02-17-2023 08:40 AM - edited 02-18-2023 05:44 AM
Hello Guys
I made this Lab in Gns3 to prepare myself for my CCNP Security exam
Everything work fine, I configure the FTD through FMC, I gave IPs for outside & inside interfaces
also, I have configured NAT and Static route, the issue is that FTD can't reach the internet (so I can't ping to 192.168.122.1)
really I don't know what is the problem, maybe could someone help me
UPDATE: there is no Problem with INTERNET ISP, I have tested with router and PC is pingable
02-17-2023 10:05 AM
I think thr issue is in NAT cloud not in FTD.
02-18-2023 05:42 AM
no cuz i tested the NAT cloud with router and PC, so there are no problems with it
02-18-2023 05:48 AM - edited 02-18-2023 05:59 AM
can I see the route in FTD toward the NAT cloud ? <<- you already share the show route
can you use wireshark between FTD and cloud
see if the FTD get ARP reply for it ARP request
02-18-2023 06:06 AM
this is the output of Wireshark between FTD and Cloud, it looks like there are no connection between, right?
02-18-2023 06:22 AM
no there is but the arp is missing.
please use workaround as I write below and check again.
02-18-2023 06:07 AM
If you not see ARP reply then simple solution to complete your lab is
add router between the cloud and FTD
then confing NATing in router.
it is some GNS limitation I think
02-20-2023 03:09 AM
02-17-2023 10:50 AM
You do not state how you tested. Regardless of any configuration problem in access-control, routing and NAT, you should be able to ping the next hop from the FTD itself.
Try if that works and if not, post the output of:
show int ip brief
show run route
show route
show arp
02-18-2023 05:49 AM
See the attachment pls, these are the outputs
02-18-2023 05:59 AM
The config looks good so that you should be able to ping the default gateway from the FTD CLI. But with the ARP table empty it is most likely that you messed up you connection between FTD and Default-Gateway inside of GNS3.
02-18-2023 04:54 AM - edited 02-18-2023 04:58 AM
I once had this issue, if you configured NAT and the route is fine, you might need to clear the ARP cache with ISP.
Edit: Noticing now you mentioned its a lab - in this case forget ISP
02-18-2023 05:57 AM
How is GNS3 installed? Is it on a Linux, Windows, VM ?
In either of these cases, my first thought would be that the Host device where GNS3 is running is not sharing its network interface with GNS3.
02-18-2023 06:00 AM
It is on VM, but there is no problem with Network, because i tested already with the router and pc in the lab (can see it beside the diagram)
02-18-2023 06:20 AM
I am not saying there is a problem with the network, I am saying there is a problem between GNS3 and the host interface. Have you tried assigning the virtual interface to a virtual PC on the VMware host and test from it? I suspect that this will also not work.
But you say that this is VMware, is there a switch between the VMware host and 192.168.122.1? If yes how is the switch port configured (trunk, access-port)?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide