Archived from groups: comp.security.firewalls (More info?)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Either set your untrusted interface to DHCP or input the static address that
you have from your ISP. If its a PPPoE connection then follow the procedure
to acquire your external IP address on the untrusted interface.
- -Scott
"Zodiac" <Nomail@internet.com> wrote in message
news:Xns94D3E467DA9FCNomailinternetcom@195.130.132.70...
>
>
> Hi all,
>
> I have a problem with a netscreen 5xp on which I would like to perform NAT
>
> Network looks like this
>
>
> Internet -- Router ISP -- untrusted Netscreen -- trusted netscreen -- Lan
>
> 10.0.0.1 10.0.0.2 192.162.0.1
>
>
> Now when a client form the inside goes out his internal adress is
> translated to 10.0.0.2 wich of course is wrong and the packet doesn't
> come back
>
> Can I make a setting so that it gets translated to a valid IP adres (Wich
i
> have)
>
>
> Thks
>
> Z
>
-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
Archived from groups: comp.security.firewalls (More info?)
No its a sDSL line... The ISP router is in our office but we don't have
control over it. So my untrusted IP has to be 10.0.0.2...
Z.
"SA" <localhost@null.xxx> wrote in news:%c%hc.6159$w96.834242@attbi_s54:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Either set your untrusted interface to DHCP or input the static
> address that you have from your ISP. If its a PPPoE connection then
> follow the procedure to acquire your external IP address on the
> untrusted interface.
>
> - -Scott
>
>
> "Zodiac" <Nomail@internet.com> wrote in message
> news:Xns94D3E467DA9FCNomailinternetcom@195.130.132.70...
>>
>>
>> Hi all,
>>
>> I have a problem with a netscreen 5xp on which I would like to
>> perform NAT
>>
>> Network looks like this
>>
>>
>> Internet -- Router ISP -- untrusted Netscreen -- trusted netscreen --
>> Lan
>>
>> 10.0.0.1 10.0.0.2 192.162.0.1
>>
>>
>> Now when a client form the inside goes out his internal adress is
>> translated to 10.0.0.2 wich of course is wrong and the packet
>> doesn't come back
>>
>> Can I make a setting so that it gets translated to a valid IP adres
>> (Wich
> i
>> have)
>>
>>
>> Thks
>>
>> Z
>>
> -----BEGIN PGP SIGNATURE-----
> Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
>
> iQA/AwUBQIh/oeAH+KdEQeVvEQJm4gCgrFqWMVI7gvEMTQyPA5TECB6G3nMAoMe6
> 9kqr1P3HUT/EALnHwuB+spYl
> =6t/D
> -----END PGP SIGNATURE-----
>
>
>
Archived from groups: comp.security.firewalls (More info?)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
That's fine. So, its like this...
LAN (192.168.0.x)->NS5XP (Trusted, 192.168.0.1)->NS5XP (Untrusted,
10.0.0.2)->Router (10.0.0.1)->Routable IP Address->Cloud
"Zodiac" <Nomail@internet.com> wrote in message
news:Xns94D4D535FC99ANomailinternetcom@195.130.132.70...
>
> No its a sDSL line... The ISP router is in our office but we don't have
> control over it. So my untrusted IP has to be 10.0.0.2...
>
> Z.
>
>
>
> "SA" <localhost@null.xxx> wrote in news:%c%hc.6159$w96.834242@attbi_s54:
>
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > Either set your untrusted interface to DHCP or input the static
> > address that you have from your ISP. If its a PPPoE connection then
> > follow the procedure to acquire your external IP address on the
> > untrusted interface.
> >
> > - -Scott
> >
> >
> > "Zodiac" <Nomail@internet.com> wrote in message
> > news:Xns94D3E467DA9FCNomailinternetcom@195.130.132.70...
> >>
> >>
> >> Hi all,
> >>
> >> I have a problem with a netscreen 5xp on which I would like to
> >> perform NAT
> >>
> >> Network looks like this
> >>
> >>
> >> Internet -- Router ISP -- untrusted Netscreen -- trusted netscreen --
> >> Lan
> >>
> >> 10.0.0.1 10.0.0.2 192.162.0.1
> >>
> >>
> >> Now when a client form the inside goes out his internal adress is
> >> translated to 10.0.0.2 wich of course is wrong and the packet
> >> doesn't come back
> >>
> >> Can I make a setting so that it gets translated to a valid IP adres
> >> (Wich
> > i
> >> have)
> >>
> >>
> >> Thks
> >>
> >> Z
> >>
> > -----BEGIN PGP SIGNATURE-----
> > Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
> >
> > iQA/AwUBQIh/oeAH+KdEQeVvEQJm4gCgrFqWMVI7gvEMTQyPA5TECB6G3nMAoMe6
> > 9kqr1P3HUT/EALnHwuB+spYl
> > =6t/D
> > -----END PGP SIGNATURE-----
> >
> >
> >
>
-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
Archived from groups: comp.security.firewalls (More info?)
