03-16-2024 03:22 AM
Can someone please explain the exact need for nat hairpin. When server01 is published to the inrernet and server02 is in the same subnet, they can both communicate using their private ip but server02 can't reach server01 public IP Is it because server01 dropping the packet or is it because the firewall dropping the packet due to asymmetric routing or any other reason. Can someone please explain the exact flow?
03-16-2024 03:27 AM
firewall dropping <<- not the FW drop the packet but the Server drop the packet
TCP handshake
Server1(private IP)- TCP SYN -Server2(public IP)
FW NAT public IP to private IP using static NAT which work bidirectional
Server2(private IP)- TCP SYN/ACK -Server1(private IP) <<- here the server1 receive TCP SYN/ACK with different IP and drop TCP
MHM
03-16-2024 05:21 AM
Hello medisonp2,
Please go through the link...You may find similar discussion:
https://community.cisco.com/t5/routing/nat-hairpinning/td-p/2475807
Best regards
******* If This Helps, Please Rate *******
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide