I cannot provide a pcap as there's too much private information, but I have prepared a graphical representation of the flow in both cases and a sanitized text dump of the SIP dialog in both cases. I hope this sufficiently illustrates the problem.
So there are two things a) duplicated INVITE (second is missing the Contact: header) b) the ACK and BYE are not relayed to the correct IP address
As mentioned I can reproduce this with certainty any time. Endpoints that are not behind NAT don't seem affected.

[badcall-sanitized.txt](https://github.com/kamailio/kamailio/files/791821/badcall-sanitized.txt) [goodcall-sanitized.txt](https://github.com/kamailio/kamailio/files/791823/goodcall-sanitized.txt)