I'm trialling a vSRX installation in one of my Amazon VPC's.
I've followed the general vSRX setup guide and a few KB's to:
- Assign eth1 (public & private, untrust) and eth2 (private, trusted) to the instance
- Configure the interfaces on the appliance
- Create a virtual-router and adding these interfaces, next hop on the default route is the AWS router IP on eth1 (Private).
- Create a Dst. NAT rule to NAT port on the internal ge-0/0/0 IP and port 3389 to a Windows host
- Create a firewall rule to permit untrust to trust on port 3389
- Create a firewall to permit trust to untrust / any
I can't seem to get the NAT rule to work and have tried following a few articles to troubleshoot. Packet captures don't seem to be supported on the vSRX and when I try to run one, JWEB bugs out permanently.
**Note I added source NAT recently to NAT the private traffic from the trusted zone to the egress interface in case it's an issue with the return traffic from the Windows host - but still no success.