cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1203
Views
1
Helpful
18
Replies

FTDv not natting inbound traffic in Azure

Monadnock
Level 1
Level 1

Hi all, I have an FTDv in Azure and traffic going towards the public IP is not being natted towards an internal server. I see the traffic hit it in the packet capture but no nat rules are applying and it is not being forwarded inside because of that:

Monadnock_0-1709049141147.png

The rule is :

nat (outside,inside) source static any interface destination static interface 10.1.1.1 service SVC_622771026011 SVC_622771026011 no-proxy-arp

The rule is getting 0 hits. In the packet capture with a trace, it is not hitting any nats. The FTD has a route to 10.1.1.1 and it is allowed in the ACP.

thoughts?

18 Replies 18

Can you add details to packet tracer and does the this all packet tracer output?

MHM

Any update 

MHM

nagroman
Level 1
Level 1

Hi!  

For port forwarding it should be like this

nat (INSIDE,OUTSIDE) source static local_ip pub_ip service SVC_111111 SVC_111111

AugustoS.Nunes
Level 1
Level 1

Hello, i don't know if you have solved it yet, but i saw a good article from Cisco that might help out:
https://community.cisco.com/t5/security-knowledge-base/high-availability-and-scalability-design-and-deployment-of-cisco/ta-p/4109439#toc-hId--2140473560
It's for HA deployments but has some good exemples.

Review Cisco Networking for a $25 gift card