  • 3898316
  • 29-Oct-2007
  • 07-Jun-2013


Novell BorderManager 3.8
Novell BorderManager 3.9
Novell NetWare 6.5 Support Pack 6
NAT.NLM Version 10.00.04 January 6, 2005


Customer has 3 different subnet bound to the same public nic:, where is bound to the nic., where is bound to the nic., where is bound to the nic.

Customer has dynamic nat enable on and works fine but the issue is with the static nats as follow: -> works -> does not work -> does not work .45 -> works -> works

Trace shows that when accessing, connection is immediately reset and the RST packet is sent by the address (first bound and used as outgoing source).

Dumping the ip address to bit level reveals: -> 01010011.xxxxxxxx.xxxxxxxx.00101001 -> 01010011.xxxxxxxx.xxxxxxxx.00101010 -> 01010011.xxxxxxxx.xxxxxxxx.00101011 -> 01010011.xxxxxxxx.xxxxxxxx.00101100 -> 01010011.xxxxxxxx.xxxxxxxx.00101101 -> 01010011.xxxxxxxx.xxxxxxxx.00101110 -> 01010011.xxxxxxxx.xxxxxxxx.00100101 -> 01010011.xxxxxxxx.xxxxxxxx.00100110

That the two non working addresses (.43 and .44) are finishing in 00 and 11 which are broadcast addresses so it looks like nat has an issue with the subnet mask used as with the /29 mask, this addresses are valid.


Reported to engineering.

As a workaround, we change the subnet mask to, so merging both subnet in one, After that, all static nats were working fine.

Thanks to Thorsten Trittschack to find and report the issue and help with the workaround