Guest User!

You are not Sophos Staff.

BUG - logviewer and linked NAT rules

Hi folks,

I have been trying workout why some of my linked NAT rules show no use.

Background.

I Built EAP3 and used my v17 backup as the configuration method.

I deleted all the default linked NAT rules and created one generic NAT rule. This does not work well for traffic between  internal networks. So I added a none MASQ rule to cover connections between internal networks but you need one for each internal network rule.. This was not required in V17.

The XG appears to slow down after I removed all the linked NAT rules, throughput was fine just web pages became very slow to load.

So to overcome this issue I added linked NAT rules for all external connection firewall rules, both IP4 and IPv6.

All active firewall rules are passing traffic but eh associated linked NAT rules are not.

According to the logviewer I have two firewall rules using the same linked NAT rule even though the firewall rules are shown associated to different linked NAT rules.

I have one firewall rule for my VoIP phones which uses NAT rule 0 and not the associated linked NAT rule.

 

Maybe this explains why my DPI is working on devices without CAs installed eg IoT devices?

Also intermittently some sites take two attempts to establish a secure connection and then other times during the day they will not connect at all.

 

Devs please feel free to login and investigate, Pankti of the EAP reporting team has the current access details.

 

 

Ian

Parents Reply Children
  • I have had similar problems. I created about 12 rules ALL with connected NAT rules. When tinkering too much with firewall rules for troubleshooting, I noticed that some of my firewall rules were using NAT rule 0. I also had a couple that were using another NAT rule. For example my Netflix rule only allows netflix traffic with its own NAT but then my media players have a dedicated firewall rule for other traffic with its own NAT. Every once in a while, the logs would show firewall rule Netflix and NAT rule media player. I thought linked NAT rules couldn't be used by other firewall rules.

    My only solution was to create single LAN to WAN NAT and another NAT or two for special needs like business rules or DNS catch all rules.I have used other firewalls with NAT in every firewall rule and have never run into the problem like this. Something is seriously wrong and I really don't have time to troubleshoot at the moment.

    Regards 

  • Hi Billybob,

    thank you for the confirmation. I also noted that the web page connects were faster with linked rules rather than generic rules, that is why I returned to using linked NAT.

    Ian