Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DNAT Rule not working / same configuration as other sophos XG

Hi all

i have a Sophos XG SFOS 18.5.2 MR-2-Build380

DNAT created via Wizard, checked everything with working DNAT rule on another Sophos XG. in the firewall log so far i could see that the DNAT rule was not triggered, it was always the default rule that was triggered. The new DNAT rule is above the default rule. Firewall let the traffic through...and Destination also seems to be correct, but i cant access the service...

I dont get it, how can i troubleshoot this...

thanks

Log
messageid="00001" log_type="Firewall" log_component="Firewall Rule" log_subtype="Allowed" status="Allow" con_duration="128" fw_rule_id="9" nat_rule_id="4" policy_type="1" user="" user_group="" web_policy_id="0" ips_policy_id="0" appfilter_policy_id="0" app_name="" app_risk="0" app_technology="" app_category="" vlan_id="" ether_type="Unknown (0x0000)" bridge_name="" bridge_display_name="" in_interface="Port2" in_display_interface="Port2" out_interface="Port1" out_display_interface="Port1" src_mac="64:00:F1:3E:A7:FF" dst_mac="80:EE:73:F4:E1:70" src_ip="a wan ip" src_country="BGR" dst_ip="internet ip of the XG" dst_country="CHE" protocol="TCP" src_port="46119" dst_port="7777" packets_sent="1" packets_received="0" bytes_sent="40" bytes_received="0" src_trans_ip="" src_trans_port="0" dst_trans_ip="192.168.10.240" dst_trans_port="0" src_zone_type="WAN" src_zone="WAN" dst_zone_type="LAN" dst_zone="LAN" con_direction="" con_event="Stop" con_id="638422784" virt_con_id="" hb_status="No Heartbeat" message="" appresolvedby="Signature" app_is_cloud="0"



This thread was automatically locked due to age.
  • I think we need a screenshot of your DNAT-Rule


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Hi Oliver 

    Please check local system is reachable with ping and telnet the port from cli  which you want to forward 

    console> ping 192.168.10.240

    console>telnet 192.168.10.240 7777

    share the logs with us 

    "Sophos Partner: Infrassist Technologies Pvt Ltd".

    If a post solves your question please use the 'Verify Answer' button.

Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?