A LAN client is trying to copy a file from an externally hosted TFTP server on UDP 69.Server is 3.xxx.xxx.xxx
We are seeing traffic on the LAN side making a outgoing connection to the server 3.xxx.xxx.xxx. We are seeing a reply from the server on the internet side but this traffic is not being seen on the LAN side.
LAN side capture showing outgoing request to TFTP internet hosted TFTP server on UDP 69
Client is sending it's ephemeral port shown below as 57357/8 on this capture.
59.xx.xx.x is the external facing WAN 1 IP.
03:27:26.814127 IP 10.xxx.xxx.xxx.57357 3.xxx.xxx.xxx.69: 47 RRQ "filename.bin" octet
03:27:37.813805 IP 10.xxx.xxx.xxx.57357 3.xxx.xxx.xxx.69: 47 RRQ "filename.bin" octet
03:27:48.814127 IP 10.xxx.xxx.xxx.57357 3.xxx.xxx.xxx.69: 47 RRQ "filename.bin" octet
WAN side capture. As you can see the TFTP server is replying with 57357 as the destination UDP port which seems OK.
03:28:23.321187 IP 3.xxx.xxx.xxx.40000 59.xx.xx.xx.57358: UDP, length 516
03:28:26.082806 IP 3.xxx.xxx.xxx.40001 59.xx.xx.xx.57357: UDP, length 26
03:28:27.087741 IP 3.xxx.xxx.xxx.40002 59.xx.xx.xx.57357: UDP, length 516
03:28:28.072184 IP 3.xxx.xxx.xxx.40003 59.xx.xx.xx.57357: UDP, length 516
03:28:28.335387 IP 3.xxx.xxx.xxx.40000 59.xx.xx.xx.57358: UDP, length 516
03:28:31.079360 IP 59.xx.xx.xx.57358 3.xxx.xxx.xxx.69: 47 RRQ "filename.bin" octet
03:28:31.317015 IP 3.xxx.xxx.xxx.40001 59.xx.xx.xx.57358: UDP, length 516
03:28:34.325215 IP 3.xxx.xxx.xxx.40001 59.xx.xx.xx.57358: UDP, length 516
03:28:37.093729 IP 3.xxx.xxx.xxx.40002 59.xx.xx.xx.57357: UDP, length 26
03:28:38.133726 IP 3.xxx.xxx.xxx.40003 59.xx.xx.xx.57357: UDP, length 516
03:28:38.344658 IP 3.xxx.xxx.xxx.40000 59.xx.xx.xx.57358: UDP, length 516
I rasied a TAC case as my understanding is that the MX should not block this traffic and just forward it on to the orignating client.
My reply from Meraki TAC
===================
The problem is at the UDP port numbers 40000, 40001, 40002, 40003 from the TFTP server 3.xxx.xxx.xxx.
The MX has the flow for UDP port 69 to the TFTP server and it does not have an egress flow for UDP port 4000* to the TFTP server.
As the nature of the firewall, the MX just drops the unmatched packets.
The MX has NAT'ed properly for the outgoing traffic and the TFTP server has received the packets and replied back.
===================
Is my understanding of MX's functions wrong. Why would I need to port forward 4000x in the MX.
I never see a single packet from 3.xxx.xxx.xxx appear on the LAN side.
Cheers
Barry