Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Internal cannot reach internet

$
0
0

Ethernet0/0 with IP 1.1.1.1. Which connected to the modem

I've an existing subnet 192.168.1.0/24 set at interface ethernet0/1. Computers within this subnet can reach internet .

Now, I created another subnet 192.168.2.0/24 set at interface ethernet0/2. Computers in this subnet can ping to 1.1.1.1. But cannot ping further more.

1.1.1.1 belongs to untrust zone and using virtual router 1.

192.168.1.0/24 subnet belong to trust zone and using virtual router 2.

192.168.2.0/24 subnet use the new created DMZ zone and using virtual router 2 too.

Destination default route which next hop is virtual router 1 was set. 192.168.1.0/24 should use this to reach internet. I expect 192.168.2.0/24 should use this too.

Policy from DMZ zone to untrust zone permit all was set.

 

I don't see anything missing. Just simply copy the settings from 192.168.1.0/24. I suppose it should work.


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>