Solved

1 to 1 mapped address for Juniper SSG320 / ScreenOS  how to

Posted on 2013-05-13
7
484 Views
Last Modified: 2014-10-21
Hi all,

I need to add an 1-to-1 mapped IP on a juniper ScreenOS ssg320m. I'm not familiar with the screenos at all and never used one so if someone out there could help me that would be awesome as I'm the accidental administrator right now..


e 0/0 - trust - LAN subnet 192.168.1.0/24
e 0/1 - dmz - 10.0.0.0/24
e 0/2 - public IP1 (connects to cable modem) say 1.1.1.1
e 0/3 - unused -


I called our ISP and it seems that we have another public ip I can use that we are not using so far.. say 1.1.1.2
(but only one connection from the cable modem to the firewall?? How that will work?)

I have an internal host that I would like to map the new public ip address. Note that the host will not be connecting directly to the firewall due to distance but to a switch that the firewall's trust interface is connected to.

So question 1... how can I map host 192.168.1.100 to the 2nd public ip that we have 1.1.1.2 ?

Question 2... if we were to run a cable from that host directly to port 3 of the firewall, can that host be on a different subnet, like 192.168.6.100 ?







thank you,
0
Comment
Question by:bazingaa
7 Comments
 
LVL 18

Accepted Solution

by:
Sanga Collins earned 250 total points
ID: 39162419
To answer your questions:

1: http://kb.juniper.net/InfoCenter/index?page=content&id=KB4739
The above KB article describes how to create a 1to1 mapping. In juniper-speak it is called a MIP (mapped IP)

2: You can create a new subnet on the unused port on the juniper (example 192.168.6.1/24) and then put a server at 192.168.6.100 and have the MIP point to that server.

notes: MIP is one to one so you can only connect one server on your lan to one public IP.

Please post additional question or if you need more clarification.
Thanks
0
 

Author Comment

by:bazingaa
ID: 39162914
Thanks for the reply sangamc,

ok 1 question... if I can't connect that server directly to port s0/3 of the firewall but only to a switch down the path that connects to the trust interface of the ssg (e0/0), can I still do a different subnet than the one configured?
0
 
LVL 18

Expert Comment

by:Sanga Collins
ID: 39162993
As long as the SSG can route to that subnet, then you will be able to configure a MIP pointing to an IP address on it.

If you have CLI access to your device you can try to ping an ip on the alternate subnet. If you get a reply, you should be able to configure a MIP without any problems.
0
 
LVL 69

Assisted Solution

by:Qlemo
Qlemo earned 250 total points
ID: 39163116
In your interface list, go into the eth0/0 interface, and set "Secondary IP" to an IP in the 192.168.6.0/24 network. That should allow implicit routing to that network using that interface.
0
 
LVL 3

Expert Comment

by:Nasir-Siddique
ID: 39200311
Edit the interface 3 and add the IP 192.168.6.1 with proper subnet. Connect the switch to it and provide proper VLAN tagging to the Uplink Port of that switch.
Once you connect the server to the switch with the same subnet's IP that is 192.168.6.100....it should create a route in the routing table of the SSG, once any host in the interface and subnet is UP.
Create MIP as per the Knowledge Base, create the required policy with specific services to be allowed.
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question