Port Forwarding Issue
  

Imran Tahir Lv3Posted 02 Apr 2022 16:51

Unable to forward the port
Situation:
Problem description:
1. DNAT is not working.

Assessment:
Technical Severity: Level 3
Findings:
1. Perform checking on the configuration, do not find abnormal.
2. Verified the connectivity between NGAF and the CCTV portal is accessible.
3. Perform packet capture over the LAN port and found the portal had replied to the packets.
4. Enabled passthrough for own public ip found issue persisted.
5. Perform packet capture, found the packet is going out from eth2 instead of eth3(original incoming interface).
6. Further checked on the routing and interface configuration, and found the eth3 DNS lookup-based link state detection is failed.
7. Suspect it is due to this DNS lookup failure causing the issue, tried to disable the DNS lookup based link state detection and test again, found the issue resolved.

Resolution:
Is the issue resolved?: Yes
Suggestion/Conclusion:
1. Link state detection failure causes the packet cannot go out from the same public ip and leads to DNAT not working.

Like this topic? Like it or reward the author.

Creating a topic earns you 5 coins. A featured or excellent topic earns you more coins. What is Coin?

Enter your mobile phone number and company name for better service. Go

Sangfor Jojo Lv4Posted 05 May 2022 15:26
  
Thanks for sharing.