The source IP address of NAT loopback's packet incorrect

The source IP address of NAT loopback's packet incorrect

The source IP address of NAT loopback's packet incorrect
The source IP address of NAT loopback's packet incorrect
a week ago
Model: Deco BE65-5G  
Hardware Version:
Firmware Version: 1.0.5

Referring to article https://community.tp-link.com/en/home/stories/detail/1726

 

When a local computer is accessing a local server with router's external IP with port forwarding, the router's NAT loopback does not work with the scource IP address correctly. The source IP address in the NAT loopback packet should be the router's internal IP address but the router doesn't, the source IP address of the packet is still router's external IP address, which is not correct NAT loopback behaviour.

 

As in some network environment, for security concerns, external IP cannot access some servers/devices behind a internal firewall. Therefore when a computer which is physically connected to local network, but it still cannot access to those servers.

 

 

  1      
  1      
#1
Options
5 Reply
Re:The source IP address of NAT loopback's packet incorrect
Friday

@David-TP 

 

I'm not sure if this is a question or if the story is wrong 

 

Please advise 

 

 

Need help with the Deco app, setup, Ethernet backhaul, network switch or rolling back firmware? Router or AP mode? https://community.tp-link.com/us/home/forum/topic/699816?page=1
  0  
  0  
#2
Options
Re:The source IP address of NAT loopback's packet incorrect
Friday - last edited Friday

  @dejiko 

Hi, nice to see you again.

You are right that the story is partially correct. It only highlights how the Destination NAT (DNAT) rewrites the incoming packet's destination IP address to be the local server IP, and doesn't mention the Source NAT (SNAT) process, how the router must perform a second translation step to rewrite the source IP to be the LAN IP of the router.

 

The actual NAT Loopback process on Deco BE65*5G should include both. So if you ran into any issues with NAT Loop on the Deco BE65-5G_1.0.5, please update the firmware of Deco to the latest 1.1.0 first:

Deco BE65-5G(EU)_V1_1.1.0 Build 20250730

 

Thank you very much.

Best regards.

File:
NAT Loopback.docxDownload
  0  
  0  
#3
Options
Re:The source IP address of NAT loopback's packet incorrect
Friday

  @David-TP 

 

Hello again and thanks for your prompt reply.

 

Interesting, the Deco App always say the firmware 1.0.5 is the latest one and not allowing me to upgrade, and seem no option to upload the downloaded firmware file. I will try it using web browser later.

 

  0  
  0  
#4
Options
Re:The source IP address of NAT loopback's packet incorrect
Saturday

  @David-TP 

 

Hi David, I just updated firmware to the latest one but the result is same. May I confirm the version 1.1.0 is really fixed the issue?

  1  
  1  
#5
Options
Re:The source IP address of NAT loopback's packet incorrect
Tuesday

  @dejiko 

Hi, thanks a lot for your time and patience.

The NAT Loopback on the Deco BE65-5G should work as expected, and there has been no previous feedback about NAT Loopback on this model as far as I'm concerned.
If you'd like to spend a little more time, I will collect some details and forward your case to the senior engineer for further analysis.

Please check whether you can receive my email later.

Thank you very much.

Best regards.

  0  
  0  
#6
Options