为啥做了nat server 丢给fib路由黑洞,业务不通,其他地址没问题,tcp业务没问题,只有udp业务有问题
*May 23 12:18:47:194 2025 F5000 IPFW/7/IPFW_PACKET: -Chassis=1-Slot=2;
Receiving, interface = Ten-GigabitEthernet1/2/2/7
version = 4, headlen = 20, tos = 20
pktlen = 425, pktid = 63915, offset = 0, ttl = 53, protocol = 17
checksum = 64119, s = 117.176.129.76, d = 119.6.226.9
channelID = 0, vpn-InstanceIn = 0, vpn-InstanceOut = 0.
VsysID = 1
prompt: Receiving IP packet from interface Ten-GigabitEthernet1/2/2/7.
Payload: UDP
source port = 5060, destination port = 5060
checksum = 0xe1ab, length = 405.
*May 23 12:18:47:195 2025 F5000 IPFW/7/IPFW_PACKET: -Chassis=1-Slot=2;
Discarding, interface = Ten-GigabitEthernet1/2/2/7
version = 4, headlen = 20, tos = 20
pktlen = 425, pktid = 63915, offset = 0, ttl = 52, protocol = 17
checksum = 64375, s = 117.176.129.76, d = 119.6.226.9
channelID = 0, vpn-InstanceIn = 0, vpn-InstanceOut = 0.
VsysID = 1
prompt: FIB BLACKHOLE.
Payload: UDP
source port = 5060, destination port = 5060
checksum = 0xe1ab, length = 405.
(0)
最佳答案
根据日志提示FIB BLACKHOLE
,防火墙NAT Server的报文被黑洞路由丢弃,主要原因为NAT转换后的目的地址匹配了防火墙自动下发的防环黑洞路由。以下是关键排查点:
display nat all
检查接口下流表状态是否为Inactive
,若提示Not enough resources
,需释放流表资源或优化配置。nat server global 112.0.0.1 vpn-instance external_vpn inside 10.0.0.1
确保NAT规则中指定了正确的VPN实例。undo ip route-static 112.0.0.1 32 NULL0
注意:需评估是否可能引发环路,建议优先修正NAT配置。nat server protocol tcp global 112.0.0.1 80 inside 10.0.0.1 8080
确保转换后的目的地址非防火墙接口地址。(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论