Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: MIP VPN

$
0
0

Sorry, I had forgotten we were talking about a MIP here.  You are right this is confusing.

 

MIP are in the global zone for some reason.  Thus policies that use MIP are written to the global zone.  When you create a MIP you will see that it becomes available on the web UI select list in all zones as a result.  And when you pick the MIP object the policy is created in the global zone on that side.

 

But in your case your MIP is an entire network and your policies more specific so you needed to create them manually this way.

 

I have also noticed that this only seems to be enforced when the MIP is the source of traffic.  For some reason unknown to me the destination hit of the MIP object still seems to work with the policy written to the interface zones.


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>