ExamGecko
Question list
Search
Search

Related questions











Question 287 - PCNSE discussion

Report
Export

After implementing a new NGFW, a firewall engineer sees a VoIP traffic issue going through the firewall After troubleshooting the engineer finds that the firewall performs NAT on the voice packets payload and opens dynamic pinholes for media ports

What can the engineer do to solve the VoIP traffic issue?

A.
Disable ALG under H.323 application
Answers
A.
Disable ALG under H.323 application
B.
Increase the TCP timeout under H.323 application
Answers
B.
Increase the TCP timeout under H.323 application
C.
Increase the TCP timeout under SIP application
Answers
C.
Increase the TCP timeout under SIP application
D.
Disable ALG under SIP application
Answers
D.
Disable ALG under SIP application
Suggested answer: D

Explanation:

According to the Palo Alto Networks documentation1, application-level gateway (ALG) is a feature that allows the firewall to inspect and modify the payload of some protocols, such as SIP, to enable NAT traversal and firewall policy enforcement. However, ALG can also cause issues with some VoIP implementations, such as modifying the SIP headers incorrectly or opening unnecessary pinholes for media ports. Therefore, disabling ALG under SIP application can help solve the VoIP traffic issue by preventing the firewall from altering the voice packets payload and opening dynamic pinholes2.

Therefore, the correct answer is D.

The other options are not relevant or helpful for solving the VoIP traffic issue:

Disable ALG under H.323 application: This option would disable ALG for H.323 protocol, which is another VoIP protocol, but not the one used in this scenario. The scenario mentions SIP as the signaling protocol, so disabling ALG under

H.323 application would have no effect on the VoIP traffic issue.

Increase the TCP timeout under H.323 application: This option would increase the TCP timeout for H.323 protocol, which is another VoIP protocol, but not the one used in this scenario. The scenario mentions SIP as the signaling protocol, which uses UDP by default, so increasing the TCP timeout under H.323 application would have no effect on the VoIP traffic issue.

Increase the TCP timeout under SIP application: This option would increase the TCP timeout for SIP protocol, which is the signaling protocol used in this scenario. However, SIP uses UDP by default, so increasing the TCP timeout would have no effect on the VoIP traffic issue. Moreover, increasing the TCP timeout would not address the problem of NAT on the voice packets payload and dynamic pinholes for media ports.

Reference: 1: https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/app-id/disable-the-sipapplication-level-gateway-alg 2:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEsCAK

asked 23/09/2024
Aleksey Koltsov
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first