TMS zl Management and Configuration Guide ST.1.0.090213

D-50
Troubleshooting
Troubleshooting the TMS zl Module in Routing Mode
3. Use the show connections command to verify that addresses are translated
as you expect them to be.
Check the NAT policies in the Firewall > NAT Policies > Policies window
to ensure that they are configured correctly.
For destination NAT, verify that an access policy to the Self zone
permits the traffic selected for NAT.
4. Ensure that other network routers have the correct routing information
to route the packets.
The following are commonly asked questions about the TMS zl Module’s NAT
functionality:
How does multicast NAT work on the TMS zl Module?
The TMS zl Module does not support NAT with multicast traffic. When
you configure a NAT policy, the TMS zl Module will not apply that policy
to any multicast traffic.
What happens if the TMS zl Module does not match traffic to a NAT
policy?
The TMS zl Module will continue to process the traffic if there are no NAT
policy matches. The module will try to match the traffic against access
policies, and if the traffic matches an access policy, it will not be dropped.
Troubleshooting Port Maps
You receive one of the following errors when you try to add a port map:
At the CLI:
Error failed to add port-map
At the Web browser interface:
The port map could not be added.
Make sure that the number of port map entries does not exceed the limit. The
TMS zl Module currently supports up to 1001 port map entries.
Troubleshooting IPS
If you need to troubleshoot IPS, you should first check the following:
IPS is enabled globally.
IPS is enabled on each access policy for which you want to check the
related traffic.