Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  general question about destination nat on ScreenOS FW

    Posted 03-24-2017 09:56

    hey i have the following scenario. I have a server in the dmz (no public IPs), which should be reachable externally via port 443 tcp and udp. 

     

    can i just configure to seperate VIPs (one for tcp and one for udp) + the additional policies to get this working?

     

    will a Custom Service, that contains both port 443 for tcp and udp work for the VIP?



  • 2.  RE: general question about destination nat on ScreenOS FW
    Best Answer

    Posted 03-24-2017 10:13

    You can configure a custom service with multiple protocols and set that to the VIP.  You would need to enable VIP multi port though.

     

    https://kb.juniper.net/InfoCenter/index?page=content&id=KB5471&actp=METADATA

     

     



  • 3.  RE: general question about destination nat on ScreenOS FW

    Posted 04-07-2017 07:30

    thank you very much, much appreciated