What version of screenos you running bud? Am still looking for any ADSL gotchas, but all I can see at the mo is that is should just work, but if you dont have the option there ) ie its not listed, then its a bit odd.
I would try to active the interface to see if it makes a diff cos that may be stopping us here.
See the article below which gives a bit more confirmation that we should be able to get this done.
http://kb.juniper.net/KB55
Can a Virtual IP (VIP) use the same IP address as the untrusted interface?
Knowledge Base ID: KB5571
Synopsis:
Can a Virtual IP (VIP) use the same IP address as the untrusted interface? Which Firewalls support "VIP same as Untrust"?
Problem:
* Virtual IP Only have 1 Publicly available IP address
* Allow access to internal servers using the same IP address as the untrust
* Cannot set VIP as the same IP address as Untrust interface
* Which firewalls support 'VIP same as untrust'?
Solution:
ScreenOS 6.0 and below:
VIPs can only be defined in the Untrust zone.
VIP Same as Untrust IP feature is supported on the lower end platforms. These include the following:
* NetScreen-5
* NetScreen-5XP
* NetScreen-5XT
* NetScreen-5GT (including ADSL and WLAN versions)
* NetScreen-HSC
* NetScreen-25
* NetScreen-50
* SSG-5 (all variants)
* SSG-20
* SSG-140
* SSG-320M
* SSG-520 (and SSG-520M)
ScreenOS 6.1 and higher (applies to all models):
* You can configure the virtual IP (VIP) address as the same as the interface IP address on any device in any zone.
* You can configure the VIP and mapped IP (MIP) address on the same interface using the same IP address. This allows you to selectively redirect traffic for specific applications to designated servers.
* You can configure VIP, MIP, and dynamic IP (DIP) addresses in any combination on any interface.
New CLI command: set interface <interface-num> vip interface-ip <port-number> <service name> <IP address>
Refer to the following KB for the models that support the 'MIP same as untrust' feature:
KB11167 - MIP can use the same address as an interface in some models
Additional information:
KB14223 - Limitations to Services that Can Be Used for VIP Same as Untrust or VIP Same as Interface IP
Main Topics
Browse All Topics





by: deimarkPosted on 2009-08-06 at 01:20:24ID: 25031066
You are correct, the VIP needs to be defined on the untrust interface, ie the public side.
Is there any way you can enable the DSL interface at all just to see if the VIP option makes itself available and I will also have a wee look to see if there are any gotchas with ADSL and VIP