Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  Can VPN packets be NAT'ed to the firewall's public IP address?

    Posted 07-18-2014 06:29

    Hi,

    I have to build a site to site VPN between my network(LAN 1 10.1.1.0/24) using my ScreenOS firewall(public IP 3.3.3.1) and another entity's LAN.

    They gave me their internal LAN range LAN 2 192.168.10.0/24 and their firewall public IP address(2.2.2.1)

    Is there any possiblity for me to NAT the packets comming from my network LAN 1 10.1.1.0/24 to the same IP as my firewall's public IP address 3.3.3.1 on ScreeenOS?

    Which is the best practice in these situations? Route based VPNs or policy based VPNs?

    Regards,

    TCP



  • 2.  RE: Can VPN packets be NAT'ed to the firewall's public IP address?

    Posted 07-18-2014 08:21

    I dont think you can do that. Other side would then need to route your public ip address to tunnel to make it reachable through the tunnel. And because the tunnel itself is created by using that same ip address it needs to routed through the interface facing the public network (wan). Why would you want to NAT your clients to public IP anyways? Can you tell us more about this scenario?

     

    If you are satisfied with the answer, please click "Accepted as Solution". Kudos also welcome!



  • 3.  RE: Can VPN packets be NAT'ed to the firewall's public IP address?

    Posted 07-21-2014 04:40

    Hi,

    I didn't see a configuration like that yet but somebody told me it did it on a Fortigate and wanted it replicated on my Juniper SSG140.

    I agree on the part with the routing at remote end but the guy says he is sure about that mapping.

    Regards,

    TCP.



  • 4.  RE: Can VPN packets be NAT'ed to the firewall's public IP address?
    Best Answer

    Posted 07-21-2014 21:48

    Hi,

     

    If he says so. I havent tried this but I am pretty sure it wont work. And I still fail to see why would one want to do that anyways.

     

    If you are satisfied with the answer, please click "Accepted as Solution". Kudos also welcome!