Le 06/07/2012 3:56, Chris Hellberg a écrit :
The order is: screen options -> D-NAT -> route lookup -> policy -> S-NAT -> 
others.

/chris
---
This order implies that you must systematically use real IP addresses in your security policies, even if there is NAT involved; (this is a main difference with ScreenOS for those who are familiar with ScreenOS NAT).

_______________________________________________
juniper-nsp mailing list juniper-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp

Reply via email to