Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: MIP or VIP or DIP? How can I realize the following scenario?

$
0
0

Since you have overlapping subnets on the same SSG this will be difficult to achieve.  For overlapping subnets we typically need to do both source and destination nat on the traffic between the sites.  But in this case the two sites are on the same SSG and destination nat occurs before zone look up so this would become a self reference for the traffic on the device.

 

This might work if you put both interfaces into different VR and then also have a second "outside" interface in each of these VR that you loop together.  Thus being able to treat them as if they are two SSG.  And then use the VPN with overlapping subnets to connect the two virtual sites.

the pdf link here is broken so I am uploading it.

https://kb.juniper.net/InfoCenter/index?page=content&id=KB5346

 

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>