cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
322
Views
0
Helpful
5
Replies

Hairpin Nat issues FMC

I have FMC and configured hairpin NAT to access to web server with public IP from internal LAN, and it works fine when I try to access to web server with public ip from internal LAN, but problem is when I try to enter to web server with internal IP from internal LAN FMC drop packet.

111.png

 

222.png

 

333.png

 

444.png

 

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

Where is the Gateway for this Subnet ? on FTD ?

If the same subnet it should not be, are you trying to access using IP address or DNS FQDN., in these kind of scenario always have DNS A entry for Local IP to resolve.

check some config (hope you come across this document)  - clear the NAT and test it.

https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/221985-configure-hairpin-with-firepower-managem.html

https://integratingit.wordpress.com/2021/07/11/ftd-nat-reflection/

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Gateway is in FTD, subnet is same, I am trying to access by IP, If I disable NAT rule it works 

In NAT advance 

There is option 

""Translate DNS replies that match this rule""

This option need to translate private IP to public IP for dns reply.

MHM

But this option is inactive, I think I haven't error in my NAT rule but it works incorretly

this your network ?
If Yes then no need hairpin NAT you can use FTD NAT from external user to server and add option 

""Translate DNS replies that match this rule""

NOTE:- here the traffic is not pass via FTD

NAT issue FTD.png

Review Cisco Networking for a $25 gift card