SRX Services Gateway
Reply
Visitor
rblack
Posts: 9
Registered: ‎12-10-2007
0
Accepted Solution

SRX VIP with Dynamic Public IP

I am trying to configure an SRX 210 (running 10.0R2.10) with a dynamic Internet IP to use VIP type functionality.  When I configure the NAT, it requires me to put an IP address however because this is dynamic and could change I can't.  I used the keywork interface (set security Nat proxy-ARP interface ge-0/0/0.0 address interface) and it accepts the command, however in the configuration it replaces the interface command with an IP address that does not exist on the box (not even the dynamic IP I currently have)

 

Is the ScreenOS VIP functionality available on the SRX if you have a dynamic Internet IP? 

Contributor
storerc
Posts: 47
Registered: ‎01-23-2010
0

Re: SRX VIP with Dynamic Public IP

Try using 0.0.0.0/0 as the destination IP in your DNAT rule.

 

See this thread with discussion and config examples.

 

Regards,

-Chris
Visitor
rblack
Posts: 9
Registered: ‎12-10-2007
0

Re: SRX VIP with Dynamic Public IP

Thanks for that, the 0.0.0.0/0 does seem to be fine for the rule-set, however my problem seems to be with teh proxy-arp section which I have:

 

proxy-arp {
    interface ge-0/0/0.0 {
        address {
            0.0.0.0/0;
        }
    }

and when I try to comit I get the following error:

 

[edit security nat proxy-arp interface ge-0/0/0.0]
  'address 0.0.0.0/0'
    IP address 0.0.0.0 is invalid
error: configuration check-out failed

 

 

Contributor
storerc
Posts: 47
Registered: ‎01-23-2010
0

Re: SRX VIP with Dynamic Public IP

Because you are actually wanting to answer on the IP that belongs to the interface, there should be no need for the proxy-arp.

-Chris
Visitor
rblack
Posts: 9
Registered: ‎12-10-2007
0

Re: SRX VIP with Dynamic Public IP

Thank you,

 

You are right, I don't need the proxy arp entry and it is working perfectly.

 

Thanks for your help.

 

Richard

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.