same source IP first rule SNAT to inet, second rule DNAT into IPsec VPN
version 7.2.11
from same source IP first rule SNAT to inet, second rule DNAT into IPsec VPN; the issue is, FG takes always the DNAT pool address as source; even in the SNAT (outgoing interface) rule the FG takes the assigned pool addres as source, but sends the traffic to the destination in inet; result I get an outgoing hit to my SNAT rule, but the traffic doesn't come back; in sequence the SNAT rule comes before the DNAT rule destinations are not overlapping; the SNAT target in the internet are three host addresses; so very small;
is there something I've to consider specifically? After my opinion the FG shall process the rules after sequence and SA/DA match before processing NAT rules;
Is there a good hint to get this solved?
thx br Hanno
