MISMDS Lv3Posted 2022-Dec-18 14:06
  
I think it is a bug on the side of Sangfor
Konstantin Lv1Posted 2022-Dec-18 19:51
  
Funny! Looks like NGAF bug.
It worse when I deleted NAT policy:
Old connection is working. I was waiting for 5 minitues but traffic didn't stop.
New connection's doesn't work.

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Konstantin Lv1Posted 2022-Dec-18 19:54
  
...... and right after reboot NGAF device, everythig works as it shoud:

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Konstantin Lv1Posted 2022-Dec-18 20:17
  
.... then, I create new S-NAT -bingo (really not)
Some old connection are still in block mode....


PS Really raw solution. Is someone using NGAF in production?

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Noah19 Lv3Posted 2022-Dec-18 22:01
  
can you delete the SNat and do the Dnat
Konstantin Lv1Posted 2022-Dec-19 04:19
  
Dnat - is completely different feature (function).
And additionally I don't see any means how to DNATing ICMP packets. It seems works for UDP/TCP only.....
Pat Lv4Posted 2022-Dec-19 13:54
  
For fast solution, just clear the whole config
noime Lv3Posted 2022-Dec-19 14:08
  
try to delete all the NAT config and return one at at time
Franky Lv3Posted 2022-Dec-19 14:23
  
Reset all the translations
Konstantin Lv1Posted 2022-Dec-19 14:27
  
Everything works if you delete NAT rule then create new and restart device.
It is acceptable for student's lab but completely not acceptable for corporate network.
For me it is unclear how Gartner mentioned NGAF in their report.....

I Can Help:

Change

Moderator on This Board

11
8
5

Started Topics

Followers

Follow

1
3
5

Started Topics

Followers

Follow

0
4
5

Started Topics

Followers

Follow

67
20
3

Started Topics

Followers

Follow

3
14
3

Started Topics

Followers

Follow

1
138
3

Started Topics

Followers

Follow

Board Leaders