SNAT Not Applied to Traffic Over Site-to-Site IPsec VPN

Description

Traffic sourced from a local host and destined for a remote subnet over a policy-based site-to-site IPsec VPN (IKEv2) does not undergo the configured Source Network Address Translation (SNAT), and the translated source address is not observed at the remote endpoint. This occurs on SonicOS 8.2.2 and 7.3.2 when a manual NAT policy is configured under Network > NAT Policies for traffic that also matches the Local and Remote Networks defined in the IPsec VPN Policy.

Resolution

1. Verify that the traffic in question matches the Local Networks and Remote Networks defined in the site-to-site IPsec VPN Policy.
2. Note that when a Policy-Based VPN is configured, the IPsec Policy takes precedence over manual NAT policies for traffic matching the negotiated Security Association (SA).
3. Configure the required address translation using the built-in NAT feature inside the IPsec VPN Policy configuration instead of a manual NAT policy under Network > NAT Policies. Reference: https://www.sonicwall.com/support/knowledge-base/how-can-i-configure-nat-over-vpn-in-a-site-to-site-vpn/kA1VN0000000NBA0A2
4. Verify the translated source address by capturing packets at the remote peer and confirming the expected translated source IP appears.

 

Note:

  • A manual NAT policy created under Network > NAT Policies will either be bypassed or, if it alters the source or destination outside the negotiated SA, cause the firewall to drop the packet as non-VPN traffic.
  • The IPsec-based NAT applies to all traffic on the tunnel, not to a single host, so it cannot be scoped to one machine using this method.
  • Packet Monitor may show VPN traffic as Consumed rather than Forwarded; this does not by itself indicate that NAT failed.

Related Articles

  • Troubleshoot steps if a firewall status is Offline on NSM SaaS
    Read More
  • GVC : Degraded Internet throughput from local ISP even though connected in Split tunnel
    Read More
  • How to configure failover when there are two or more WAN Interfaces?
    Read More
not finding your answers?