  MIP and NAT

    Posted 04-29-2010 05:01

    Hi Everyone,


    I'm new to the SSG350 6.3r3 and I have the folowing question / situation.

    (I have used the configuration wizard by the first startup of the device)


    We have several server (+20) who needs to be accessd from outside our network by a public dnsname / IP. I can't get this to work with MIP.


    My Config:


    Trust IP range; /

    Untrust IP range: x.87.182.1 /


    Trust interface:

    Untrust interface: x.87.182.1


    Routing Entries: Trust-vr

    IP/Network               Gateway          Interface                   Protocol        Vsys                                   ethernet0/0              C                     Root                                   ethernet0/0              H                     Root

    x.87.182.0/24                                   ethernet0/2              C                     Root

    x. 87.182.2                                        ethernet0/2              H                     Root                    x.87.182.1     ethernet0/2              C                     Root 


    On the untrust interface I have configured a MIP for testing purposes: x.87.182.100 to

    ( is a simple webserver and is working in the internal network)


    Policy from Trust to Untrust = Any to Any

    Policy from Untrust to Trust = Any to Any


    From the Untrust network:

    - I can't connect to the internal website

    - I can ping the untrust interface x.87.182.1 but NOT the MIP  x.87.182.100


    What do I wrong?





  RE: MIP and NAT
    Posted 04-29-2010 05:53

    Hi Frank,


    Try adding the MIP as the destination instead of "ANY" (Untrust, any, Trust, MIP).



  RE: MIP and NAT

    Posted 04-29-2010 06:00

    YES ! it's working now. Sometimes things are very easy 🙂


    Thanks John.

  RE: MIP and NAT

    Posted 11-02-2010 15:29
  RE: MIP and NAT

    Posted 10-18-2011 09:27

    HI,firewall72,I have a very strange question,could you help me?

    My equipment is SSG550, Netscreenos  :6.5.0


    my config


    ethernet 1: route mode   untrust zone        ip: 

    ethernet 2: route mode   trust zone             ip: 


    my intranet ip are /24


    Now I find that when the server which ip  is visit an ip range such as ,its ip is not be translated,it is still  Then the question comes,when vist any other ip ,its ip would be translated to for untrust



    But I do not do any policy to permit this,and I do not config any Mip,Dip and Vip ,I confirm that both two interfaces are route mode,is it a bug?





