Netscreen port forwarding from ISP-assigned IP address

Hi,

I have a NetScreen 204 firewall which handles the connection to Internet usingPPPoE. What I want to do seems to be really straitghtforward - I have done it many times using Unix -, but I didn't succeed with ScreenOS through the many attemps I have made so far : I want to forward all connections arriving on, say, port 80 to a server in my private network. This is basically called "port forwarding" in network computing language.

Connection sharing (source NAT) works well.

I have tested various policies, varying from/to zones (Untrust/Trust/Global), but I couldn't get what I want. While wandering across ScreenOS documentation, I found that VIP would surely achieve what I need to do, but unfortunately, I can't create a VIP using the IP address assigned to my external interface.

I hope to get a reply soon. I'm pretty sure I'm missing something obvious, but after (too) many tries, I really can't get what.

Thank you. Regards,

--=20 J=E9r=E9mie Le Hen snipped-for-privacy@gmail.com

Reply to
Jeremie Le Hen
Loading thread data ...

hi,

I googled some more for a while and found that this functionnality is called "VIP-same-as-untrust". Unfortunately, this feature is only provided on NetScreen 5 product family and all above products are considered as "corporate grade" which means, for NetScreen guys, that more than one IP address is available. Therefore this feature is merely hidden in NetScreen 204.

Hope this will helpsome lost soul in the future. Regards,

Reply to
Jeremie Le Hen

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.