Exam PCNSE All QuestionsBrowse all questions from this exam
Question 520

After implementing a new NGFW, a firewall engineer sees a VoIP traffic issue going through the firewall. After troubleshooting, the engineer finds that the firewall performs NAT on the voice packets payload and opens dynamic pinholes for media ports.

What can the engineer do to solve the VoIP traffic issue?

    Correct Answer: D

    The issue described involves NAT modification of voice packets' payload and the opening of dynamic pinholes for media ports. An Application-Level Gateway (ALG) tends to interfere with VoIP signaling, especially with protocols like SIP (Session Initiation Protocol). By disabling the SIP ALG, the firewall will stop making unnecessary modifications to the payload, allowing the VoIP traffic to be handled correctly by native NAT intelligence in the client application.

Discussion
mercysayno765Option: D

Agree with D https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/app-id/disable-the-sip-application-level-gateway-alg

Merlin0o

From the provided link: The Palo Alto Networks firewall uses the Session Initiation Protocol (SIP) application-level gateway (ALG) to open dynamic pinholes in the firewall where NAT is enabled. However, some applications—such as VoIP—have NAT intelligence embedded in the client application. In these cases, the SIP ALG on the firewall can interfere with the signaling sessions and cause the client application to stop working. One solution to this problem is to define an Application Override Policy for SIP, but using this approach disables the App-ID and threat detection functionality. A better approach is to disable the SIP ALG, which does not disable App-ID or threat detection.

MarshpillowzOption: D

D is correct