SNAT table clean up

Konstantin Lv1Posted 16 Dec 2022 23:53

Is it possible to clean up NAT table?
When I change SNAT rules (disable/enable/delete/create) some traffic continue to work infinitely.
For instance ICMP traffic newer stop when I disable NAT rule it continues to use NAT even if it was deleted. I checked by tcpdump - yes it stil translating IP!!!

By solving this question, you may help 723 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Konstantin Lv1Posted 17 Dec 2022 14:46
  
It could be chache on an NGAF so I'm asking how to clean it...
But it could NOT be chache on endpoint.

This is working NAT rule:
ICMP and HTTP/S are ok


This is disabed NAT:

Ping are stil ok (but must be stoped)
HTTP blocked

Tcpdump shows that ICMP packects are stil NATed.
Konstantin Lv1Posted 17 Dec 2022 15:06
  
After NGAF reboot thigs getting more strange:
Just after rebbot:


In tcpdump mode everything works:



Konstantin Lv1Posted 18 Dec 2022 19:51
  
Funny! Looks like NGAF bug.
It worse when I deleted NAT policy:
Old connection is working. I was waiting for 5 minitues but traffic didn't stop.
New connection's doesn't work.

3905639efe5845692.png (28.03 KB, Downloads: 240)

3905639efe5845692.png
Konstantin Lv1Posted 18 Dec 2022 19:54
  
...... and right after reboot NGAF device, everythig works as it shoud:

Konstantin Lv1Posted 18 Dec 2022 20:17
  
.... then, I create new S-NAT -bingo (really not)
Some old connection are still in block mode....


PS Really raw solution. Is someone using NGAF in production?
Konstantin Lv1Posted 19 Dec 2022 04:19
  
Dnat - is completely different feature (function).
And additionally I don't see any means how to DNATing ICMP packets. It seems works for UDP/TCP only.....
Konstantin Lv1Posted 19 Dec 2022 14:27
  
Everything works if you delete NAT rule then create new and restart device.
It is acceptable for student's lab but completely not acceptable for corporate network.
For me it is unclear how Gartner mentioned NGAF in their report.....

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
0
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders