VOS uses the following ports for specific services as mentioned, if DNAT or Basic NAT-44 is configured for the below ports, then traffic will be consumed by the mentioned service before it hits the CGNAT service.

 

SNOProtocolPort number
Service
1
TCP
22SSH
2TCP1020 to 1120Versa Director HA
4TCP3000 to 3003Versa Director HA
6TCP9878Versa Director HA
7UDP53DNS
8UDP67 and 68DHCP
9UDP123NTP
10UDP4500IKE/IPSEC
11UDP500IKE/IPSEC
12UDP3066CMPv2
13UDP3067OSCP
14UDP3784 and 4784BFD
15UDP4790VXLAN SDWN
16UDP9201DHCP Lease sync
17UDP3002 and 3003HA



NOTE:

If you would like to use any of the above ports then use different IP from the WAN Pool which is not part of any interface.


If you have deployed Versa devices in active-active, please follow below steps to configure DNAT or basic nat-44 over any of above ports:

  • Configure NAT pool for IP which is not part of any VOS interfaces including VRRP VIP.
  • Disable Proxy ARP under CGNAT rule created for DNAT or Basic nat-44 on both Active-Active VOS devices
  • Configure Proxy ARP under interface interface on both Active-Active devices for IP used in NAT pool.
  • Configure VRRP on both Active-Active devices with one has master and other as backup by adjusting priority and configure VIP on IP which is not same as IP used in NAT pool.