> Source: [sk185138](https://support.checkpoint.com/results/sk/sk185138)

# sk185138 - When 'fw_sip_no_nat_client_comm' is enabled, NAT rules do not apply to SIP traffic

| Property | Value |
|----------|-------|
| Solution ID | sk185138 |
| Date Created | 2026-07-08 |
| Last Modified | 2026-07-15 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |

## Symptoms

- * SIP communication fails after migrating a PBX to Azure.

* The SIP provider does not respond to REGISTER requests.

* Packet captures show SIP UDP port 5060 traffic leaving the Security Gateway with the original source IP address instead of the NAT IP.

* The issue persists even when SIP inspection is disabled and after upgrading firmware.

* On the Security Gateway, the following command returns a value of `1`: `fw ctl get int fw_sip_no_nat_client_comm`.

## Cause

The kernel parameter `fw_sip_no_nat_client_comm` is enabled on the Security Gateway.  
When this parameter is enabled, the packet leaves the appliance toward the SIP provider with the original client source IP instead of the translated source IP. As a result, SIP UDP traffic (port 5060) leaves the Security Gateway with the original source IP address instead of the translated address.  
If the SIP provider allows traffic only from the NAT IP address, it rejects these requests.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
