NSF Cannot Ping 8.8.8.8 or External Domains, but Internet Access Works

Nauman Ali Lv1Posted 2026-Jul-29 15:52

Last edited by Nauman Ali 2026-Jul-29 15:53.

Hello ,
We are experiencing an unusual issue with our NSF firewall.
We are unable to ping external IP addresses such as 8.8.8.8 from the NSF itself. We are also unable to ping external domain names such as google.com and yahoo.com from the NSF.
However, we are able to successfully ping 1.1.1.1 from the NSF.
Current observations:
  • DNS on the NSF is configured as 8.8.8.8.
  • The NSF has two internet connections:

    • One connection comes through an IAG device.
    • The second connection is connected directly to the NSF.

  • End users and virtual machines can successfully access the internet.
  • Users and servers can also ping external destinations without any issues.
  • General internet connectivity is working normally across the network.
  • 1.1.1.1 is reachable from the NSF, but 8.8.8.8 and external domain names are not.

The issue appears to be limited to the NSF itself. We would like to understand why some public IPs are reachable while 8.8.8.8, google.com, and yahoo.com are not.
Has anyone encountered a similar issue? Are there any settings, security policies, routing configurations, DNS-related settings, or system-level restrictions on the NSF that could cause this behavior?
Any guidance would be appreciated.
Thank you.

By solving this question, you may help 1006 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Prosi Lv4Posted 2026-Jul-29 20:06
  
Hi,

This is likely specific to the firewall's own management plane traffic, not the transit traffic passing through the firewall.
Troubleshooting:
Verify which WAN interface the NSF uses for its own traffic (Highest Priority).
Check the routing table. Verify the DNS configuration. Test whether ICMP is specifically blocked. Check whether IAG is affecting management traffic. Verify Source NAT for system traffic. Compare packet captures. Verify whether Anti-DDoS/Local ACL/Control Plane protection is in place.
Zonger Lv5Posted 2026-Jul-30 05:44
  
Based on your provided symptoms this is unlikely to be an Internet connectivity issue because hosts behind the NSF have full Internet access. The issue is isolated to traffic originated by the NSF itself.

The most probable causes are:
1) Incorrect routing or source interface for locally generated traffic especially with dual WAN
2) Google DNS (8.8.8.8) is unreachable from the NSF's own source IP which causing both ICMP to 8.8.8.8 and DNS resolution failures.
3) Management plane traffic is following a different route or policy than forwarded traffic.
Korchai Lv2Posted 2026-Jul-30 19:16
  
Given that hosts behind the NSF have complete Internet connection, it seems doubtful that the problems you have described are related to a problem with Internet connectivity. The problem only affects traffic that comes from the NSF itself.

The most likely reasons are:
1) Improper source interface or routing for locally generated traffic, particularly when using dual WAN
2) ICMP to 8.8.8.8 and DNS resolution issues are caused by the NSF's inability to access Google DNS (8.8.8.8).
3) The route or policy of management aircraft traffic differs from that of forwarded traffic.
Newbie A4 Lv1Posted 2026-Aug-03 18:31
  
This is probably exclusive to the management plane traffic that passes through the firewall, not the transit traffic.
Troubleshooting
Check which WAN interface (Highest Priority) the NSF utilises for its own traffic.
Examine the routing table. Check the DNS setup. Check to see if ICMP is particularly prohibited. Verify whether management traffic is being impacted by IAG. For system traffic, confirm Source NAT. Examine packet captures. Check for the presence of Anti-DDoS, Local ACL, and Control Plane security.
Newbie509292 Lv1Posted 2026-Aug-04 18:09
  
The issue is most likely associated with management-plane traffic processed by the firewall itself, rather than transit traffic flowing through the device.

Troubleshooting Approach

- Determine which WAN interface, based on the highest priority, is being used by the NSF for its own communication.
- Inspect the routing table to verify that traffic is following the intended path.
- Validate the DNS configuration to ensure successful name resolution.
- Check whether ICMP traffic is being filtered or blocked.
- Assess whether IAG policies are interfering with management-plane communication.
- Verify that Source NAT is correctly configured for system-generated traffic.
- Review packet captures to identify where the communication is failing.
- Investigate whether security features such as Anti-DDoS, Local ACLs, or Control Plane Security are restricting or dropping management traffic.

A structured review of these components will help isolate the root cause and ensure reliable management-plane connectivity.

I Can Help:

Change

Moderator on This Board

1
156
3

Started Topics

Followers

Follow

1077
227
100

Started Topics

Followers

Follow

Board Leaders

rizzuan

Weekly Sharers

Nauman ...

Weekly Questioners