Link to home
Start Free TrialLog in
Avatar of MattToner
MattTonerFlag for United Kingdom of Great Britain and Northern Ireland

asked on

Range Port Forwarding on Juniper SSG5

Hi,

I'm trying to open ports 10000-20000 on a Juniper SSG 5.

I know how to do it for individual ports via VIP but is there a way to do more ports in one go?

Thanks
Avatar of Qlemo
Qlemo
Flag of Germany image

Just define a custom service using the port range. Then add that service in the VIP definition, and provide the first (!) port to map the VIP to (10000).
The according policy for that VIP will automatically allow traffic from those ports, so nothing to do there, if you already have a policy for the VIP.
Avatar of MattToner

ASKER

I have tried that, but it hits a limit of 64 ports.
Possible. That's the way VIP works, it is not intended to have such a wide-spread port range, and unless you want to break it down to 64 ports packages, there is no way around.

You should consider using a MIP instead - if you've got more than one public IP, that is.

Or maybe you should explain why you would need to do that - there might be better options.
its due to Voice Traffic, (RTP)

I will have a play with MIP instead

Thank you.
ASKER CERTIFIED SOLUTION
Avatar of Qlemo
Qlemo
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
done using MIP and working fine now...

Thanks for your help.