There are multiple external network addresses under the firewall network interface. Only the first address can be accessed and the others cannot be accessed.

environment:

Active and backup firewall 8.0.75
AF-2000-FH2130B-SC

Problem Description:

Double-click hot standby for two firewalls. There are multiple external network addresses under the high-availability firewall virtual network interface Eth4. Only the first address can be accessed and the others cannot be accessed.

Insert image description here

Insert image description here

solution:

1. Check firewall routing settings (not resolved)

2. Open the firewall and troubleshoot the command console

Insert image description here
3. Start capturing the packets. It shows that the packets come in from the eth4 port and go out from the eth1 port. There is something wrong here.

tcpdump -i eth4 icmp and host 106.108.121.155 -nnc 1000

Insert image description here
4. Enable the source-in-source-out function under the physical interface eth4 (to solve this case)

Insert image description here

Guess you like

Origin blog.csdn.net/weixin_42672685/article/details/132413731