Yes, that's the setup Exactlly... But now if a clients goes out to the
internet thet translated NAT address is 10.0.0.2 wich of course is the
wrong one..
Do you have any idea how to fix this?
rgds
Z.
"SA" <localhost@null.xxx> wrote in news:4Mhic.13773$_L6.1049392
@attbi_s53:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> That's fine. So, its like this...
> LAN (192.168.0.x)->NS5XP (Trusted, 192.168.0.1)->NS5XP (Untrusted,
> 10.0.0.2)->Router (10.0.0.1)->Routable IP Address->Cloud
>
>
>
> "Zodiac" <Nomail@internet.com> wrote in message
> news:Xns94D4D535FC99ANomailinternetcom@195.130.132.70...
>>
>> No its a sDSL line... The ISP router is in our office but we don't
have
>> control over it. So my untrusted IP has to be 10.0.0.2...
>>
>> Z.
>>
>>
>>
>> "SA" <localhost@null.xxx> wrote in news:%c%hc.6159$w96.834242
@attbi_s54:
>>
>> > -----BEGIN PGP SIGNED MESSAGE-----
>> > Hash: SHA1
>> >
>> > Either set your untrusted interface to DHCP or input the static
>> > address that you have from your ISP. If its a PPPoE connection
then
>> > follow the procedure to acquire your external IP address on the
>> > untrusted interface.
>> >
>> > - -Scott
>> >
>> >
>> > "Zodiac" <Nomail@internet.com> wrote in message
>> > news:Xns94D3E467DA9FCNomailinternetcom@195.130.132.70...
>> >>
>> >>
>> >> Hi all,
>> >>
>> >> I have a problem with a netscreen 5xp on which I would like to
>> >> perform NAT
>> >>
>> >> Network looks like this
>> >>
>> >>
>> >> Internet -- Router ISP -- untrusted Netscreen -- trusted netscreen
--
>> >> Lan
>> >>
>> >> 10.0.0.1 10.0.0.2 192.162.0.1
>> >>
>> >>
>> >> Now when a client form the inside goes out his internal adress is
>> >> translated to 10.0.0.2 wich of course is wrong and the packet
>> >> doesn't come back
>> >>
>> >> Can I make a setting so that it gets translated to a valid IP
adres
>> >> (Wich
>> > i
>> >> have)
>> >>
>> >>
>> >> Thks
>> >>
>> >> Z
>> >>
>> > -----BEGIN PGP SIGNATURE-----
>> > Version: PGPfreeware 7.0.3 for non-commercial use
<http://www.pgp.com>
>> >
>> > iQA/AwUBQIh/oeAH+KdEQeVvEQJm4gCgrFqWMVI7gvEMTQyPA5TECB6G3nMAoMe6
>> > 9kqr1P3HUT/EALnHwuB+spYl
>> > =6t/D
>> > -----END PGP SIGNATURE-----
>> >
>> >
>> >
>>
> -----BEGIN PGP SIGNATURE-----
> Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
>
> iQA/AwUBQImoXeAH+KdEQeVvEQJpuACfYVugCjpKXAbhrtEVCI0zjvgCy4oAnjYh
> 7SJQ7+KyRBad7nRUrTMoZwHO
> =wjYS
> -----END PGP SIGNATURE-----
>
>
Archived from groups: comp.security.firewalls (More info?)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Is your gateway setup on your NS5XP Untrusted side? Should be pointing to
your router 10.0.0.1
"Zodiac" <Nomail@internet.com> wrote in message
news:Xns94D5A052CE59ENomailinternetcom@195.130.132.70...
> Yes, that's the setup Exactlly... But now if a clients goes out to the
> internet thet translated NAT address is 10.0.0.2 wich of course is the
> wrong one..
>
> Do you have any idea how to fix this?
>
> rgds
>
> Z.
>
>
>
> "SA" <localhost@null.xxx> wrote in news:4Mhic.13773$_L6.1049392
> @attbi_s53:
>
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > That's fine. So, its like this...
