Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: public subnet routing woes - SRX320

$
0
0

So if the second subnet is routed to your first subnet interface, I think your best solution is to place this on another interface directly and have your tenant connect to that.

 

Internet ---- WAN ge-0/0/0 SRX *.*.131.198/30

   ge-0/0/4 (or availabe interace)  *.*.138.217/30 --- Tenant interface *.*.138.218/30  (tenant uses *.*.138.217 as default route

 

Place the ge-0/0/4 into the untrust zone

create an untrust to untrust allow all rule without any NAT

 

Proxy arp is only needed when you have a connected subnet at layer2.  The routed subnets that exist behind your SRX will not need proxy arp.


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>