I am trying to reach other IPs outside my VLAN test network (Vlan 23 10.0.23.x). I can't ping anything but hosts within the VLAN and my outbound interface (untrust gateway IP). For example, the gateway x.x.x.x IP of the untrust can be pinged. But, I can't ping 8.8.8.8 for example (google DNS).
For example
MAC Address Address Name Interface Flags
00:18:ba:87:dd:c3 10.0.23.2 10.0.23.2 vlan.23 none
00:0e:d7:f2:b9:c0 10.0.23.101 10.0.23.101 vlan.23 none
00:1f:12:39:f8:3f 10.0.23.102 10.0.23.102 vlan.23 none
switch# ping 10.0.23.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.0.23.2, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms
Ping the untrust interface:
switch#ping xxx.xxx.xxx.206
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to x.x.x.206, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/4 ms
I have a following configurations
my_VLAN {
vlan-id 23;
l3-interface vlan.23;
}
ge-0/0/4 {
unit 0 {
family ethernet-switching {
port-mode trunk;
vlan {
members my_VLAN;
}
}
}
}
show security policies from-zone test to-zone untrust
policy test_to_internet {
match {
source-address any;
destination-address any;
application any;
}
then {
permit;
}
}
show security zones security-zone test
host-inbound-traffic {
system-services {
all;
}
protocols {
all;
}
}
interfaces {
vlan.23;
ge-0/0/4.0;
}
root@host# run show route
inet.0: 13 destinations, 13 routes (13 active, 0 holddown, 0 hidden)
+ = Active Route, - = Last Active, * = Both
0.0.0.0/0 *[Static/5] 1w3d 04:09:59
> to xxx.xxx.xxx.201 via ge-0/0/14.0
10.0.23.0/24 *[Direct/0] 6d 08:10:16
> via vlan.23
10.0.23.1/32 *[Local/0] 6d 13:17:53
Local via vlan.23
192.168.1.0/24 *[Direct/0] 6d 06:48:20
> via vlan.0
192.168.1.1/32 *[Local/0] 2w1d 13:55:39
Local via vlan.0
xxx.xxx.xxx.200/29 *[Direct/0] 1w3d 04:09:59
> via ge-0/0/14.0
xxx.xxx.xxx.206/32 *[Local/0] 3w0d 10:24:43
Local via ge-0/0/14.0