Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: SSG 5 - get VIP to look for route in Untrust-vr

$
0
0

Hi

 

Here below is the debug flow basic. I have also attached a little more detailed config experpt.

1.1.1.2 external ip

2.2.2.2 SSG firewall

 

****** 472511.0: <Untrust/ethernet0/0> packet received [82]******
  ipid = 28685(700d), @0384c310
  packet passed sanity check.
  flow_decap_vector IPv4 process
  ethernet0/0:1.1.1.2/2398->2.2.2.2/20409,17<Root>
  no session found
  flow_first_sanity_check: in <ethernet0/0>, out <N/A>
  [ Dest] 95.route 1.1.1.2->2.2.2.1, to ethernet0/0
  self check, not for us
  chose interface ethernet0/0 as incoming nat if.
  flow_first_routing: in <ethernet0/0>, out <N/A>
  search route to (ethernet0/0, 1.1.1.2->10.238.135.227) in vr trust-vr for vsd-0/flag-0/ifp-null
  no route to (1.1.1.2->10.238.135.227) in vr trust-vr/0
  packet dropped, no route
****** 472513.0: <Untrust/ethernet0/0> packet received [82]******
  ipid = 29032(7168), @03826b10
  packet passed sanity check.
  flow_decap_vector IPv4 process
  ethernet0/0:1.1.1.2/2398->2.2.2.2/20409,17<Root>
  no session found
  flow_first_sanity_check: in <ethernet0/0>, out <N/A>
  [ Dest] 95.route 1.1.1.2->2.2.2.1, to ethernet0/0
  self check, not for us
  chose interface ethernet0/0 as incoming nat if.
  flow_first_routing: in <ethernet0/0>, out <N/A>
  search route to (ethernet0/0, 1.1.1.2->10.238.135.227) in vr trust-vr for vsd-0/flag-0/ifp-null
  no route to (1.1.1.2->10.238.135.227) in vr trust-vr/0
  packet dropped, no route
****** 472519.0: <Untrust/ethernet0/0> packet received [82]******
  ipid = 29812(7474), @03878b10
  packet passed sanity check.
  flow_decap_vector IPv4 process
  ethernet0/0:1.1.1.2/2398->2.2.2.2/20409,17<Root>
  no session found
  flow_first_sanity_check: in <ethernet0/0>, out <N/A>
  [ Dest] 95.route 1.1.1.2->2.2.2.1, to ethernet0/0
  self check, not for us
  chose interface ethernet0/0 as incoming nat if.
  flow_first_routing: in <ethernet0/0>, out <N/A>
  search route to (ethernet0/0, 1.1.1.2->10.238.135.227) in vr trust-vr for vsd-0/flag-0/ifp-null
  no route to (1.1.1.2->10.238.135.227) in vr trust-vr/0
  packet dropped, no route

Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>