> > LAN (192.168.0.x)->NS5XP (Trusted, 192.168.0.1)->NS5XP (Untrusted,
> > 10.0.0.2)->Router (10.0.0.1)->Routable IP Address->Cloud
> >
> >
> >
> > "Zodiac" <Nomail@internet.com> wrote in message
> > news:Xns94D4D535FC99ANomailinternetcom@195.130.132.70...
> >>
> >> No its a sDSL line... The ISP router is in our office but we don't
> have
> >> control over it. So my untrusted IP has to be 10.0.0.2...
> >>
> >> Z.
> >>
> >>
> >>
> >> "SA" <localhost@null.xxx> wrote in news:%c%hc.6159$w96.834242
> @attbi_s54:
> >>
> >> > -----BEGIN PGP SIGNED MESSAGE-----
> >> > Hash: SHA1
> >> >
> >> > Either set your untrusted interface to DHCP or input the static
> >> > address that you have from your ISP. If its a PPPoE connection
> then
> >> > follow the procedure to acquire your external IP address on the
> >> > untrusted interface.
> >> >
> >> > - -Scott
> >> >
> >> >
> >> > "Zodiac" <Nomail@internet.com> wrote in message
> >> > news:Xns94D3E467DA9FCNomailinternetcom@195.130.132.70...
> >> >>
> >> >>
> >> >> Hi all,
> >> >>
> >> >> I have a problem with a netscreen 5xp on which I would like to
> >> >> perform NAT
> >> >>
> >> >> Network looks like this
> >> >>
> >> >>
> >> >> Internet -- Router ISP -- untrusted Netscreen -- trusted netscreen
> --
> >> >> Lan
> >> >>
> >> >> 10.0.0.1 10.0.0.2 192.162.0.1
> >> >>
> >> >>
> >> >> Now when a client form the inside goes out his internal adress is
> >> >> translated to 10.0.0.2 wich of course is wrong and the packet
> >> >> doesn't come back
> >> >>
> >> >> Can I make a setting so that it gets translated to a valid IP
> adres
> >> >> (Wich
> >> > i
> >> >> have)
> >> >>
> >> >>
> >> >> Thks
> >> >>
> >> >> Z
> >> >>
> >> > -----BEGIN PGP SIGNATURE-----
> >> > Version: PGPfreeware 7.0.3 for non-commercial use
> <http://www.pgp.com>
> >> >
> >> > iQA/AwUBQIh/oeAH+KdEQeVvEQJm4gCgrFqWMVI7gvEMTQyPA5TECB6G3nMAoMe6
> >> > 9kqr1P3HUT/EALnHwuB+spYl
> >> > =6t/D
> >> > -----END PGP SIGNATURE-----
> >> >
> >> >
> >> >
> >>
> > -----BEGIN PGP SIGNATURE-----
> > Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
> >
> > iQA/AwUBQImoXeAH+KdEQeVvEQJpuACfYVugCjpKXAbhrtEVCI0zjvgCy4oAnjYh
> > 7SJQ7+KyRBad7nRUrTMoZwHO
> > =wjYS
> > -----END PGP SIGNATURE-----
> >
> >
>
-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
Archived from groups: comp.security.firewalls (More info?)
Yep the gateway is ok.. when I create a MIP for an internal server on an
external address is working ok... But this off course is no option for
all my workstations..
rgds,
Z.
"SA" <localhost@null.xxx> wrote in
news:jlYic.35127$_L6.2009709@attbi_s53:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Is your gateway setup on your NS5XP Untrusted side? Should be
> pointing to your router 10.0.0.1
>
>
> "Zodiac" <Nomail@internet.com> wrote in message
> news:Xns94D5A052CE59ENomailinternetcom@195.130.132.70...
>> Yes, that's the setup Exactlly... But now if a clients goes out to
>> the internet thet translated NAT address is 10.0.0.2 wich of course
>> is the wrong one..
>>
>> Do you have any idea how to fix this?
>>
>> rgds
>>
>> Z.
>>
>>
>>
>> "SA" <localhost@null.xxx> wrote in news:4Mhic.13773$_L6.1049392
>> @attbi_s53:
>>
>> > -----BEGIN PGP SIGNED MESSAGE-----
>> > Hash: SHA1
>> >
>> > That's fine. So, its like this...
>> > LAN (192.168.0.x)->NS5XP (Trusted, 192.168.0.1)->NS5XP (Untrusted,
>> > 10.0.0.2)->Router (10.0.0.1)->Routable IP Address->Cloud
>> >
>> >
>> >
>> > "Zodiac" <Nomail@internet.com> wrote in message
>> > news:Xns94D4D535FC99ANomailinternetcom@195.130.132.70...
