Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: unable to ping/ssh slave ssg firewall through vpn

$
0
0

As Gokul mentions a nat rule may take care of the asymmetrical routing but to be sure exactly what is happening and why a diagram would be helpful. 

 

Clearly from the spoof report your traffic is coming in one interface while the route on the device is pointing to a different one.  So that is the issue that needs to be resolved.

 

We can change the return route to match the ingress.

Change the forwarding route on the previous device so that it comes in on the expected interface.

Or source nat the traffic on the previous device so that the return address matches a route pointing to the ingress interface.

 

Any of these actions will clear the spoofing report.

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>