Hi @AEK That's the expected behavior. If a tunnel does not have an IP
address assigned, it takes the IP address of the interface with the
lowest index number.
Can you share the system config of your firewall. sh full system
settingsor config system settingssh full You can also verify if traffic
is processed by SIP or SIP-ALG
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-confirm-if-FortiG...
Are you using VOIP profile on firewall policy? If so then SIP traffic is
processed by SIP-ALG and you have RTP disabled on your VOIP config which
means it will block automatic pinhole creation for SIP traffic.