CLI Configuration Guide 9.23 - Inspection for Voice and Video Protocols — Cisco Systems · tier 2 current vendor documentation · SIP Inspection > PAT Limitations for SIP Inspection
Cite this note
APA
WarmTransfer. (2026, September 25). SIP ALG problems on firewalls and routers: source note sip-alg-problems-asa-pat-ip-leak. WarmTransfer. https://warmtransfer.net/knowledge/claims/sip-alg-problems-asa-pat-ip-leak
BibTeX
@misc{warmtransfer-claim-sip-alg-problems-asa-pat-ip-leak,
title = {SIP ALG problems on firewalls and routers: source note sip-alg-problems-asa-pat-ip-leak},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/sip-alg-problems-asa-pat-ip-leak},
note = {Source note sip-alg-problems-asa-pat-ip-leak, checked 2026-09-25}
}