SRX

last person joined: 20 hours ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  Static NAT and Proxy ARP

    Posted 11-30-2012 12:07

    So we all know that if you have a block of IP addresses that have the same gateway, you can have two web servers behind your Juniper SRX on port 80 by having one IP address set up as your main IP address but then use Static NAT and Proxy ARP to route requests from the second IP address in your block directly to the second webserver on your network.

     

    So what happens if you have two static IP addresses and two default gateways?

     

    JamesNT



  • 2.  RE: Static NAT and Proxy ARP

    Posted 12-01-2012 00:28

    Hi

     

    Multple gateways, do you mean two WAN connections on the SRX, or to seperate gateways on your internal LAN vis different devices?

     

    Do you have a specific question or problem?

     

    There are multiple posts on this forum about having multiple WAN connections on the SRX.  Do you a quick search.

     

    However, if you have two gateways on your internal network, then you have some interesting challenges.

     

     

     

     

     

     

     



  • 3.  RE: Static NAT and Proxy ARP

    Posted 12-01-2012 06:10

    We are talking one WAN connection with two static IP's and the two static IP's have their own gateway.

     

    JamesNT



  • 4.  RE: Static NAT and Proxy ARP
    Best Answer

    Posted 12-08-2012 09:15

    This approach is NOT recommended.  To hard to get working and to hard to maintain.

     

    You should call your ISP and just get a standard 5 address /29 block and be done with it.

     

    JamesNT



  • 5.  RE: Static NAT and Proxy ARP

    Posted 12-09-2012 09:01
    Try this - remove proxy arp for those ip addresses... Make the wan interface IP address as primary and preferred. Then add the ip addresses you are nating as the secondary ip addresses on your wan interface.


  • 6.  RE: Static NAT and Proxy ARP

    Posted 12-09-2012 09:05

    We have already gotten the 5 block /29 addresses from our ISP and implemented those.  The situation that your solution would possibly work for no longer exists.  Thank you, anyway.  🙂

     

    JamesNT