Stabbing myself in the eyes with a Juniper SSG-550

"Blake Pfankuch" <bpfankuch-iDUpQSA8o47qlBn2x/[email protected]>
Newsgroups gmane.org.operators.internet-access
Message-ID <[email protected]>
Right.  So im getting a serious headache here.  Working with a Juniper
SSG-550 firewall and a cisco 1700 on the outside.  What I am trying to
do is set up SNMP off the Cisco to a monitoring point inside the
firewall.  They have this firewall configured secure as hell and im
running into trouble running from Trust to Untrust and back on SNMP.

SNMP rule is configured to allow udp 1-65535 and tcp 161 to and from the
router.

Where I am running into issues is with a DIP on the firewall.  It is
pooling everything that is not on a MIP to the DIP to 63.229.***.162
however when I monitor the logs on rules, going out it works.  But when
it comes in, it doesn't even show up in the hit.  I can't seem to get it
to forward through the DIP.

Any Ideas?

Blake
-- 
Eat sushi frequently. - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.