Good afternoon, Gilson! All right?
I'm William, Blockbit analyst.
According to their account (some of them register and others receive 408 Request Timeout via VPN), it is very likely that the SIP ALG is interfering with the Contact header and or the maintenance of the source ports, generating inconsistencies in the return of PBX. In scenarios SIP over VPN, ALG is usually not necessary and may even disturb, as the tunnel already guarantees transport and the NAT should not “mexere” in traffic.
What you should do:
- Disable SIP-ALG in firewall.
- Disable H.323-ALG (not used in SIP, but remove any interference in VoIP).
Use these commands in the firewall CLI from 2.4.1:
disable-sip
disable-h323
After that, re-validate the branch register.
About SIP/H323:
SIP: Most common signage protocol today (port 5060/5061), uses messages like REGISTER/INVITE and loads addresses/doors in SDP. Therefore, ALG “rewrites” can break the return if there is VPN/NAT on the way.
H.323: older VoIP/videoconferencing pattern, with multiple control channels and media. It also has ALG itself; if not used, it is best to keep it disabled so as not to inspect undue traffic.