Smart questions
Smart answers
Smart people
INTELLIGENT WORK FORUMS
FOR COMPUTER PROFESSIONALS

Member Login

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips now!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!

Join Tek-Tips
*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

LINK TO THIS FORUM!

Add Stickiness To Your Site By Linking To This Professionally Managed Technical Forum.
Just copy and paste the
code below into your site.

Partner With Us!

"Best Of Breed" Forums Add Stickiness To Your Site
Partner Button
(Download This Button Today!)

Feedback

"...I have tons of books, have book marked tons of tutorials, which have helped, but this forum has answered those "impossible to find" solutions. I am thrilled with this site..."

Geography

Where in the world do Tek-Tips members come from?
GM2005 (ISP)
25 Oct 07 7:15
Hi

I have never used Netscreen before and have to migrate a netscreen firewall to a Cisco ASA. Can someone explain what VIP::1 is? In the policy rules there are a lot of entries statically mapped to VIP::1, and under advanced is the option to look in the address book for the destination. Where would that be then? I am looking everywhere and can see no address book, not any group, user or destination linked to VIP::1

Packet7 (IS/IT--Management)
25 Oct 07 18:58
Hi,

I would recommend taking a look at the config in a text editor.  You can download this from the WebUI or connect via the console/ssh.  Once you see the config, everything should fall into place.  The ScreenOS is not much different from Cisco IOS.

Regarding the VIP, it means "Virtual IP".  In ScreenOS it's used for many to one NAT.

Rgds,

John
GM2005 (ISP)
26 Oct 07 14:54
Hi Packet7. The config file is all set commands. It's made more difficult as i've never 'seen' the network it is going in to and it was installed by a third party who are not around to assist.

From what you wrote I guess it is an alias for a group of addresses. If that's the case i'm happy with that. Thanks for the explanation.
Packet7 (IS/IT--Management)
26 Oct 07 15:30
Hi,

Actually, it's a Virtual IP used to map a single IP to several other machines using specific ports.  If you like, you can post some of the config and I will take a look.  Please xxx out anything that is sensitive.  I hope this helps.

Rgds,

John
GM2005 (ISP)
27 Oct 07 15:22
I don't have it with me and i'm going to site Tuesday. What you've explained already is enough I reckon. A VIP is used for static nat translations as I understand it.

The bit that i'm stuck on is where under the menu the mapping is configured. I have taken the time to go through every menu, submenu item and can't find anywhere where the VIP is tied to an address or port. That is where i'm concerned I am misunderstanding it.

Packet7 (IS/IT--Management)
27 Oct 07 17:12
Hi,

I'm hoping this helps (see below).  Let me know.

ScreenOS WebUI:

1.  Select Network, Interfaces
2.  Click on the interface you want to apply to VIP to (e.g. Untrust or E3) and click Edit
3.  The default view is "Basic".  At the top of the page click "VIP".
4.  From this screen, you can setup the VIP, port and service.  
5.  Upon completion, you need to create a Policy (e.g. Untrust to Trust).  Click Policies, Untrust to Trust and click New.
6.  Select your source, destination (VIP), service, and action (permit).  Make sure the service used in the policy matches the service specified in the VIP.

Once this is done, you should be all set.  One thing to note is that a VIP is unidirectional and a MIP is bidirectional.  The inbound VIP traffic will translate accordingly.  However, the outbound traffic from the VIP server will use the NAT associated with the interface (e.g. Interface NAT).

I hope this helps.

Rgds,

John

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close