防火牆上有WAN1和WAN2兩條對外線路(不同ISP),並都開啟PA的GP SSL-VPN
1.WAN1的GP正常、ping和tracert都正常
2.WAN2的GP目前測試起來只要是中華電信的網路(手機熱點分享網路給筆電or光世代和ADSL)都會無法連線到WAN2的GP也ping和tracert不到,但只要透過非中華的網路則GP可以正常使用、ping和tracert都可以正常
設備廠商說為ISP業者的問題,但報修WAN2,已請查修人員查修
1.將筆電設定WAN2的IP並且直接接到MODEM後面,再透過中華的網路做ping和tracert為正常
2.使用一台Fortigate並設定ssl-vpn,再透過中華的網路做ssl-vpn連線和ping與tracert為正常
測試透過中華電信手機熱點分享給筆電,使用GP連線wan2並從PA上撈log給原廠分析(無法連線),回覆如下方,連線WAN2但卻跑到WAN1,這部分WAN2的ISP回覆是PA設定的問題非線路問題
並同時也請原廠support協助,回復如下:(e1/1 WAN1,e1/2 WAN2)
Please refer the logs below, we found it has the SYN ACK packet using this ISP, which is working as expected, and immediately following receive SYN packet again (then get in fastpath). The 'Route lookup in virtual-router 1, IP (手機熱點給筆電的IP)/Route found, interface ethernet1/1, zone 3, nexthop 6(WAN1的router IP)' and 'Transmit packet size 52 on port 16'(port id 16 is e1/1) indicates the packet has sent out from ethernet1/1 then, hence we suggest you to confirm with the other ISP on e1/1 - WAN to probe into where the packet drops, thank you.
Packet received at forwarding stage, tag 108374, type ATOMIC
Packet info: len 66 port 0 interface 17 vsys 1
wqe index 228011 packet 0x0x80000003161eb8c0, HA: 0, IC: 0
Packet decoded dump:
L2: 00:00:00:00:00:00->00:00:00:00:00:00, type 0x0800
IP: (WAN2 IP)->(手機熱點分享的IP), protocol 6
version 4, ihl 5, tos 0x00, len 52,
id 55899, frag_off 0x0000, ttl 64, checksum 13253(0x33c5)
TCP: sport 443, dport 50584, seq 2237298253, ack 3724531897,
reserved 0, offset 8, window 65535, checksum 34794,
flags 0x12 ( SYN ACK), urgent data 0, l4 data len 0
TCP option:
00000000: 02 04 05 78 03 03 02 01 01 01 04 02 ...x.... ....
Forwarding lookup, ingress interface 17
L3 mode, virtual-router 1
Route lookup in virtual-router 1, IP (手機熱點分享的IP)
Route found, interface ethernet1/1, zone 3, nexthop (WAN1的router IP)
Packet forwarded to different zone 3 than zone 7 in session 108374
Resolve ARP for IP (WAN1的router IP) on interface ethernet1/1
ARP entry found on interface 16
Transmit packet size 52 on port 16
目前設備廠商說為ISP問題,ISP業者反應已測試過筆電和Fortigate設備測試此線路和IP都沒有問題,請問從這個回覆能判斷是ISP問題或是PA的設定問題嗎?
謝謝
是你PA上的ECMP, 跟路由設定出問題