06-01-2010 08:29 AM
Do NAT rules need to be configured on an SRX firewall in order to pass traffic between different security zones? Or, by default, will the SRX function like a ScreenOS firewall with all of its interface in "Route" mode.
Regards,
06-01-2010 09:50 AM
no, Nat rules are not needed to pass traffic
Security policies are needed
06-01-2010 07:03 PM
Thank you. That is what I thought and what my testing seems to indicate. But I am looking for an answer to some strange connectivity issues with an SRX cluster.
Regards,
06-05-2010 03:20 PM
Hi.
to investigate connectivity issues traceing on security flow is big help.
set security flow traceoptions file my_logfile
set security flow traceoptions flags basic-datapath
set security flow traceoptions packet-filter my_filter Some filter condition
commit
Run traffic
Look at he results with (run) show log ny_logfile