Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  Can the traffic flows well without NAT?

    Posted 01-20-2016 00:15

    Hello, I'm so shocked because I just saw the weird situation.

     

    First of all, plz see the below catured picture.

     

    How can successful..JPEG

     

     

     

    To sum up,

    1. I configured HA configuration between SSG-140 deivces.

    2. I configured IP configuration on SSG at Trust(10.0.0.1) and Untrust(192.168.10.80)

    3. I permitted the policies (http, https, dns, ping) from Trust to Untrust.

     

    That's all, and then I did ping 8.8.8.8 at PC, but it flows very well.

     

                                               ping 192.168.10.1

     

    I don't think it flows well because I don't configure at SSG to configure NAT! (eg.VIP, DIP, MIP)

     

    I just configured IP and policies.

    Even though I permitted PING policy, I don't know why it flows well without NAT.

     

    Anybody knows its fundamentals?

     

    Regards,



  • 2.  RE: Can the traffic flows well without NAT?
    Best Answer

    Posted 01-20-2016 03:59

    Dear ksk79174766,

     

    If you have NAT configured on the "Sharer" then you don't need it on the SSGs, as long as you have a default route to the "Sharer" and a route on the "Sharer" back to the network ( 10.0.0.0/24 ). Which is probably the scenario you have if the topology graph and ping is correct.



  • 3.  RE: Can the traffic flows well without NAT?

    Posted 01-20-2016 23:33

    Thank you!! haha



  • 4.  RE: Can the traffic flows well without NAT?

    Posted 01-20-2016 10:25

    By default, traffic from trust to untrust will automatically be NAT'd to the egress interface IP.  If you would like to change this behavior, set your trust interface to "route" instead of "nat".



  • 5.  RE: Can the traffic flows well without NAT?

    Posted 01-20-2016 23:32

    Ah..!

     

    Actually I configured its mode was "NAT"..

     

    Thank you so muchㅠ_ㅠ