SIP traffic for VoIP calls does not appear as new connection/unified events in Cisco Secure Firewall Management Center (FMC), even though inbound and outbound calls are completed successfully.
This impacts monitoring and troubleshooting visibility only; call functionality is not affected.
Product: Cisco Secure Firewall
Protocol: SIP over TCP
Port: TCP 5060
No defect or configuration change is required.
This is normal and expected firewall behavior for SIP over TCP.
New SIP connection events only appear if: Existing SIP connections are cleared manually, or the TCP session naturally times out (not typical due to keepalives).
Packet captures and functional call tests confirm traffic is passing correctly.
+-----------+ +-------------------+ +-----------+
| IP Phone | | Cisco Secure FW | | CUCM |
| | | (FTD / FMC) | | |
+-----------+ +-------------------+ +-----------+
| | |
|--- SIP REGISTER (TCP 5060) -------------------->|
| | |
|<-- 200 OK --------------------------------------|
| | |
|==== TCP CONNECTION ESTABLISHED & MAINTAINED ====|
| | |
|--- SIP REGISTER (Keepalive, every ~2 mins) ---->|
| | |
A single long‑lived TCP connection is created.
FMC logs one connection event for TCP 5060.
Periodic REGISTER messages keep the connection alive.
+-----------+ +-------------------+ +-----------+
| IP Phone | | Cisco Secure FW | | CUCM |
| | | (FTD / FMC) | | |
+-----------+ +-------------------+ +-----------+
| | |
|--- SIP INVITE --------------------------------->|
| | |
|<-- 100 Trying / 180 Ringing --------------------|
| | |
|<-- 200 OK --------------------------------------|
| | |
SIP INVITE uses the existing TCP 5060 session.
No new source/destination IP or port.
No new connection‑start event is generated.
This behavior is expected for SIP over TCP:
SIP phones send SIP REGISTER messages periodically (such as every 2 minutes).
These REGISTER messages create long‑lived TCP connections to CUCM on port 5060.
SIP INVITE messages for calls reuse the existing TCP session (same source/destination IP and ports).
Because the firewall is connection‑based, no new connection‑start event is generated when traffic matches an existing connection.
TCP keepalives prevent the connection from timing out, so it remains active in the connection table.
| Revision | Publish Date | Comments |
|---|---|---|
1.0 |
06-Oct-2026
|
Initial Release |