WAN IP subnet outside Gateway address subnet (Scaleway/Online.net)
So I have been pulling my hair out trying to get this to work. From alot of reading, I gathered the following to be true
the OVA file deployed added 3 nics
Nic1 = fxp0
Nic2 = Ge-0/0/0
Nic3 = Ge-0/0/1
So Online.net failover IPs ( as the primary gets installed as the esxi management ip ) does a wonderful here used this slash 32 ip and point the gatewayto this other ip address that not even in the same /8 .
Now I used them fora long time and know this works as they white list the mac of the network interface that is getting the wan ip.
This has worked with out issues in Linux ( untangle ) and BSD with PfSense/Opnsense as goofy as it may seem.
So I have my interfaces setup as following
fxp0.0 = dhcp 10.0.8.21
Ge-0/0/0.0 10.0.10.1/24 (LAN / trusted zone )
Ge-0/0/1.0 188.8.131.52/32 ( Wan / untrusted )
config still very basic but show route will not show my static from 184.108.40.206 to 220.127.116.11 or that 18.104.22.168 to 0.0.0.0
Re: WAN IP subnet outside Gateway address subnet (Scaleway/Online.net)
Thank you for your quick reply.
I will say it very disappointing that this is the first virtualized firewall that has not been able to handle this. As even the horrible sonicwall virtual appliance works with this setup as well does Cisco ASAv platform.
Since this was in a "lab" environment option 1 just not going to work, while option 2 could work it defeats the purpose of the test. This was for an evaluation purpose where I needed to put a real load on all the features of the vsrx and then move on to physical at our office. I may just reach out to our rep for a hardware trial of the srx300 as that is what we would deploy the most for a large number of our clients.
It is what it is as they say. Thank you for your help.