Indeed they would also keep a firewall state open, however with Sipgate on IPv6, incoming signalling for calls on port 5060 can arrive from several different IPv6 servers with different addresses, so keepalives anyway are not reliable on IPv6 with Sipgate, as the firewall will only allow in packets from the original IPv6 address that is 'keeping alive' the firewall state. To make it all work, I simply have a firewall rule that allows all traffic in from Sipgate's IPv6 range (2001:ab7::/32), therefore no keepalives.