Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Translated Source Address Using Default Gateway Not Alternate Public IP

$
0
0

Steve, thanks for the response. I have added the PBR as instructed and I also enabled ARP but I am still getting the same results. I added all of the details below so hopefully we can get this resolved. Thanks again for all of your help on this.

 

ARP ENABLED

2018-02-12 12:22:03 notif ARP always on destination enabled

 

Interface

Interface List Page

 
NameIP/NetmaskZoneTypeLinkPPPoE
ethernet1192.168.0.1/24TrustLayer3Up-
ethernet2192.168.100.1/24DMZLayer3Up-
ethernet324.24.24.69/24UntrustLayer3Up-
ethernet4212.24.24.42/29UntrustLayer3Up-

 

Interface: Ethernet4 (212.24.24.42/29)

Dynamic IP List Page

NAT
 
IDIP Address RangeDIP TypeConfigure
5212.24.24.45--212.24.24.45Port-XlateIn use

 

 Destination

Network Routing Table List Page

trust-vr
 IP/NetmaskGatewayInterfaceProtocolPreferenceMetricVsysConfigure
*192.168.0.0/24 ethernet1C  Root -
*192.168.0.1/32 ethernet1H  Root -
*24.24.24.0/24 ethernet3C  Root -
*24.24.24.68/32 ethernet3H  Root -
*212.24.24.40/29 ethernet4C  Root -
*212.24.24.42/32 ethernet4H  Root -
*0.0.0.0/024.24.24.1ethernet3S201Root  
*24.24.24.61/32 ethernet1S201Root  
*212.24.24.45/32 ethernet1S201Root  

 

 

Source Routing

Network Source Routing Table List Page

trust-vr  
  Source Routing
 IP/NetmaskGatewayInterfaceProtocolPreferenceMetric 
*192.168.0.45/32 ethernet4S201

 

Source Interface Based Routing

Network Interface Routing Table List Page

ethernet4(trust-vr)
 IP/NetmaskGatewayInterfaceProtocolPreferenceMetric 
*212.24.24.45/32 ethernet1S20

 

 

PBR INFORMATION

 

trust-vr
Extended Access List ID : 1

 

Seq NoSource IPSource PortDestination IPDestination PortProtocolQOS PriorityConfigure
1192.168.0.45N/A0.0.0.0/0N/AANYN/A 

 

 

trust-vr

Match Group ID: Email-Match

Seq NoACL-EXT NameConfigure
11Remove

 

trust-vr

Action Group ID : Email-Action

Seq NoNext Interface/Next Hop Configure
1ethernet4Remove

 

trust-vr

Policy Name: Email-Policy

Policy NameMatch GroupAction GroupConfiguration
1Email-MatchEmail-ActionRemove

 

 

Policy Binding

 
 
Virtual RouterPolicy NameZonePolicy NameInterfacePolicy NameAction Policy
trust-vrN/ATrustN/Aethernet1Email-PolicyEmail-Policy
UntrustN/Atunnel.2N/AN/A
tunnel.1N/AN/A
ethernet4N/AN/A
ethernet3N/AN/A
Untrust-TunN/AtunnelN/AN/A
DMZN/Aethernet2N/AN/A

 

Policy

Policy list page

Untrust To Trust

Any to 212.24.24.45/32

Policy Configuration

Advanced Policy Settings

NAT (Destination Translation) to 192.168.0.45

 

Trust To Untrust

192.168.0.45 to Any

Service: DNS and Email

Policy Configuration

Advanced Policy Settings

NAT (Source Translation) to DIP 212.24.24.45

 

LOG DETAILS

 

Untrust To Trust Results

Date/TimeSource Address/PortDestination Address/PortTranslated Source Address/PortTranslated Destination Address/PortServiceDurationBytes SentBytes ReceivedClose Reason
2018-02-12 17:39:4421.200.12.95:15628212.24.24.45:2521.200.12.95:15628192.168.0.45:25SMTP (TCP)18 sec.78390Close - AGE OUT
2018-02-12 17:39:1421.200.12.95:15628212.24.24.45:2521.200.12.95:15628192.168.0.45:25SMTP (TCP)19 sec.390624Close - AGE OUT

 

Trust To Untrust Results

 

 
Traffic log for policy :
IDSourceDestinationServiceAction
150Trust/192.168.0.45:/32Untrust/AnyDNS Services
Web Services
Permit

Date/TimeSource Address/PortDestination Address/PortTranslated Source Address/PortTranslated Destination Address/PortServiceDurationBytes SentBytes ReceivedClose Reason
2018-02-12 17:36:48192.168.0.45:496908.8.8.8:53212.24.24.45:43728.8.8.8:53DNS88 sec.6020Close - AGE OUT
2018-02-12 17:36:40192.168.0.45:422728.8.8.8:53212.24.24.45:43718.8.8.8:53DNS90 sec.6230Close - AGE OUT
2018-02-12 17:36:04192.168.0.45:397468.8.8.8:53212.24.24.45:43708.8.8.8:53DNS86 sec.4860Close - AGE OUT

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>