ER8411 not applying NAT

ER8411 not applying NAT

ER8411 not applying NAT
ER8411 not applying NAT
a week ago
Model: ER8411  
Hardware Version: V1
Firmware Version: 1.3.6

Hi,

I have an infrastructure based on an OC400 controller and ER8411 routeur and then multiples switches and APs mainly Omada compatibles.

The configuration is pretty basic : one WAN and one LAN with few options enabled.
Things were working fine despite the ER8411 on firmware 1.3.6.

Then, we added a firewall between our 10Gb fiber termination and the ER8411 setted up with a double NAT.
Things seems to work fine but the firewall is reporting a lot of IP spoofing from the LAN side, which means the firewall is seeing LAN IP instead of seeing only the WAN IP interface of the ER8411.

In order to debug this, I removed a lot of not essentials features, but it continues. Everything indiactes that the ER8411 are not applying NAT rules on somes packets without apparent reason.

0
0
#1
3 Reply
Re:ER8411 not applying NAT
a week ago

Hi @deepdam 

Thanks for reaching out to TP-Link Business Forums.

 

This sounds like a classic NAT misconfiguration issue.

To help me diagnose this effectively, I need a bit more information. Could you please provide the following?

1. What's the entire network topology, i.e., ISP Fiber - - (WAN) Firewall (LAN) - - (WAN) ER8411 (LAN) - - PC, etc. ?

What IP range did you configure on the firewall and the gateway?

2. Did you configure the NAT rules on the firewall or the gateway? Can you upload the settings here so that we could check it? Please erase your personal information before uploading.

3. Can you provide an example of one or two "IP spoofing" alerts? What are the Source IP, Destination IP, and potentially Source Port and Protocol listed in these alerts?

0
0
#2
Re:ER8411 not applying NAT
a week ago

Hi   @Gabriel-TP 
 

  1. Yes that is exactly that. From the ER8411 the configuration is such as
    1. The WAN has static IP 192.168.5.1/24 with the gateway pointing to the FW with static IP 192.168.5.254/24 as gateway
    2. The only LAN confgured uses Gateway 192.168.0.254/24 (i.e. the ER8411) and the DHCP range 192.168.0.1/24
    3. There are 2 WLAN : classic and guest
  2. The only NAT rules defined are port forwarding, on both the Firewall and ER8411,they are working and not showing up in the problem
  3. You can see the attached screencap.
    1. Source IP is a LAN IP where only 192.168.5.1 is expected on the firewall side
    2. Destination IP varies
    3. Protocols can be jabbers/https/icmp

 

There is not much configuration done, and it seems to work most of the time since there is not fonctionnal evidence of the issue on the client side. Which makes me think that when a paquets is lost, the exact same is passing in the mean time by automatic retries.
Open for any suggestions or explanations.



0
0
#3
Re:ER8411 not applying NAT
a week ago

Hi @deepdam 

 

To better assist you, I've created a support ticket via your registered email address. The ticket ID is TKID260508215, please check your email box and ensure the support email is well received. Thanks!

0
0
#4