SRX Services Gateway
Reply
Visitor
Tomdolo
Posts: 6
Registered: ‎08-29-2010
0

port forwarding without destination address

Hi,

Is it possible in Junos not to specify the destination address when doing port forwarding?

I try to translate this statement from ScreenOS into Junos:

 

set interface untrust vip untrust 25 "SMTP" 192.168.168.9

 

 

rule-set port-forwarding {
    from zone untrust;
    rule r1 {
        match {
            destination-port 25;
            ## Warning: missing mandatory statement(s): 'destination-address'
        }
        then {
            destination-nat pool s1-SMTP;
        }
    }
}

 

 

Regards,

Tom

Super Contributor
arizvi
Posts: 287
Registered: ‎10-21-2008
0

Re: port forwarding without destination address

Hi,

 

Can you please provide the "get conf | i untrust" from the screenOs box.

 

Thanks

Atif

Visitor
routeruser
Posts: 8
Registered: ‎12-17-2009
0

Re: port forwarding without destination address

If you do not care about the address in the match condition for destination address provide "0.0.0.0/0"

 

This will match any address and not care about teh specific prefix .

Visitor
Tomdolo
Posts: 6
Registered: ‎08-29-2010
0

Re: port forwarding without destination address

Thanks routeruser, but how to configure the proxy-arp?

 

commit check
[edit security nat proxy-arp interface pp0.0]
  'address 0.0.0.0/0'
    IP address 0.0.0.0 is invalid
error: configuration check-out failed

 

Regards,

Tom

Contributor
Prathi
Posts: 27
Registered: ‎07-15-2010
0

Re: port forwarding without destination address

try this, not proxy arp needed if you are using the interface IP.

 

ule-set port-forwarding {
    from zone untrust;
    rule r1 {
        match {
            destination-port 25;
            destination-address 0.0.0.0/0;
        }
        then {
            destination-nat pool s1-SMTP;
        }
    }
}

 

-Pra

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.