ScreenOS Firewalls (NOT SRX)
ScreenOS Firewalls (NOT SRX)

Do I need to create route if both subnet using the same virtual router

3 weeks ago

After created the 2 subnets
ethernet0/1 192.168.1.0/24 Layer3
ethernet0/2 192.168.2.0/24 Layer3

There were 4 route entries auto created
192.168.1.0/24 ethernet0/1 Protocol C
192.168.1.1/32 ethernet0/1 Protocol H
192.168.2.0/24 ethernet0/2 Protocol C
192.168.2.1/32 ethernet0/2 Protocol H

Policies for the 2 zones were set. Do I need to create new route for these 2 subnets to reach each other?

4 REPLIES 4
ScreenOS Firewalls (NOT SRX)
Solution
Accepted by topic author jlotag
3 weeks ago

Re: Do I need to create route if both subnet using the same virtual router

3 weeks ago

Nothing on the firewall but you need appropriate gateways configured on the hosts in that particular subnet to reach the Firewall and the routing is taken care by the firewall with the routes available as they are directly connected to it.

 

Thanks and Regards,

Pradeep Kumar M.

ScreenOS Firewalls (NOT SRX)

Re: Do I need to create route if both subnet using the same virtual router

3 weeks ago

Thanks pradkm.

Actually, I set the ethernet interfaces to be the gateway.

ethernet0/1
Static IP 192.168.1.1 /24
Zone Trust
ethernet0/2
Static IP 192.168.2.1 /24
Zone DMZ

Is that enough for the computers in the 2 different subnets reach each other?

ScreenOS Firewalls (NOT SRX)

Re: Do I need to create route if both subnet using the same virtual router

3 weeks ago

Yes, that should do.

 

Thanks and Regards,

Pradeep Kumar M

ScreenOS Firewalls (NOT SRX)

Re: Do I need to create route if both subnet using the same virtual router

3 weeks ago

The configuration does cover the routing but this is a firewall too.

 

So the interfaces need to be assigned to a zone.

 

If they are in the same zone the default policy is permit.  

If they are different zones then a policy must be created to permit the traffic.

 

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home