Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: NS 208 port forwarding

$
0
0

The config looks ok. It must be a reachability issue.

 

You can try:

1. Set the VIP IP as the manage-IP on eth3 and try pinging it from the internet. This will validate IP reachability.

2. enable logging on the VIP policy to check if you see any hits.

3. run a debug while attempting to access one of the VIP services:

- clear db

set ff dst-ip <vip> dst-port <service you are testing>

set ff src-ip <vip> src-port <service you are testing>

debug flow basic

<<Send test traffic>>

<<Press Esc key to stop the debug>>

get db st --- this will dump the debug data

Please share this, you may replace the public IPs before sharing

4. Try adding a static ARP entry on the upstream router for the VIP IP, pointing to eth3 MAC


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>