Source record · tier 2 current vendor documentation
SIP ALG | Junos OS
- Publisher
- Juniper Networks
- URL
- https://www.juniper.net/documentation/us/en/software/junos/alg/topics/topic-map/security-sip-alg.html
- Published
- unknown
- Updated
- unknown
- Accessed
- 2026-09-25
- HTTP status
- 200
- License
- Juniper copyright; all rights reserved; no-redistribution; short excerpts and locators only
Source notes citing this source
- An ALG can be detected by capturing the same SIP message on both sides of the NAT device. If Via, Contact, Record-Route or the SDP c= and m= values differ between the two captures, the device has rewritten the SIP payload, beyond translating the IP and UDP headers. inferred in context
- Juniper's SIP ALG topic page states that the SIP ALG is disabled by default on SRX devices and enabled by default on other devices. disputed in context
- The Junos SIP ALG monitors SIP transactions and dynamically creates pinholes for RTP and RTCP, based on the addresses and ports it extracts from the SDP. in context
- Juniper documents that the Junos SIP ALG modifies the Via, Contact, Route and Record-Route headers and the SDP c= and m= fields. in context
- On Junos OS, show security alg status in operational mode shows whether the SIP ALG is enabled. in context
- One-way or no audio is a plausible result of an ALG that rewrites the SDP c= or m= values incorrectly, or opens RTP pinholes for the wrong address or port. The far end then sends RTP to a destination that does not reach the phone. inferred in context
Cite this source record
APA
WarmTransfer. (2026, September 25). SIP ALG | Junos OS. WarmTransfer. https://warmtransfer.net/knowledge/sources/juniper-junos-sip-alg-topic
BibTeX
@misc{warmtransfer-juniper-junos-sip-alg-topic,
title = {SIP ALG | Junos OS},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/sources/juniper-junos-sip-alg-topic},
note = {Juniper Networks, accessed 2026-09-25}
}