Need help with Nating on a Juniper Netscreen 5gt please.
Posted on 2007-10-02
Ok the network admin has left the company and I am now here trying to figure out how to get all of this to work lol. here is the layout of our network. We currently have around 45 hospitals that connect into our data center. Our data center as a Cisco 3030 concentrator to host the VPN's and the hospitals all have a juniper netscreen 5gt onsite that the VPN goes into. Each hospital has a VPN that goes from their juniper to the concentrator. Any vendors that are trying to connect to the hospital come into the concentrator and we route them to the right VPN tunnel aka the hospitals VPN tunnel and then forward the traffic through that. As you know you can only have on IP subnet on the network so there is some NATing going on. From what I was told is that the junipers handle the Nating but the interfaces are not in nat mode. The only thing I can tell from the configuration of them is the ipsec VPN tunnel does a nat on it but some of the hospitals have multiple networks behind the trust interface. (all hospitals are setup in a untrust, trust interface mode.) from what I was told when asking about the NATS is that the nats are a one to one thing. So a 192.168.1.23 address would be a 192.168.111.23 address after the NAT. he has also made mention of using policy based NATing but I dont see any evidence of that but then again I have no idea what I am looking for lol. there are two hospitals I need help with that I know is doing nating. One vendor needs access to a network that is not even defined on the trust interface which I am assuming something beyond the juniper does the routing for that, but they need access to it and I know it is natted but is there a way to confirm the address it is suppose to be natting to.
The other hospital has a few things they need done, one is to give them the nat address for some IP addresses they have sent over. If it is one to one then that is easy but no where in the juniper can I find what network it is suppose to be natted for. I was reading up about DIPs to do natting but that is not how it has been done so there has to be another way he was doing it. I need help figuring out how he went about doing the natting for these two hospitals. I can send over a copy of the config file if needed just let me know what your email address is. for hippa reasons I dont want to post it on the site.
Also if anyone knows of a list of commands for the netscreen in the command line interface that would be great, all I can find on the internet is the unknown commands and what not but I need to know the known ones first lol. if anyone can help out that would be greatly appreciated.