Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Roy_Tam
Participant

VPN established, but failed to forward traffic via VPN with source and destination NAT.

Recently we are migrating the internet VPN tunnel from CP1430 to CP6600 due to EoL. Firewall log is attached, showing the source and destination NAT is done. The connection was encrypted.  But it failed to connect to the destination. Opened the TAC SR, but still not able to fix the problem. May I have a help from anyone...?

===========================================

NAT:
Original Source:
internal private IP
Original Destination: our public IP_1

Translated Source: our public IP_2
Translated Destination: External party's private IP
*public IP_1 and public IP_2 are different subnet

Encryption Domain:
Center Gateways (Our side): public IP_2
Satellite Gateways (External party): our public IP_1 & External party's private IP

 


Ran the fw monitor, see the traffic from internal to the public IP_1. But are unable to see the traffic after the translation.


> fw monitor -e "accept host(our public IP_1) or host(our public IP_2);" -m iO

[vs_0][fw_0] eth1:i[44]: internal private IP -> public IP_1 (TCP) len=60 id=48107 TCP: 19189 -> 28161 .S.... seq=2cf0285d ack=00000000
[vs_0][fw_2] eth1:i[44]: internal private IP -> public IP_1 (TCP) len=60 id=48274 TCP: 19475 -> 28161 .S.... seq=2d2bb491 ack=00000000
[vs_0][fw_1] eth1:i[44]: internal private IP -> public IP_1 (TCP) len=60 id=17132 TCP: 46560 -> 28161 .S.... seq=49f63204 ack=00000000
[vs_0][fw_1] eth1:i[44]: internal private IP -> public IP_1 (TCP) len=60 id=30396 TCP: 46562 -> 28161 .S.... seq=ec481354 ack=00000000

 

Troubleshoot I did:
1. Removed public IP_1 or External party's private IP from the encryption domain, but still got the issue.
2. Moved public IP_1 from Satellite Gateways's encryption domain to Center Gateways's encryption domain, but not working.
3 Added a static route that pointing public IP_1 to the internet gateway address, failed to work.

 

0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events