>> >>
>> >> No its a sDSL line... The ISP router is in our office but we don't
>> have
>> >> control over it. So my untrusted IP has to be 10.0.0.2...
>> >>
>> >> Z.
>> >>
>> >>
>> >>
>> >> "SA" <localhost@null.xxx> wrote in news:%c%hc.6159$w96.834242
>> @attbi_s54:
>> >>
>> >> > -----BEGIN PGP SIGNED MESSAGE-----
>> >> > Hash: SHA1
>> >> >
>> >> > Either set your untrusted interface to DHCP or input the static
>> >> > address that you have from your ISP. If its a PPPoE connection
>> then
>> >> > follow the procedure to acquire your external IP address on the
>> >> > untrusted interface.
>> >> >
>> >> > - -Scott
>> >> >
>> >> >
>> >> > "Zodiac" <Nomail@internet.com> wrote in message
>> >> > news:Xns94D3E467DA9FCNomailinternetcom@195.130.132.70...
>> >> >>
>> >> >>
>> >> >> Hi all,
>> >> >>
>> >> >> I have a problem with a netscreen 5xp on which I would like to
>> >> >> perform NAT
>> >> >>
>> >> >> Network looks like this
>> >> >>
>> >> >>
>> >> >> Internet -- Router ISP -- untrusted Netscreen -- trusted
>> >> >> netscreen
>> --
>> >> >> Lan
>> >> >>
>> >> >> 10.0.0.1 10.0.0.2
>> >> >> 192.162.0.1
>> >> >>
>> >> >>
>> >> >> Now when a client form the inside goes out his internal adress
>> >> >> is translated to 10.0.0.2 wich of course is wrong and the
>> >> >> packet doesn't come back
>> >> >>
>> >> >> Can I make a setting so that it gets translated to a valid IP
>> adres
>> >> >> (Wich
>> >> > i
>> >> >> have)
>> >> >>
>> >> >>
>> >> >> Thks
>> >> >>
>> >> >> Z
>> >> >>
>> >> > -----BEGIN PGP SIGNATURE-----
>> >> > Version: PGPfreeware 7.0.3 for non-commercial use
>> <http://www.pgp.com>
>> >> >
>> >> > iQA/AwUBQIh/oeAH+KdEQeVvEQJm4gCgrFqWMVI7gvEMTQyPA5TECB6G3nMAoMe6
>> >> > 9kqr1P3HUT/EALnHwuB+spYl
>> >> > =6t/D
>> >> > -----END PGP SIGNATURE-----
>> >> >
>> >> >
>> >> >
>> >>
>> > -----BEGIN PGP SIGNATURE-----
>> > Version: PGPfreeware 7.0.3 for non-commercial use
>> > <http://www.pgp.com>
>> >
>> > iQA/AwUBQImoXeAH+KdEQeVvEQJpuACfYVugCjpKXAbhrtEVCI0zjvgCy4oAnjYh
>> > 7SJQ7+KyRBad7nRUrTMoZwHO
>> > =wjYS
>> > -----END PGP SIGNATURE-----
>> >
>> >
>>
> -----BEGIN PGP SIGNATURE-----
> Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
>
> iQA/AwUBQIxRyOAH+KdEQeVvEQKiRQCgt1U6Hm9zGYnVCIUUjryDpLxavGwAn049
> E2xeqt7XP50FCBQrqQ2Cty/9
> =X4qN
> -----END PGP SIGNATURE-----
>
>
>
Archived from groups: comp.security.firewalls (More info?)
So, when you do a MIP for like 192.168.0.254->10.0.0.254 it works fine but
when a DHCP address from the 192.168.0.x tries to get out they don't work.
Check your subnet mask and DHCP Server settings on your NS5XP (Trusted).
"Zodiac" <Nomail@internet.com> wrote in message
news:Xns94D7D5639DF9ENomailinternetcom@195.130.132.70...
> Yep the gateway is ok.. when I create a MIP for an internal server on an
> external address is working ok... But this off course is no option for
> all my workstations..
>
> rgds,
> Z.
>
>
> "SA" <localhost@null.xxx> wrote in
> news:jlYic.35127$_L6.2009709@attbi_s53:
>
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA1
> >
> > Is your gateway setup on your NS5XP Untrusted side? Should be
> > pointing to your router 10.0.0.1
> >
> >
> > "Zodiac" <Nomail@internet.com> wrote in message
> > news:Xns94D5A052CE59ENomailinternetcom@195.130.132.70...
> >> Yes, that's the setup Exactlly... But now if a clients goes out to
> >> the internet thet translated NAT address is 10.0.0.2 wich of course
> >> is the wrong one..
