I have tried the policy config like you say but no luck. The loopback is in the untrust zone in untrust vr The testing zone is in VR-test. You suggest to put in the untrust vr a route 192.168.90.2 pointing to the VR-test?
-----Original Message----- From: Stefan Fouant [mailto:[EMAIL PROTECTED] Sent: Tuesday, September 02, 2008 5:06 PM To: SunnyDay Cc: Juniper-Nsp Subject: Re: [j-nsp] MIP issue On Wed, Jun 1, 2005 at 12:09 AM, SunnyDay <[EMAIL PROTECTED]> wrote: > The policy is from untrust to global with source any destination MIP > And no I dont have route.i don't understand the use of the route or what > route to configure. When the incoming ICMP echo-requests come into the device, does the device know how to reach the network where those requests are coming from so it can respond with the echo-replies? Have you tried changing the policy from 'untrust to global' to 'untrust to testing' zone... check and see if that makes a difference. -- Stefan Fouant Principal Network Engineer NeuStar, Inc. - http://www.neustar.biz GPG Key ID: 0xB5E3803D _______________________________________________ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp