Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Internal ip address SSG 550M

$
0
0

I can think of two possibilities.

 

Policies

Confirm that the ip addresses involved are permited by the policies when the device moves.

Especially chech that MIP and VIP that are interface associated are not affected by the change (sounds like not since these would be on the untrust side and I think you are moving the trust side.)

 

Asymmetrical routing

 

What is the default gateway for the traffic and how does it get to the SSG?

If there are two firewalls in the same subnet and the ASA is the default gateway for the devices which then forwards to the SSG the reverse flows will not match the outbound flows.  This prevents correct session tables from being setup.

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>