In Sangfor NGAF firewall, how could we bypass stateful traffic inspection on LAN port.
  

Newbie184795 Lv1Posted Mar-13-2025 11:21

Last edited by Newbie184795 2025-Mar-13 11:23.

All of our devices are using Sangfor NGAF LAN IP (192.168.10.1) as default gateway.
I have setup a new Site-to-Site VPN device (192.168.10.252).
I create a static route in Sangfor NGAF  (192.168.12.0/24 192.168.10.252)

But when I traceroute on user machine, it keeps stuck at 192.168.10.1 and not going to next hop 192.168.10.252.  I suspect the stateless traffic is being blocked.

When I create a static route on Windows machine, it can route to next hop 192.168.10.252.

Any idea?
Great thanks.
  

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Zonger Lv5Posted Mar-14-2025 06:49
  
The issue likely stems from the Sangfor NGAF lacking a firewall policy permitting traffic to 192.168.12.0/24 or NAT interfering. Create a Policy Route under Policy > Routing > Policy Routing: set source IP, destination (192.168.12.0/24), action Forward, next-hop 192.168.10.252. Ensure no NAT rules apply to this traffic (disable NAT in the policy). Verify the static route is prioritized over default routes and confirm bidirectional firewall rules allow the traffic. Use Diagnostics > Packet Capture on the NGAF to check if traffic egresses toward 192.168.10.252.
AR Lv2Posted Mar-14-2025 14:06
  
Hello,
The problem is probably caused by NAT interfering or the Sangfor NGAF not having a firewall policy that allows traffic to 192.168.12.0/24.  Under Policy > Routing > Policy, create a Policy Route.  Routing: action Forward, next-hop 192.168.10.252, destination (192.168.12.0/24), and source IP configured.  Make sure that this traffic is not subject to any NAT rules by disabling NAT in the policy.  Make sure the bidirectional firewall rules permit the traffic and that the static route is given priority over the default routes.  Use the NGAF's Diagnostics > Packet Capture to see if traffic is egressing towards 192.168.10.252.
Newbie184795 Lv1Posted Mar-17-2025 11:51
  
Thank you Zonger and AR for your comments.

I have created a policy route and specify the source and destination.  
However, it still does not work.
The user machine still stuck at default gateway 192.168.10.1 (Sangfor LAN port) and not going to next hop 192.168.10.252.

I also run the packet capture, no clue also.

No idea why the Sangfor NGAF not willing to route 192.168.12.0/24 traffic to other device 192.168.10.252.
MarkGrindulo Lv1Posted Mar-19-2025 13:48
  
Is this NGAF or NSF? If NSF change the route priority arrangement and make SSL VPN, IPSEC the top two priority