Trapped into the same. A self-hosted installation of 3CX (not the SBC, the other variant) includes a Firewall checker with a SIP-ALG detector. Not on the first run but on the second, the headers VIA and FROM are changed from the public IP of the Internet access to the private IP of the host machine. Not in the request SIP message sended, only in the response from the remote server. In case of VIA, both the parameter received and the host part. Not sure what’s the benefit of that. Is that a software bug in that module?

That worked as well, thanks!
Web interface → Applications → Plug-ins: kmod-nf-nathelper-extra → Uninstall → Reboot