Hot!Double_NAT

Author
shaan129
New Member
  • Total Posts : 5
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/10/22 12:30:38
  • Location: United Arab Emirates
  • Status: offline
2019/11/13 11:34:26 (permalink)
0

Double_NAT

Dear All ,

Need your help , expertise on the below issue

Server 1 is in LAN behind the Fortigate 60 FW both share ip address from the same subnet , GW for the server 1 is ip of the Fortigate . Fortigate is connected to a Cisco Router (handled by different vendor) & on its LAN there is a Server 2 whose gateway is one of the interface of the cisco router . Now i am trying to communicate Server 1 with Server 2 and vice versa but issue is server 1 before communicating or exiting the Fortigate interface should changed its ip address to a different ip address . Now i have done the test and i am able to ping to ping the server 2 from server 1 but when i do the same from server 2 to server ping not responding & traceroute reaches until ip of the Fortigate ip which is connected to the Cisco router and nothing after that .

I have attached diagram for better understanding , kindly help with your inputs

Regards
shaan

Attached Image(s)


Regards
Shaan
 
#1

4 Replies Related Threads

    Dave Hall
    Expert Member
    • Total Posts : 1542
    • Scores: 167
    • Reward points: 0
    • Joined: 2012/05/11 07:55:58
    • Location: Canada
    • Status: offline
    Re: Double_NAT 2019/11/13 14:32:14 (permalink)
    0
    If the path of server 2 traffic is hitting the WAN port(s) of the Fortigate then you likely need to set up a VIP (port forward); if both LANs on each side of the fgt are connecting via an internal port, you may need to define a route to 192.168.255.254/32 directly.  However, I don't think this is actually needed.  I suggest checking the return firewall policy (from server2 to server1) - you will need two firewall rules for both directions of that fgt connection. Perhaps post a screenshot (san identifiable IP info) here.

    NSE4/FMG-VM64/FortiAnalyzer-VM/5.4/6.0 (FWF40C/FW92D/FGT200D/FGT101E)/ FAP220B/221C
    #2
    sw2090
    Platinum Member
    • Total Posts : 484
    • Scores: 23
    • Reward points: 0
    • Joined: 2017/06/14 01:27:25
    • Location: Regensburg
    • Status: offline
    Re: Double_NAT 2019/11/14 00:50:53 (permalink)
    0
    are you sure the cisco does nat server2 back to the FortiGate?
    If traffic reaches the FGT with the original IP of server2 there will be no answer because the FGT doesn't know that subnet nor has a route to it.
     
    #3
    emnoc
    Expert Member
    • Total Posts : 5389
    • Scores: 353
    • Reward points: 0
    • Joined: 2008/03/20 13:30:33
    • Location: AUSTIN TX AREA
    • Status: offline
    Re: Double_NAT 2019/11/14 04:11:28 (permalink)
    0
    I do not think you need to do anything but check for route to the src-address that server1 is SNAT to. What does diag sniffer packet show and the src_address that enters the  Fortigate ?
     
     

    PCNSE 
    NSE 
    StrongSwan  
    #4
    shaan129
    New Member
    • Total Posts : 5
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/10/22 12:30:38
    • Location: United Arab Emirates
    • Status: offline
    Re: Double_NAT 2019/11/16 01:04:45 (permalink)
    0
    Dear All ,
     
    I have the source route in place ... from Fortigate interface connecting to Cisco router i cna ping the server 2 and i am able to get the response as well only issue with NATing i guess and i got below response from the router team who is managing the Cisco router 
     
    I captured the logs from the continuous ping done earlier and it looks like the traffic initiated from the server1 (192.168.255.254) is being NATed to the 10.249.107.98 (instead of 10.249.107.80 IP) before coming to the cisco router.
     
    This is why when you try to ping the 10.249.107.80 from the server 2(10.249.104.x) it is not working as that NAT (192.168.255.254 - 10.249.107.80 ) is not working.
     
     
    Regards
    shaan
     
     

    Regards
    Shaan
     
    #5
    Jump to:
    © 2019 APG vNext Commercial Version 5.5