Heyo,
I'm having troubles with a brand new NSX Edge Gateway configuration
The NSX GW is having 2 interfaces:
1 is the uplink with a public IP Address
1 is an internal network with IP : 192.168.10.1/24
I enable DHCP on the internal network and my Windows Server VMs is able to retrieve an ip and to ping the internal gateway.
The problem is that the Windows Server VM does not get internet access even though I added a SNAT rule to do so.
Is there a way for me to troubleshoot where the magic does not happen or could you help me directly?
Thanks a lot.
Flip to the uplink interface for the NAT configuration and do share the results.
Do check if Edge is having connectivity to external world via the right interface . You could perform a debug as well -> debug packet display interface interface number(vNic_x) to know(Gathering Troubleshooting Data ) if you have a successful NAT session. Also perform a trace-route from the underlying machine and check the connectivity path and try to rule out if it is routing/Firewall/NAT issue with the debug commands.
Note: If you are unsure about the root cause, please post Guest O/S ipstack details with gateway and mask, Edge routing,NAT and firewall config , followed by the display out of the debug command during the NAT test.
Heyo,
Thank you for the fast reply !
Here is the Windows Guest OS ipconfig
The NSX Edge GW is able to ping 8.8.8.8 or 1.1.1.1 so I assume there is no internet connectivity issue there.
When I do a tracert on the Guest VM I can reach the internal network gateway but i'm just getting a timeout after. (sorry for the french language)
On both the Windows and NSX firewall I opened everything to be sure that there was not firewall issue.
When I do the debug packet display interface as you said, I don't see any internal network to public interface going through but the NAT rule is there when I type show nat
On the NSX Edge GW, I didn't make any routing configuration beside putting the public IP gateway.
Here is the Firewall configuration
And here is the NAT configuration
Thanks again for your help
Thanks.
Can you please share interface configuration output of edge..
Note : Please hide the public IP info , i can see you have shared the ip as well.
Heyo,
If you click on the screenshot you'll have the full size displayed to you
Yeah forgot about hiding the public IP ... It will change later anyway so it's ok for this time
Thanks a lot
Yeah, i have a feeling you applied NAT on wrong interface. Either switch to the right interface or please provide the interface configurations screenshot to confirm it.
Here is the interfaces configuration os the Edge GW
vNIC 1 is the Uplink configured with the public IP.
The vNIC is the PROD LAN (where the issue occurs) configured on vSwitch 5000
I didn't test the STAGING LAN yet.
You have the NAT configuration in the previous messages.
Thanks
Flip to the uplink interface for the NAT configuration and do share the results.
It worked....
I can't believe it was that simple
I kidna don't understand the logic behind this then.
Because I thought the rule would apply on the Prod LAN interface to link to the UPLINK.
Thanks a lot !
Apologize for bringing such old topic back, so you switch from vNic1 to vNic0 and Guest VM can not access the internet?