cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
481
Views
2
Helpful
2
Replies

Why the need for nat hairpin?

medisonp2
Level 1
Level 1

Can someone please explain the exact need for nat hairpin. When server01 is published to the inrernet and server02 is in the same subnet, they can both communicate using their private ip but server02 can't reach server01 public IP Is it because server01 dropping the packet or is it because the firewall dropping the packet due to asymmetric routing or any other reason. Can someone please explain the exact flow?

2 Replies 2

 firewall dropping <<- not the FW drop the packet but the Server drop the packet 
TCP handshake
Server1(private IP)- TCP SYN -Server2(public IP)

FW NAT public IP to private IP using static NAT which work bidirectional 

Server2(private IP)- TCP SYN/ACK -Server1(private IP) <<- here the server1 receive TCP SYN/ACK with different IP and drop TCP

MHM

Gopinath_Pigili
Spotlight
Spotlight

Hello medisonp2,

Please go through the link...You may find similar discussion:

https://community.cisco.com/t5/routing/nat-hairpinning/td-p/2475807

Best regards
******* If This Helps, Please Rate *******