Issue With Port Forwarding (MX behind Att Router)

Solved
EDIT
Here to help

Issue With Port Forwarding (MX behind Att Router)

Hi Team,

 

Running into a networking and/or firewall issue where I'm not getting http and https traffic for host on my internal LAN. My setup is as follows:

 

Previous working topology:

 

Edge router (att BGW210) <> Virtual switch <> Web Server

 

New topology not working:

 

Edge router (att BGW210) <> MX Firewall <> MS Switch <> Virtual switch <> Web Server

 

On my previous topology, only way it works if I setup port forwarding on the att router to the internal web server. However now that I've implemented the MX firewall and MS switch, can't get port forwarding to work. 

 

On my att router, I now have port forwarding http and https traffic to my MX firewall where I then configured port forwarding on the MX and set my web server as the destination LAN server.  Not sure what step I'm missing buy any guidance would be greatly appreciated. 

 

Note that I tried packet captures on the switch uplink where not seeing any http or https traffic being sent from the MX. 

1 Accepted Solution
EDIT
Here to help

Thanks I found the issue and end up being unrelated to the setup. Confirming that my new setup now works. 

View solution in original post

4 Replies 4
ww
Kind of a big deal
Kind of a big deal

Do you see the the traffic an the mx wan.

You can also make packet captures  there

EDIT
Here to help

Thanks I found the issue and end up being unrelated to the setup. Confirming that my new setup now works. 

FRover
Here to help

Do you recall the solution?

EDIT
Here to help

I do it was a internal DNS issue in my case. At that time I was using same domain name for both internal/external and although it worked with my Att router originally my assumption is it broke when I migrated to the MX. I've since moved to split brain DNS for my AD and also bought a public IP block so I use public IP on the MX outside interface essentially removing MX from being behind NAT device and allowing NAT at the MX

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels