From Meraki
- capture "Traffic out to destination 54-39-182-217",
LAN capture line#863 (time: 11:34:17.807734) > PBX 192.168.0.3 sending Binding Request to 54.39.182.217 via Source port 10664 and Destination port 3478.
Internet capture line#111, MX passes through traffic to 54.39.182.217 with same Source and Destination port.
- capture "Traffic come from source 51.79.116.90",
Internet capture line#280, IP 51.79.116.90 sends Binding Response to MX via Source port 3479 and Destination port 10664.
LAN capture line#1021, MX passes through traffic to 192.168.0.3 with same Source and Destination port.
In MX point of view, it passes through traffic without changing any port numbers. In normal traffic flow, when client sending traffic to server, it expects the same server IP replies then MX is considering this is the same traffic flow and MX allows inbound (reply) traffic as MX is state-full firewall.
In this case, traffic sending to 54.39.182.217 but replies from 51.79.116.90. MX considers this is as different traffic flow and without Port-Forwarding rule, this inbound traffic will be dropped. But because you configure Port-Forwarding rule, then MX just passes traffic as second capture.
The questions now are;
- Why different server reply traffic Binding Response?
- As MX passes traffic through, does server see that traffic reaching the server?
Traffic out to destination (Our IP has been hidden)
Traffic from remote destination for test (Our IP has been hidden)
