“Unchange” BNAT Cannot Work On Certain Environment

|
  • 129
  • 7

Issue Description

The customer requirement is using telnet to server port 445 by using public IP 192.168.19.40, but the result will fail.

Handling Process


From the BNAT configuration, we can see the Bidirectional NAT -> Translate Src To was set to “Unchanged

Root Cause

Unchanged” setting will not work in this environment. Because the translate scr PC is configured to “Unchanged” so it will be using original host IP to access the server. The PC and the server are in the same network segment, so the return traffic from Server will not pass through the firewall, it will direct forward back to PC since the server knows where the pc is. It will cause 3 way handshake failed.

Solution

The solution is changing Translate Src To to “Egress interface” so it will use firewall IP to access the server instead of host IP, the return will also using firewall IP.
Faisal Posted 22 Aug 2020 06:55
  
Thank you very much for the information ...
Muhammad Bilal Lv4Posted 14 Sep 2020 02:51
  
Great issue resolution
Faisal Posted 22 Oct 2020 12:30
  
Nice article ...
Faisal Posted 19 Dec 2020 10:32
  
Great info ...
Ellechar Lv4Posted 25 Jan 2021 16:47
  
Very nice infoooooooooooooooooooooooooooooo
Faisal Posted 20 Mar 2021 08:24
  
Very informative …
Faisal Posted 05 Jun 2021 00:08
  
Nice guidance ...

I want to write a case
Doc ID: 2401
Author: LamWeiSiang
Updated: 2019-12-22 18:02
Version: