Avatar of tsaico
tsaico
Flag for Afghanistan asked on

juniper firewall with two separate subnets for public IPs giving me hassle

I have a juniper ssg5 that is giving me some headache.  I was given two public facing blocks of 6 IPs.  
example
1.1.1.1\29
and
2.2.2.1\29

Which I have entered a single IP on the windows IIS server behind it as a public facing IP, forwarded 443 and 80, no problems (this is one from the 1.1.1.1 address).

The second block I put in as virtual IPs on the public NIC on the windows box, and added the first address as a secondary gateway, the ISP instructed me that 2.2.2.1 is my gateway and 2-6 are my usable).  In the firewall, I added the block as a network object and as secondary IP on the trusted connection with he original IP block that is working fine. Then forwarded forwarded 80 and 443.  The last IP, 2.2.2.6 doesn't respond to a ping at all, but 1-5 do. I ran a tracert from my own IP, and it stops right before my firewall, whereas the others get to my firewall and then to my IP.  Then only 2.2.2.4 responds to 443 requests, the others (2, 3, 5, 6) don't respond at all and look like they are closed to 443 from the outside world.  Any ideas?

I don't think it is my firewall setup since it can ping all my addresses, but then th elast usable doesn't work at all.  Then I don't know why it would only work for just one IP in the new block, and half way for the others in IIS.

This is on a standalone IIS box running current updates on Windows 2008 R2.
Internet ProtocolsMicrosoft IIS Web ServerWindows Server 2008

Avatar of undefined
Last Comment
tsaico

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
tsaico

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy