|
此文章由 夜游神 原创或转贴,不代表本站立场和观点,版权归 oursteps.com.au 和作者 夜游神 所有!转贴必须注明作者、出处和本声明,并保持内容完整
I was troublshooting on one extremely tricky network issue around the DMZ area.
Inside that DMZ, if an application needs to get out heading to Internet, it will be NATed at the DMZ Internal firewall (From inside heading into the DMZ)
Then the outbound traffic will be NATed again at the DMZ external firewall (From DMZ heading into the Internet cloud)
While the client iniciated the session request, I am able to capture the real time interesting traffic on both the Internal & External firewall.
However, the application client still getting a timeout error or a distination unreachable error.
The final work around to fix the issue is diable the NAT on the DMZ internal firewall and only running NAT on external firewall for only one time.
So here is my question, why sometimes the multiple NATs would cause connectivity issue for some of TCP based network application? |
评分
-
查看全部评分
|