Re: [j-nsp] ns-50 NAT problem

2007-07-17 Thread Joe Horton
PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gabriel Sent: Tuesday, July 17, 2007 7:23 AM To: juniper-nsp@puck.nether.net Subject: [j-nsp] ns-50 NAT problem Hi, I am having problems configuring a nat on a netscreen 50. Basically

Re: [j-nsp] ns-50 NAT problem

2007-07-17 Thread Andrew Mulheirn
Yeah - thanks Joe. Things have obviously moved on since my last experience with this. Apologies to Gabriel for being out of date... Andrew >[mailto:[EMAIL PROTECTED] On Behalf Of Joe Horton >Sent: Tuesday, July 17, 2007 3:36 PM >Glad to help. > This e-mail is private and may be confidential a

Re: [j-nsp] ns-50 NAT problem

2007-07-17 Thread Joe Horton
Glad to help. Joe Horton 972-663-3010 mailto://[EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gabriel Sent: Tuesday, July 17, 2007 9:26 AM To: juniper-nsp@puck.nether.net Subject: Re: [j-nsp] ns-50 NAT problem > > You

Re: [j-nsp] ns-50 NAT problem

2007-07-17 Thread Gabriel
> > You can do what you want by using "loopback groups" on the 50. > > You define the loopback interface, place the NAT information > you want to use > (MIP or DIP) on the loopback. Then tie the external interfaces to the > loopback via a loopback group. > > Joe > Omg It works! Thanks! Ga

Re: [j-nsp] ns-50 NAT problem

2007-07-17 Thread Andrew Mulheirn
Hi Gabriel, > So Basically you are saying the only way to have this work is to have a > second device do the nat? There is no other way arround right? I tried to make the NAT come from either a loopback or another sub-interface on the Netscreen, and (when I was using dynamic NAT) it always used t

Re: [j-nsp] ns-50 NAT problem

2007-07-17 Thread Gabriel
> > I tried to make the NAT come from either a loopback or another > sub-interface on the Netscreen, and (when I was using dynamic NAT) it > always used the egress interface. I couldn't make it do > anything else. > > I'm no expert on ScreenOS, but a colleague of mine who has worked with > the

Re: [j-nsp] ns-50 NAT problem

2007-07-17 Thread Gabriel
> Hi there, > > >From past experience, we've found it impossible to get the > Netscreen to > do this. It can't use anything other than a MIP or the > egress interface > of the box. I think is is an architectural thing - NAT is configured > around an interface in ScreenOS. > > In this respec

Re: [j-nsp] ns-50 NAT problem

2007-07-17 Thread Andrew Mulheirn
Hi there, >From past experience, we've found it impossible to get the Netscreen to do this. It can't use anything other than a MIP or the egress interface of the box. I think is is an architectural thing - NAT is configured around an interface in ScreenOS. In this respect it differs from a PIX,

[j-nsp] ns-50 NAT problem

2007-07-17 Thread Gabriel
Hi, I am having problems configuring a nat on a netscreen 50. Basically I have two interfaces facing the web with two different types of links and an internal interface facing the office. What I would like to do is have the NAT use a loopback IP on the netscreen as the translation IP...but for som