ScreenOS Firewalls (NOT SRX)
Reply
Contributor
vovochka83
Posts: 23
Registered: ‎06-09-2011
0

VIP over MPLS link?

[ Edited ]

It is possible to map the public ip 11.11.11.11/24 to the server ip 192.168.10.10? So that public user able to access the server from internet.

 

Distinguished Expert
spuluka
Posts: 2,828
Registered: ‎03-30-2009
0

Re: VIP over MPLS link?

I've not used the serial interface wan before.  I assume you are saying that the vip option is not showing up on that interface.

 

Try using destination nat (nat-dst) instead.  This is the selection kb for choosing the right method.

 

http://kb.juniper.net/InfoCenter/index?page=content&id=KB11910

Steve Puluka BSEET
Juniper Ambassador
Expert Network Security Engineer - UPMC Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC
JNCIS-FWV JNCIS-SSL
ACE PanOS 6
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home
Contributor
vovochka83
Posts: 23
Registered: ‎06-09-2011
0

Re: VIP over MPLS link?

No, the vip option is showing up, but i could not access from internet to that server.

Distinguished Expert
spuluka
Posts: 2,828
Registered: ‎03-30-2009
0

Re: VIP over MPLS link?

Did you also create the policy using the vip to allow the traffic?

 

http://kb.juniper.net/InfoCenter/index?page=content&id=KB4740

 

Or are you using the same ip address as the interface?  That is not supported for vip on all platforms.

Steve Puluka BSEET
Juniper Ambassador
Expert Network Security Engineer - UPMC Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC
JNCIS-FWV JNCIS-SSL
ACE PanOS 6
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home
Contributor
vovochka83
Posts: 23
Registered: ‎06-09-2011
0

Re: VIP over MPLS link?

yes, i did create the policy to allow untrust to that vip, i got other vip running on the same interface, all other vip is working (but the ip is not mapping over mpls, only internet server).

Distinguished Expert
spuluka
Posts: 2,828
Registered: ‎03-30-2009
0

Re: VIP over MPLS link?

Confirm that the services work on the local LAN.  And cross check the configuration against the working one.

 

Run the tests for the vip in kb5545 and see if these help in the issue.

 

http://kb.juniper.net/InfoCenter/index?page=content&id=KB5545

Steve Puluka BSEET
Juniper Ambassador
Expert Network Security Engineer - UPMC Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC
JNCIS-FWV JNCIS-SSL
ACE PanOS 6
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.