suschoud Fri, 03/09/2007 - 06:50
when a request come from internal workstations/servers to the inside interface of the firewall,it had to be natted so that it could go outside on internet.

i do not think that any packet going outside will have the source ip address of the router/switches until that request is initiated from the switch/router itself.

in normal scenerios,we nat the whole internal range ( which includes workstations/routers/switchs/servers )

in your setup,are the routers/switches generating traffic which would need to be natted ???



