How to disable SIP ALG on the Comcast Business Gateway DPC3941B
Router & ISP SIP ALG issuesMANUAL FIX INSIDEFREE — NO SIGNUP
Quick answer. The DPC3941B runs SIP ALG on ports 5060/5061 by default, and it silently rewrites the Via and Contact headers of SIP signaling passing through it. When the ACK confirming a call is mangled or dropped by that rewriting, the SBC's Timer H expires exactly 32 seconds (64×T1) after the 200 OK — RFC 3261 — and the call drops, every single time. The fix is to disable SIP ALG in the gateway where the firmware exposes it — and on firmware where the toggle is hidden or ineffective, to move SIP signaling to port 5062, which the ALG never inspects.
The raw code check
Run this before you change anything — it confirms the root cause in one pass:
signaling through the DPC3941B on 5060FAIL
Via: SIP/2.0/UDP 10.0.0.14:5060;branch=z9hG4bK1ab2 ← rewritten
Contact: <sip:2001@73.12.8.44:5060> ← ALG-injected public Contact
ACK ... corrupted in transit
BYE at T+32.0s — Timer H expiry, call dropped
signaling via 5062 (or ALG off)OK
Via: SIP/2.0/UDP 10.0.0.14:5062;branch=z9hG4bK1ab2 ← intact
Contact: <sip:2001@73.12.8.44:5062> ← as sent
ACK → received, 200 OK → confirmed
call continues past 32s — no Timer H expiry
The manual fix — 3 steps
- Disable SIP ALG in the gateway admin (where exposed). Browse to the gateway admin page (default 10.0.0.1) with the account credentials on the device label, open the Firewall / advanced settings area, and disable SIP ALG (labeled "SIP ALG", "SIP passthrough", or under custom firewall levels). Save and reboot the gateway. On some DPC3941B firmware this toggle exists; on some it does not.
- If the toggle is missing or the drops continue, move signaling to port 5062. SIP ALG inspection applies to 5060/5061 only. Changing the worker's SIP client (or your SBC edge) to listen and send on port 5062 bypasses the ALG entirely — this works even on firmware where the toggle is hidden or where ALG stays on after "disabling" it. Note this applies to the customer's own SIP endpoints; VoipFlow's signaling runs on 5062 for exactly this reason.
- Verify with a scan and a real call. Run the free SIP ALG Port Scanner against the worker's public IP to confirm 5060 shows rewriting while 5062 passes clean, then place a 5-minute test call: a call that survives past the 32-second mark with two-way audio confirms the fix better than any dashboard.
The automated alternative
If you'd rather never do this again: VoipFlow runs this whole class of maintenance as software — certificate issue-and-bind in about 12 seconds, signaling on port 5062 so SIP ALG rewriting never engages, per-tenant isolation, flat $399/mo. The 14-day sandbox is free, no credit card, and no sales follow-up unless you ask for one.
Deploy Free 14-Day Sandbox — No Credit Card Required