Symptom
traceroute do not work when we have NAT pool overload configured on SDWAN Cedge with NAT DIA configuration.
The return packets are dropped by implicit ACL on WAN port.
Conditions
The issue is seen with below two conditions.
- NAT pool overload
- NAT pool addresses are in different subnet as of WAN interface IP.
Workaround
Use explicit ACL to allow all packets on WAN port or use interface overload.
Further Problem Description