
Originally Posted by
ankda14
Hi,
Are you talking about nat cache table. i set it to 0 as well and clear the fw connection table and nat table. still NAT is done through first rule that is primary ISP external interface.
I disabled the first NAT rule as well and in rule base there is only one rule hide nat to external interface of ISP-B but still packet get natted to ISP-A external interface.
it seems still there are entries in nat cache table.
I was going through NAT optimization section in max-power book:
Once the first packet of an accepted connection has been NATted, the NAT rulebase and its
fwx_cache table is never consulted again for that particular connection, and as such the
NAT applied to a connection's packets cannot ever change after the connection’s first
packet.
This means NAT rule base and NAT cache table will never be consulted again. Correct? So which table is firewall looking at for existing NAT translations?
If i tired to ping to same destination with different source IP. Source IP get translated to ISP-B external Interface.
Thanks
Bookmarks