MISMDS Lv3Posted 18 Dec 2022 14:06
  
I think it is a bug on the side of Sangfor
Konstantin Lv1Posted 18 Dec 2022 19:51
  
Funny! Looks like NGAF bug.
It worse when I deleted NAT policy:
Old connection is working. I was waiting for 5 minitues but traffic didn't stop.
New connection's doesn't work.

3905639efe5845692.png (28.03 KB, Downloads: 288)

3905639efe5845692.png
Konstantin Lv1Posted 18 Dec 2022 19:54
  
...... and right after reboot NGAF device, everythig works as it shoud:

Konstantin Lv1Posted 18 Dec 2022 20:17
  
.... then, I create new S-NAT -bingo (really not)
Some old connection are still in block mode....


PS Really raw solution. Is someone using NGAF in production?
Noah19 Lv3Posted 18 Dec 2022 22:01
  
can you delete the SNat and do the Dnat
Konstantin Lv1Posted 19 Dec 2022 04:19
  
Dnat - is completely different feature (function).
And additionally I don't see any means how to DNATing ICMP packets. It seems works for UDP/TCP only.....
Pat Lv4Posted 19 Dec 2022 13:54
  
For fast solution, just clear the whole config
noime Lv3Posted 19 Dec 2022 14:08
  
try to delete all the NAT config and return one at at time
Franky Lv3Posted 19 Dec 2022 14:23
  
Reset all the translations
Konstantin Lv1Posted 19 Dec 2022 14:27
  
Everything works if you delete NAT rule then create new and restart device.
It is acceptable for student's lab but completely not acceptable for corporate network.
For me it is unclear how Gartner mentioned NGAF in their report.....

I Can Help:

Change

Moderator on This Board

11
7
5

Started Topics

Followers

Follow

1
3
5

Started Topics

Followers

Follow

0
4
5

Started Topics

Followers

Follow

67
20
3

Started Topics

Followers

Follow

3
14
3

Started Topics

Followers

Follow

1
137
3

Started Topics

Followers

Follow

Board Leaders