Hello,
First of all I wanted to confirm if I have understood the problem correctly which is as follows:-
- You have configured multiple IP addresses on your ge-0/0/0 interface so that it does proxy arp for it and users from the external side of the SRX can access the resources which are being NATd using these IP addresses.
- The external users are able to access resources using these IP addresses but when you try to reach the same IP addreses from your LAN / DMZ zone, it does not work.
First of all could you share the confoguration of how you are acheiving the proxy-arp . I need to check if you have configured multiple IP addresses on the interface itself or you have configured proxy-arp under the heirarchy edit security nat proxy-arp.
Also share the complete configuration of one server which you are trying to NAT on SRX using one of these IP addresses and you are failing to access it from behind LAN/DMZ zone but are able to access it from external zone users.
IMO if i am correct with my understanding of the problem then you will need the configuration as in the below KB article:-
https://kb.juniper.net/InfoCenter/index?page=content&id=KB17448&smlogin=true&actp=search
Thanks,
Pulkit Bhandari
Please mark my response as Solution Accepted if it Helps, Kudos are Appreciated too.