Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Newbie issue with SSG140 MIP/VIP configuration for multipl public IPs on different subdomains

$
0
0

Yes, destination NAT inside of your policy is how you do this.

 

You can have the destination device in any zone you want.  Naturally the best practice is to isolate any hosts you expose to the internet in a DMZ secured internal zone.  But this is not a technical requirement to use the feature and the zones can have any name.

 

Create your inbound allow pollicy from Untrust zone to your internal zone

Destination address is the public address you want to translate.  make this object in the same zone as your server internal address.

Permit the desired ports in this policy

On the advanced tab of the policy check the box for destination translation and enter the internal address.

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>