Business Rule - Reflexive rule option is not useful when outbound LAN access requires NAT.

Setup:

WAN: public IP Address

LAN: private Class C range

 

When creating a DNAT rule and enabling the "Create Reflexive rule" option is selected and a MASQ is required to translate LAN IP range to single Public IP, traffic fails to flow out correctly.

The Create Reflexisive rule needs an outbound NAT/MASQ configuration option OR a warning is needed to advise admins of this behaviour.

 

When Reflexive Rule is enabled:

When reflexive option is disabled and another Outbound LAN-WAN rule is available.

 

 

Rule list:

  

Thanks,

Matt G -