Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG v19.5 IPv6 DNAT not Working? See Below (src-ip = dst-trans-ip)

2023-11-28 21:19:50Firewallmessageid="00001" log_type="Firewall" log_component="Firewall Rule" log_subtype="Allowed" status="Allow" con_duration="134" fw_rule_id="62" fw_rule_name="DNAT to Spiderman (IPv6)" fw_rule_section="Local rule" nat_rule_id="4" nat_rule_name="WAN -> Plex (IPv6)" policy_type="1" sdwan_profile_id_request="0" sdwan_profile_name_request="" sdwan_profile_id_reply="0" sdwan_profile_name_reply="" gw_id_request="2" gw_name_request="WAN_GW_6" gw_id_reply="2" gw_name_reply="WAN_GW_6" sdwan_route_id_request="0" sdwan_route_name_request="" sdwan_route_id_reply="0" sdwan_route_name_reply="" user="" user_group="" web_policy_id="0" ips_policy_id="7" appfilter_policy_id="0" app_name="" app_risk="0" app_technology="" app_category="" vlan_id="" ether_type="Unknown (0x0000)" bridge_name="" bridge_display_name="" in_interface="Port1" in_display_interface="Port1" out_interface="Port1" out_display_interface="Port1" src_mac="00:01:xx:93:16:xx" dst_mac="7C:5A:xx:7F:B6:xx" src_ip="xxxx:xxxx:fa0d:e9f:6088:7345:42cc:f2a2" src_country="" dst_ip="xxxx:xxxx:7008:500:7412:9d9e:73fa:49b9" dst_country="" protocol="TCP" src_port="64029" dst_port="32400" packets_sent="7" packets_received="0" bytes_sent="588" bytes_received="0" src_trans_ip="" src_trans_port="0" dst_trans_ip="xxxx:xxxx:fa0d:e9f:6088:7345:42cc:f2a2" dst_trans_port="0" src_zone_type="WAN" src_zone="WAN" dst_zone_type="WAN" dst_zone="WAN" con_direction="" con_event="Stop" con_id="748840573" virt_con_id="" hb_status="No Heartbeat" message="" appresolvedby="Signature" app_is_cloud="0" log_occurrence="1" flags="0"

Shouldn't dst_trans_ip = {internal server ip}?

IPv4 traffic shows correctly.



This thread was automatically locked due to age.
  • Hi,

    there is a bug in v19.5 and v20 reporting in logviewer which will be fixed either in v20.0.1 mr-1 or mr-2, I can't remember which.

    I have identified a similar bug and there is an NC for it.

    The NAT works correctly just not reporting.

    Ian

    XG115W - v20.0.2 MR-2 - Home

    XG on VM 8 - v21 GA

    If a post solves your question please use the 'Verify Answer' button.

  • I did figure out the issue.  The NAT IPv6 does not work with Link-Local addresses.  I used the main IPv6 address for the internal server and it worked.

    But yes the reporting still shows src-ip = dst-trans-ip when working.