Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Translated Source Address Using Default Gateway Not Alternate Public IP

$
0
0

Spuluka, I have removed the MIP for that IP as recommended and setup new policies but for some reason I am getting the same results.   Incoming is working perfectly with the 'destination' updated in the policy (advanced) to point to the internal NAT address.  The issue still is with the outgoing translated source, it is still defaulting to the default subnet IP on eth3 instead of the IP related to the eth4 subnet. 

 

The mail server associated with eth3 works fine for both incoming and outgoing. The mail server associated with eth4 works for incoming but outgoing translates to the eth3 default.  The outgoing IP for the email server that is not translating is 212.24.24.45 and it is part of subnet 212.24.24.42/29 associated with eth4.  Do i need to setup a source or destination route?

 

I setup source translation on the outgoing policy but nothing gets out. If I turn off source translation under advanced on the outgoing policy, then packets are sent but they are sent with the IP associated with the eth3 subnet, not the IP associated with the eth4 subnet.  This did not work https://www.screencast.com/t/wUgTOKqeiT 

 

I assume I have to run in CLI mode to enable proxy-arp to the IP in the eth4 subnet?


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>