Solved

1 to 1 mapped address for Juniper SSG320 / ScreenOS  how to

Posted on 2013-05-13
7
486 Views
Last Modified: 2014-10-21
Hi all,

I need to add an 1-to-1 mapped IP on a juniper ScreenOS ssg320m. I'm not familiar with the screenos at all and never used one so if someone out there could help me that would be awesome as I'm the accidental administrator right now..


e 0/0 - trust - LAN subnet 192.168.1.0/24
e 0/1 - dmz - 10.0.0.0/24
e 0/2 - public IP1 (connects to cable modem) say 1.1.1.1
e 0/3 - unused -


I called our ISP and it seems that we have another public ip I can use that we are not using so far.. say 1.1.1.2
(but only one connection from the cable modem to the firewall?? How that will work?)

I have an internal host that I would like to map the new public ip address. Note that the host will not be connecting directly to the firewall due to distance but to a switch that the firewall's trust interface is connected to.

So question 1... how can I map host 192.168.1.100 to the 2nd public ip that we have 1.1.1.2 ?

Question 2... if we were to run a cable from that host directly to port 3 of the firewall, can that host be on a different subnet, like 192.168.6.100 ?







thank you,
0
Comment
Question by:bazingaa
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 18

Accepted Solution

by:
Sanga Collins earned 250 total points
ID: 39162419
To answer your questions:

1: http://kb.juniper.net/InfoCenter/index?page=content&id=KB4739
The above KB article describes how to create a 1to1 mapping. In juniper-speak it is called a MIP (mapped IP)

2: You can create a new subnet on the unused port on the juniper (example 192.168.6.1/24) and then put a server at 192.168.6.100 and have the MIP point to that server.

notes: MIP is one to one so you can only connect one server on your lan to one public IP.

Please post additional question or if you need more clarification.
Thanks
0
 

Author Comment

by:bazingaa
ID: 39162914
Thanks for the reply sangamc,

ok 1 question... if I can't connect that server directly to port s0/3 of the firewall but only to a switch down the path that connects to the trust interface of the ssg (e0/0), can I still do a different subnet than the one configured?
0
 
LVL 18

Expert Comment

by:Sanga Collins
ID: 39162993
As long as the SSG can route to that subnet, then you will be able to configure a MIP pointing to an IP address on it.

If you have CLI access to your device you can try to ping an ip on the alternate subnet. If you get a reply, you should be able to configure a MIP without any problems.
0
 
LVL 70

Assisted Solution

by:Qlemo
Qlemo earned 250 total points
ID: 39163116
In your interface list, go into the eth0/0 interface, and set "Secondary IP" to an IP in the 192.168.6.0/24 network. That should allow implicit routing to that network using that interface.
0
 
LVL 3

Expert Comment

by:Nasir-Siddique
ID: 39200311
Edit the interface 3 and add the IP 192.168.6.1 with proper subnet. Connect the switch to it and provide proper VLAN tagging to the Uplink Port of that switch.
Once you connect the server to the switch with the same subnet's IP that is 192.168.6.100....it should create a route in the routing table of the SSG, once any host in the interface and subnet is UP.
Create MIP as per the Knowledge Base, create the required policy with specific services to be allowed.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco To Cisco Trunk not working 2 41
Cisco Licensing for Wi Fi 4 77
Cisco Anyconnect on MS Surface 12 43
Unable to login to Cisco C800 Ver 15.3(3)M4 8 50
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question