VMware Networking Community
Abolaah
Contributor
Contributor
Jump to solution

NSX Edge Gateway does not give internet to vLAN even with SNAT rules and Firewall open

Heyo,

I'm having troubles with a brand new NSX Edge Gateway configuration

The NSX GW is having 2 interfaces:

1 is the uplink with a public IP Address

1 is an internal network with IP : 192.168.10.1/24

I enable DHCP on the internal network and my Windows Server VMs is able to retrieve an ip and to ping the internal gateway.

The problem is that the Windows Server VM does not get internet access even though I added a SNAT rule to do so.

Is there a way for me to troubleshoot where the magic does not happen or could you help me directly?

Thanks a lot.

Reply
0 Kudos
1 Solution

Accepted Solutions
Sreec
VMware Employee
VMware Employee
Jump to solution

Flip to the uplink interface for the NAT configuration and do share the results.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered

View solution in original post

Reply
0 Kudos
9 Replies
Sreec
VMware Employee
VMware Employee
Jump to solution

Do check if Edge is having connectivity to external world via the right interface . You could perform a debug as well -> debug packet display interface  interface number(vNic_x) to know(Gathering Troubleshooting Data ) if you have a successful NAT session. Also perform a trace-route from the underlying machine and check the connectivity path and try to rule out if it is routing/Firewall/NAT issue with the debug commands.

Note: If you are unsure about the root cause, please post Guest O/S ipstack details with gateway and mask, Edge routing,NAT and firewall config , followed by the display out of the debug command during the NAT test.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
Reply
0 Kudos
Abolaah
Contributor
Contributor
Jump to solution

Heyo,

Thank you for the fast reply !

Here is the Windows Guest OS ipconfig

pastedImage_7.png

The NSX Edge GW is able to ping 8.8.8.8 or 1.1.1.1 so I assume there is no internet connectivity issue there.

pastedImage_5.png

When I do a tracert on the Guest VM I can reach the internal network gateway but i'm just getting a timeout after. (sorry for the french language)

pastedImage_6.png

On both the Windows and NSX firewall I opened everything to be sure that there was not firewall issue.


When I do the debug packet display interface as you said, I don't see any internal network to public interface going through but the NAT rule is there when I type show nat

pastedImage_4.png

On the NSX Edge GW, I didn't make any routing configuration beside putting the public IP gateway.

Here is the Firewall configuration

pastedImage_8.png

And here is the NAT configuration

pastedImage_9.png

Thanks again for your help Smiley Happy

Reply
0 Kudos
Sreec
VMware Employee
VMware Employee
Jump to solution

Thanks.

            Can you please share interface configuration output of edge..

Note : Please hide the public IP info Smiley Happy , i can see you have shared the ip as well.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
Reply
0 Kudos
Abolaah
Contributor
Contributor
Jump to solution

Heyo,

If you click on the screenshot you'll have the full size displayed to you Smiley Happy

Yeah forgot about hiding the public IP ... It will change later anyway so it's ok for this time Smiley Happy

Thanks a lot

Reply
0 Kudos
Sreec
VMware Employee
VMware Employee
Jump to solution

Yeah, i have a feeling you applied NAT on wrong interface. Either switch to the right interface or please provide the interface configurations screenshot to confirm it.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
Reply
0 Kudos
Abolaah
Contributor
Contributor
Jump to solution

Here is the interfaces configuration os the Edge GW

pastedImage_0.png

vNIC 1 is the Uplink configured with the public IP.

The vNIC is the PROD LAN (where the issue occurs) configured on vSwitch 5000

I didn't test the STAGING LAN yet.

You have the NAT configuration in the previous messages.

Thanks Smiley Happy

Reply
0 Kudos
Sreec
VMware Employee
VMware Employee
Jump to solution

Flip to the uplink interface for the NAT configuration and do share the results.

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
Reply
0 Kudos
Abolaah
Contributor
Contributor
Jump to solution

It worked....

I can't believe it was that simple

I kidna don't understand the logic behind this then.
Because I thought the rule would apply on the Prod LAN interface to link to the UPLINK.

Thanks a lot !

Reply
0 Kudos
nookzzz
Contributor
Contributor
Jump to solution

Apologize for bringing such old topic back, so you switch from vNic1 to vNic0 and Guest VM can not access the internet?

Reply
0 Kudos