Central NAT Mode breaking Traffic Flow - Palo Conversion
Hi, Was hoping someone may have seen this or knows what is happening, I will do my best to explain:
I am in the process of converting legacy firewalls to a VDOM 400F, all has gone successful except for one conversion from a palo to an Internal VDOM. I used Forti convertor for all the conversions of objects policies etc and put the VDOM into Central NAT to make it easier, (I did some ASA conversions and it converted better this way)
My last conversion Palo > FGT, all worked except, 1 very important traffic flow, so had to "backout" and reintroduce the Palo, so I cant even do live troubleshooting untill I attempt it again.
Traffic flow is: Azure Cloud Exchange (51.x.x.x) > External VDOM Firewall destination Public Firewall address (60.60.60.1 as an example)
DNAT on External firewall changes 60.60.60.1 to 192.168.1.1 which is located off the INTERNAL VDOM, This all works fine, and at the moment the traffic passed to the PALO and goes on its merry way. as it leaves the External VDOM, there is a source NAT also (Central Nat) that changes the public source 51.x.x.x to the exit interface, so the Palo sees the source as 10.10.10.1 as an example,
This flow breaks when I convert to the INTERNAL VDOM firewall from the Palo, it hits the external VDOM as normal, but when it arrives on the Internal VDOM, its instantly dropped despite there being a rule to allow it (its above the deny, and the RULE is 100% correct) it drops with this in the diag debug:
INTERAL-FW (Internal) # diag debug flow trace start
INTERAL-FW (Internal) # id=65308 trace_id=47 func=print_pkt_detail line=6005 msg="vd-Internal:0 received a packet(proto=6, 10.10.10.1:54 m PORT1. flag [S], seq 2471198223, ack 0, win 65535"
id=65308 trace_id=47 func=init_ip_session_common line=6206 msg="allocate a new session-1f7a1fed"
id=65308 trace_id=47 func=iprope_dnat_check line=5487 msg="in-[PORT1], out-[]"
id=65308 trace_id=47 func=iprope_dnat_tree_check line-824 msg="len=0"
id=65308 trace_id=47 func=iprope_dnat_check line=5512 msg="result: skb_flags-02000000, vid-0, ret-no-match, act-accept, flag-00000000"
id=65308 trace_id=47 func=__vf_ip_route_input_rcu line=1989 msg="find a route: flag-80000000 gw-0.0.0.0 via Internal"
id=65308 trace_id=47 func=iprope_access_proxy_check line=457 msg="in-[PORT1T], out-[], skb_flags-02000000, vid-0"
id=65308 trace_id=47 func=__iprope_check line=2410 msg="gnum-100017, check-ffffffffa002c240"
id=65308 trace_id=47 func=iprope_policy_group_check line-4909 msg="after check: ret-no-match, act-accept, flag-00000000, flag2-00000000" id=65308 trace_id=47 func=iprope_in_check line-495 msg="in-[PORT1], out-[], skb_flags-02000000, vid-0"
id=65308 trace_id=47 func=__iprope_check line=2410 msg="gnum-100011, check-ffffffffa002cc70"
id=65308 trace_id=47 func=iprope_policy_group_check line-4909 msg="after check: ret-no-match, act-drop, flag-00000000, flag2-00000000" id=65308 trace_id=47 func=__iprope_check line=2410 msg="gnum-100001, check-ffffffffa002c240"
id=65308 trace_id=47 func=iprope_policy_group_check line-4909 msg="after check: ret-no-match, act-accept, flag-00000000, flag2-00000000" id=65308 trace_id=47 func=__iprope_check line=2410 msg="gnum-10000e, check-ffffffffa002c240"
id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000e policy-4294967295, ret-no-match, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000e policy-4294967295, ret-no-match, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000e policy-4294967295, ret-no-match, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000e policy-4294967295, ret-no-match, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000e policy-4294967295, ret-matched, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line=2380 msg="policy-4294967295 is matched, act-drop"
id=65308 trace_id=47 func=__iprope_check line=2427 msg="gnum-10000e check result: ret-matched, act-drop, flag-00000000, flag2-00000000" id=65308 trace_id=47 func=iprope_policy_group_check line-4909 msg="after check: ret-matched, act-drop, flag-00000000, flag2-00000000" id=65308 trace_id=47 func=__iprope_check line=2410 msg="gnum-10000f, check-ffffffffa002c240"
id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000f policy-4294967295, ret-no-match, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000f policy-4294967295, ret-no-match, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000f policy-4294967295, ret-no-match, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000f policy-4294967295, ret-no-match, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line=2146 msg="checked gnum-10000f policy-4294967295, ret-matched, act-accept" id=65308 trace_id=47 func=__iprope_check_one_policy line-2380 msg="policy-4294967295 is matched, act-drop"
id=65308 trace_id=47 func=__iprope_check line=2427 msg="gnum-10000f check result: ret-matched, act-drop, flag-00000800, flag2-00000000" id=65308 trace_id=47 func=iprope_policy_group_check line-4909 msg="after check: ret-matched, act-drop, flag-00000800, flag2-00000000" id=65308 trace_id=47 func=fw_local_in_handler line=620 msg="iprope_in_check() check failed on policy 0, drop"
This line:
id=65308 trace_id=47 func=iprope_dnat_check line=5487 msg="in-[PORT1], out-[]"
doesn't show an exit interface? which I think is causing it, the out interface is an EMAC VLAN , and is definitely correct as other traffic is received. My colleague is suggesting the Internal VDOM sees this traffic as local to itself, so drops it? I dont know why! On the External VDOM, as I said there is a Source NAT which is working as I see the "vd-Internal:0 received a packet(proto=6, 10.10.10.1:54 )" which is the source NAT, now the destination 192.168.1.1 has a DNAT on the External as I said, and it had "set source-nat-vip enable" which I think may be the issue? but dont really understand whats happening.
I hope this makes sense, and would love to resolve this
Thanks
