You have the servers behind the firewall, on a private network, but they also have public IPs assigned to the interfaces on the servers?
You need to remove the public IPs from the servers. They should only have private IPs assigned to their interfaces. The public IPs should be set on the firewall. And you should have firewall rules that do 1-to-1 NAT between the public IP and the private IP.
|