Snat with ipsec problem

Newbie452061 Posted 20 Sep 2024 01:17

hello dears when i configure snat for ipsec the nat dosent work , and im sure the configruation is right , i set the lan ip and destantion and nated ip from outbond interface that used for ipsec third party can any one help me ,
Note i tryed snat for another things its work probably , i think i must use the outbund interface vpntunl but i didnt see this interface in option

Farina Ahmed has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Since you don't see the VPN tunnel interface (vpntunl) as an option, it's possible the interface isn't being recognized or hasn't been properly configured for NAT. Kindly check if the VPN tunnel interface is up and properly assigned in the IPsec settings, and ensure that policy-based or route-based IPsec VPN is configured correctly for NAT traversal.
Is this answer helpful?
Farina Ahmed Lv5Posted 23 Sep 2024 14:54
  
Since you don't see the VPN tunnel interface (vpntunl) as an option, it's possible the interface isn't being recognized or hasn't been properly configured for NAT. Kindly check if the VPN tunnel interface is up and properly assigned in the IPsec settings, and ensure that policy-based or route-based IPsec VPN is configured correctly for NAT traversal.
Enrico Vanzetto Lv4Posted 23 Sep 2024 17:58
  
Hi, i suggest you to erform these steps to troubleshoot your SNAT issue for IPsec on Sangfor NGAF:

Verify Interface Assignment: Ensure the outbound interface for the IPsec tunnel is correctly assigned and visible.

Check IPsec Tunnel Configuration: Confirm the tunnel settings allow traffic and are error-free.

SNAT Configuration: Ensure SNAT rules translate the source IP to the outbound interface IP and specify the correct destination zone/interface.

Routing and Policies: Verify routing policies direct traffic through the IPsec tunnel without conflicts.

Logs and Diagnostics: Check logs for errors or warnings related to the IPsec tunnel and SNAT configuration.
Newbie452061 Posted 23 Sep 2024 18:48
  
I check evrythink you talk about , but i see on trublshooting that tha ip route driectly to destinitation ip sec server  insted of make the Snat , mybe the firewall dosent supoort nat for destiontion before route
Newbie452061 Posted 23 Sep 2024 18:54
  
i have another problem is snat when i set snat to destnation the destination still send arp recuest about snat ip

I Can Help:

Change

Moderator on This Board

11
7
5

Started Topics

Followers

Follow

1
3
5

Started Topics

Followers

Follow

0
4
5

Started Topics

Followers

Follow

67
20
3

Started Topics

Followers

Follow

3
14
3

Started Topics

Followers

Follow

1
137
3

Started Topics

Followers

Follow

Board Leaders