Description | This article describes how to solve the layer 3 connectivity issue when NAT64 and DNS64 are configured. |
Scope | FortiOS 7.0.11, 7.0.12, 7.2.5 and 7.4.0. |
Solution |
When NAT64 and DNS 64 are configured, there must be an IP pool for the policy.
Firewall policy:
If the IP pool external IP range has the same IP address as the FortiGate WAN interface IP, it will cause a connectivity issue.
The reply is not forwarded to the source.
Considering this, the NAT64 does not allow to use the WAN interface IP address as the external IP range for the IP pool. It is imperative to use an available IP address of the public range. For example, the WAN interface IP address is 192.168.1.3, therefore, the IP pool can have an available IP address within that range.
Having done this, Layer 3 connectivity is working.
Output from FortiGate sniffer CLI command. The request and reply are routed properly.
Note-Do enable arp-reply when using ippool
config firewall ippool |