Got it

Intranet users access the public IP address of the intranet server fail after configure NAT server.

Latest reply: Sep 29, 2018 08:29:46 2106 3 10 0 0
Issue Description

Intranet users access the public IP address of the intranet server fail after configure NAT server. And internet users can access the public IP address of the intranet server successfully.

5381b9b24be142c4be50f204cabe58ed

transparent.gif Handling Process

1.Checking the configuration on the USG9500.

NAT server configuration:

#

nat server test1 zone untrust protocol tcp global 1.1.1.1 www inside 192.168.1.1 83 no-reverse unr-route

nat server test2 protocol icmp global 1.1.1.1 inside 1192.168.1.1 no-reverse unr-route

#

Source NAT configuration:

#
rule name Free-Testing-INT-EXT
  source-zone trust
  destination-zone trust
  source-address 192.168.1.2
  action nat address-group natpool1
#

2. Checking the security policy, the traffic already allow from trust to trust. 
3. Checking the session table on firewall, there is no session information when intranet user visit the publc IP address of intranet server. Counting packets on the firewall, it shows that the packet drop by NAT UNR route.

transparent.gif Root Cause

nat server test1 zone untrust protocol tcp global 1.1.1.1 www inside 192.168.1.1 83 no-reverse unr-route

nat server test2 protocol icmp global 1.1.1.1 inside 1192.168.1.1 no-reverse unr-route

As ping work successfully, only web service not work, compare the NAT server configuration, the www service limit the source zone to untrust. After delete the source zone, www service work.

transparent.gif Solution

nat server test1  protocol tcp global 1.1.1.1 www inside 192.168.1.1 83 no-reverse unr-route   ///delete source zone.

Thanks for sharing, very useful.
View more
  • x
  • convention:

Thanks for sharing, it's amazing Intranet users access the public IP address of the intranet server fail after configure NAT server.-2751463-1
View more
  • x
  • convention:

Thank you for sharing, according to your case, I quickly solved a problem with the current network. Usually, we configure the NAT with the template first. Is there a configuration error? If not, you can locate it by viewing the session table.
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.