I have a customer with a new SSG 140 and I hope that you can recommand how to the setup the system:
The customer connected to the internet via ADSL (PPPoE on int 2). The LAN connected to the int 0 and the DMZ connected to int 1.
The PPOE (int. 2) obtain the IP from the ISP (DHCP): 184.108.40.206 The LAN int. (int. 0) 192.168.30.254, with the network 192.168.30.0/24 The dmz int. (int. 1) 10.10.10.254, with the network 10.10.10.0/24
The customers have to servers that need to be accessed from outside:
Exchange server: 192.168.30.1 on the LAN.
SA 2500: 10.10.10.253 on the dmz and 192.168.30.253 on the lan.
Currentlly the Exchange use the public IP: 220.127.116.11 (SMTP) and the SA 2500 use the public IP: 18.104.22.168 (IKE + HTTPS)
You can create MIP with desired local IPs at int 2 for IPs 22.214.171.124 (SMTP) & SA 2500 126.96.36.199 (IKE + HTTPS), create policy from untrust to trust for SMTP MIP and Untrust to DMZ for SA2500 MIP.
Sorry to bring back such an old topic, but i didn't felt i could create an another one, since the problem i'm facing it's always the same.
I Have no experience in Juniper products and i must conffess i'm lost even tough i have a bunch os materials here to read.
But got no sucess at all until now.
I'm trying to setup a Lan port wich is it going to be connected to a swichcore inside our datacenter and an another port whose objective is to and give internet access throughout and static ip adress given by our ISP, this interfce will usee inityally only webfiltering to all users coming troughtout the lan.
So here's what i have planned.
Unbinded all default interrfaces and seted as follow:
e0/1 it's goig to be my LAN interface that's going to be connected to the switchcore
e0/2 it's goiing to receive a WAN link with static IP and it's going to be used to provide internet access to my LAN.
e0/1 is setted in the trust zone and the e0/2 is setted in the Untrusted zone, both of them are in the trust-vr.
How can i assign all the traffic coming from e0/1 to the e0/2 and apply webfiltering on it?
Any help will be appreciated, since the subject it's URGENT.