Why is the WAN source IP not showing on internal servers of a NAT rule?

Options
Zyxel_Emily
Zyxel_Emily Posts: 1,491 image  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments

Question:
A customer using NAT rules observed that incoming traffic to their internal servers doesn't display the original WAN client source IPs. Instead, it shows the local interface private IPs.

Answer:
It may be affected by a policy route rule. This rule was set as 'incoming any, source any, destination any,' which led to the NAT traffic not functioning as expected. After disabling the problematic policy route rule, the correct external IPs appeared in the packet trace.

image.png
Tagged: