Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Netscreen 25: VIP port forward failing after adding in second untrusted interface

$
0
0

Hi,

 

I had ADSL on one interface with VIP port fowarding to various servers which was working fine.   I then added a VSDL on another interface, configured the routing table metric so this became the default route, and now the VIPs dont work. I've gotten this from the debug logs: (ADSL with VIP on ethernet3, VDSL untrusted on ethernet4)

 

****** 276256.0: <Untrust/ethernet3> packet received [60]******
ipid = 59202(e742), @c7d4b918
packet passed sanity check.
ethernet3:1.144.xxx.xxx/38366->150.yyy.yyy.yyy/ppppp,6<Root>
no session found
flow_first_sanity_check: in <ethernet3>, out <N/A>
[ Dest] 17.route 1.144.xxx.xxx->10.zzz.zzz.zzz, to ethernet4
packet dropped, drop by spoofing check.

 

What I don't understand is why my packet from outside is getting rerouted to the VDSL interface (ethernet4), instead of going to my internal IP.  Is there another route I need to add?

 

Regards

Damien.


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>