08-12-2009 01:03 AM
I'm current using SSG320M firewall, screen OS 6.1
when from trust network ping to DMZ network host, all source IP have translated to my DMZ firewall interface IP
e.g.. from 10.2.4076 ping to 10.2.42.237
get session dst-ip 10.2.42.237
id 62103/s**,vsys 0,flag 00000010/0000/0001,policy 240,time 1, dip 2 module 0
if 5(nspflag 800801):10.2.40.76/41984->10.2.42.237/512,1,001372
if 6(nspflag 10800804):10.2.42.254/11721<-10.2.42.237/512,1,001
It translated to 10.2.42.254, this is my DMZ interface IP
Please advise
08-12-2009 02:03 AM
Hello
you set your interface trust on route mode
could you please do that
get config | inc interface
and post it in this case
08-12-2009 02:57 AM
The trust and DMZ interface all in NAT mode
The command <inc interface> grab too much data, which part you want?
08-12-2009 03:06 AM
hi
if you want unset your NAT between both zone you should set route mode on interface binded in respective zone
set interface ethX route
fore more inormation please refer docuemnt Concepts & Examples ScreenOS Reference Guide Volum fondamentals chapiter 4 "interface mode" page 80
thanks
08-12-2009 08:49 AM
08-12-2009 09:03 AM
Hi Oldtimer
you are right i am aprove that ![]()
thanks