Imran Tahir Lv4Posted 02 Apr 2022 16:51

Unable to forward the port
Problem description:
1. DNAT is not working.

Technical Severity: Level 3
1. Perform checking on the configuration, do not find abnormal.
2. Verified the connectivity between NGAF and the CCTV portal is accessible.
3. Perform packet capture over the LAN port and found the portal had replied to the packets.
4. Enabled passthrough for own public ip found issue persisted.
5. Perform packet capture, found the packet is going out from eth2 instead of eth3(original incoming interface).
6. Further checked on the routing and interface configuration, and found the eth3 DNS lookup-based link state detection is failed.
7. Suspect it is due to this DNS lookup failure causing the issue, tried to disable the DNS lookup based link state detection and test again, found the issue resolved.

Is the issue resolved?: Yes
1. Link state detection failure causes the packet cannot go out from the same public ip and leads to DNAT not working.

