free tool — zero signup

SIP ALG Port Scanner

Scans a target from our edge on ports 5060/5061 and 5062, sends a SIP OPTIONS probe, and compares the signaling that comes back. If the Via header comes back rewritten, there's an ALG in the path. No forms, no sales follow-up.

How it works

The scanner opens a TCP session from our edge to your target on each port, sends a standards-form SIP OPTIONS with a unique branch parameter, and compares the Via header in the response with what was sent. Residential and ISP ALGs rewrite Via and Contact — the response betrays them. Port 5062 is probed as the control: ALGs inspect 5060/5061 only, so a clean 5062 leg next to a rewritten 5060 leg is the signature.

Usage — 3 lines

PS> # quick client-side check of your own edge first
Test-NetConnection -ComputerName sbc.yourdomain.example -Port 5060
Test-NetConnection -ComputerName sbc.yourdomain.example -Port 5062

Then scan the same target from our edge with the form — the two perspectives catch different cases.

Scan a target

rate-limited to 10 scans/min per visitor

We probe only the target you give us, reject private/reserved addresses, and keep no scan logs. Ports probed: 5060, 5061, 5062 — TCP.

If the scan confirms ALG rewriting and you'd rather never think about it again — our signaling runs on 5062 for exactly this reason.

Deploy Free 14-Day Sandbox — No Credit Card Required