vsm-500 CGN NAT44 NOT WORKING FOR IPoE, ONLY WORKING WITH PPoA
I am facing a really rare problem with the vsm-500 providing nat44, with subs using PPPoE there is not problem, but when we try to add some IPoE subs, is not working. After the IPoE session is established we are able to get ip address from the server using proxy dhcp in the ASR 9K, you even are able to have icmp reachavility (ping, traceroute) to internet. As well as dns resolution even using outside dns google etc. meaning that the nat translations are taking place in the vsm. but the sad part is that we can not load any web pages.
I tested using a interface directed connected to the inside vrf (NAT44) but it does not works. only subs using PPPoE are able to browse with no problem. there is around 4gb of traffic coming from the PPPoE users. when you check the cgn nat statistic there is not lack of resources for translations etc. i also have a second vsm for backup with no traffic. I tested from there but is not working either.
- I discarded routing problem testing direct from inside vrf,
- only a default route is being used to divert traffic from inside vrf to outside
- we tested with different CPEs and laptop connected to inside vrf etc.
- the traceroute shown the traffic passing through the vsm
I do not have any idea of what else can i check or troubleshoot. if you have any idea what can a start looking for. Please let me know
thanks in advance..
... View more