Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Translated Source Address Using Default Gateway Not Alternate Public IP

$
0
0

You will need to remove the MIP for this address.  They get processed first and cannot be used with source nat as you have seen.

 

Instead check that box fo destination nat and enter the server address there.

 

You might also then need to change the zone of your destination side to the same as your outside interface for the flow to match.

 

Also be sure you have proxy-arp enabled for this address on your outside interface.

 

Bear in mind you need to test these methods with outside connections in using the policy port.  As they only work as the policy is hit by this inbound traffic.

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles