On a supported BT Business Hub, open 192.168.1.254 or businesshub.home, choose Advanced Settings, authenticate, open Firewall > Configuration and set Disable SIP ALG to Yes under Application Layer Gateway, then Apply and retest.
Identify the exact BT Hub first
BT Business Hubs and consumer Home/Smart Hubs do not expose the same controls. The steps below come from BT Business guidance. If the page or switch is absent, do not assume hidden consumer-hub commands exist.
- Read the exact model and firmware from the hub status page or label.
- Back up or record broadband, DHCP, port-forward and firewall settings before the change.
- Confirm whether the BT Hub is the edge router or sits in front of another firewall, creating double NAT.
- Make the change from a wired or trusted local connection, not remote WAN management.
Some BT Home Hub and Smart Hub consumer variants do not provide a customer SIP ALG toggle. If the documented Business Hub control is missing, ask BT about the exact model, use a supported modem/bridge arrangement, or place a suitable business firewall at the edge.
Disable SIP ALG on the supported Business Hub
- 1Open the hub
Browse to http://192.168.1.254 or http://businesshub.home from the trusted LAN.
- 2Open Advanced Settings
Select Advanced Settings and enter the hub administrator password when prompted. This is not the Wi-Fi password unless the device label or administrator changed it that way.
- 3Open Firewall configuration
Select Firewall, then Configuration, and scroll to the Application Layer Gateway section.
- 4Select the documented option
Set Yes next to Disable SIP ALG. This wording is intentionally inverted: Yes means the ALG is switched off.
- 5Apply the setting
Select Apply and wait for the hub to confirm. Restart the affected SIP registration or endpoint if needed so it creates fresh state.
Keep the BT Hub firewall secure
Do not switch off the firewall, enable DMZ for a telephone system or create an unrestricted SIP port forward. Disabling SIP ALG stops application-layer rewriting; it does not remove the need for normal firewall and PBX protections.
- Remove test port forwards that are not required by the final supported design.
- For direct IP, restrict signalling and media to the account-specific UKDDI allowlists.
- For registered phones and trunks, prefer outbound state and the application’s supported keepalive/registration interval.
- Use a separate voice VLAN where the network design supports it and keep hub/phone management private.
Prove the change fixed the original symptom
- 1Watch registration
Confirm the trunk or phone remains registered through at least two refresh cycles.
- 2Test inbound and outbound
Use external numbers you control and confirm routing and approved caller ID.
- 3Test media and duration
Check two-way audio, keypad tones, hold and a call longer than five minutes.
- 4Check double NAT if faults remain
If another router is downstream or an upstream service also performs NAT/ALG, document both layers before making further changes.