> >>
> >> Do you have any idea how to fix this?
> >>
> >> rgds
> >>
> >> Z.
> >>
> >>
> >>
> >> "SA" <localhost@null.xxx> wrote in news:4Mhic.13773$_L6.1049392
> >> @attbi_s53:
> >>
> >> > -----BEGIN PGP SIGNED MESSAGE-----
> >> > Hash: SHA1
> >> >
> >> > That's fine. So, its like this...
> >> > LAN (192.168.0.x)->NS5XP (Trusted, 192.168.0.1)->NS5XP (Untrusted,
> >> > 10.0.0.2)->Router (10.0.0.1)->Routable IP Address->Cloud
> >> >
> >> >
> >> >
> >> > "Zodiac" <Nomail@internet.com> wrote in message
> >> > news:Xns94D4D535FC99ANomailinternetcom@195.130.132.70...
> >> >>
> >> >> No its a sDSL line... The ISP router is in our office but we don't
> >> have
> >> >> control over it. So my untrusted IP has to be 10.0.0.2...
> >> >>
> >> >> Z.
> >> >>
> >> >>
> >> >>
> >> >> "SA" <localhost@null.xxx> wrote in news:%c%hc.6159$w96.834242
> >> @attbi_s54:
> >> >>
> >> >> > -----BEGIN PGP SIGNED MESSAGE-----
> >> >> > Hash: SHA1
> >> >> >
> >> >> > Either set your untrusted interface to DHCP or input the static
> >> >> > address that you have from your ISP. If its a PPPoE connection
> >> then
> >> >> > follow the procedure to acquire your external IP address on the
> >> >> > untrusted interface.
> >> >> >
> >> >> > - -Scott
> >> >> >
> >> >> >
> >> >> > "Zodiac" <Nomail@internet.com> wrote in message
> >> >> > news:Xns94D3E467DA9FCNomailinternetcom@195.130.132.70...
> >> >> >>
> >> >> >>
> >> >> >> Hi all,
> >> >> >>
> >> >> >> I have a problem with a netscreen 5xp on which I would like to
> >> >> >> perform NAT
> >> >> >>
> >> >> >> Network looks like this
> >> >> >>
> >> >> >>
> >> >> >> Internet -- Router ISP -- untrusted Netscreen -- trusted
> >> >> >> netscreen
> >> --
> >> >> >> Lan
> >> >> >>
> >> >> >> 10.0.0.1 10.0.0.2
> >> >> >> 192.162.0.1
> >> >> >>
> >> >> >>
> >> >> >> Now when a client form the inside goes out his internal adress
> >> >> >> is translated to 10.0.0.2 wich of course is wrong and the
> >> >> >> packet doesn't come back
> >> >> >>
> >> >> >> Can I make a setting so that it gets translated to a valid IP
> >> adres
> >> >> >> (Wich
> >> >> > i
> >> >> >> have)
> >> >> >>
> >> >> >>
> >> >> >> Thks
> >> >> >>
> >> >> >> Z
> >> >> >>
> >> >> > -----BEGIN PGP SIGNATURE-----
> >> >> > Version: PGPfreeware 7.0.3 for non-commercial use
> >> <http://www.pgp.com>
> >> >> >
> >> >> > iQA/AwUBQIh/oeAH+KdEQeVvEQJm4gCgrFqWMVI7gvEMTQyPA5TECB6G3nMAoMe6
> >> >> > 9kqr1P3HUT/EALnHwuB+spYl
> >> >> > =6t/D
> >> >> > -----END PGP SIGNATURE-----
> >> >> >
> >> >> >
> >> >> >
> >> >>
> >> > -----BEGIN PGP SIGNATURE-----
> >> > Version: PGPfreeware 7.0.3 for non-commercial use
> >> > <http://www.pgp.com>
> >> >
> >> > iQA/AwUBQImoXeAH+KdEQeVvEQJpuACfYVugCjpKXAbhrtEVCI0zjvgCy4oAnjYh
> >> > 7SJQ7+KyRBad7nRUrTMoZwHO
> >> > =wjYS
> >> > -----END PGP SIGNATURE-----
> >> >
> >> >
> >>
> > -----BEGIN PGP SIGNATURE-----
> > Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>
> >
> > iQA/AwUBQIxRyOAH+KdEQeVvEQKiRQCgt1U6Hm9zGYnVCIUUjryDpLxavGwAn049
> > E2xeqt7XP50FCBQrqQ2Cty/9
> > =X4qN
> > -----END PGP SIGNATURE-----
> >
> >
> >
>
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.