NetScreen
[Top] [All Lists]

[nn] Allowing ping to a DIP

To: nn@qorbit.net
Subject: [nn] Allowing ping to a DIP
From: Jason Parsons <jparsons-nn@saffron.net>
Date: Sun, 11 Mar 2007 19:45:08 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: ns-list2@consult.net
Delivered-to: nn@qorbit.net
List-archive: <http://www.qorbit.net/nn>
List-help: <mailto:nn-request@qorbit.net?subject=help>
List-id: "Netscreen mailing list for netscreen admins." <nn.qorbit.net>
List-post: <mailto:nn@qorbit.net>
List-subscribe: <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=subscribe>
List-unsubscribe: <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=unsubscribe>
Sender: nn-bounces@qorbit.net
User-agent: Mutt/1.5.11
We have a DIP set up as such:

  set interface "ethernet1/2" zone "Untrust"

  set interface ethernet1/2 ip x.x.x.1/24
  set interface ethernet1/2 route
  set interface ethernet1/2 manage ping

  set interface ethernet1/2 dip 18 x.x.x.3 x.x.x.3

We then have a policy allowing traffic outbound via this DIP:

  set policy id 30 from "Production" to "Untrust"  "10.0.0.0/24" "Any" "HTTP"
  nat src dip-id 18 permit 
  set policy id 30
  exit

This works perfectly for outbound traffic.  However, for troubleshooting
purposes, we would like the outside world to be able to ping the DIP (ie,
x.x.x.3).  Is there any easy (or hard) way to do this?  Turning on 'manage
ping' for the "parent" interface seems to have no impact on the DIPs.

Thank you. 
 - Jason Parsons


_______________________________________________
nn mailing list
nn@qorbit.net
http://qorbit.net/mailman/listinfo/nn

<Prev in Thread] Current Thread [Next in Thread>