For When You Can't Have The Real Thing
[ start | index | login ]
start > Juniper > SRX100 > Multiple Networks on Trust Interface

Multiple Networks on Trust Interface

Created by dave. Last edited by dave, 10 years and 273 days ago. Viewed 3,268 times. #1
[edit] [rdf]
(2013 March 7)

If you have an interface defined with two IP addresses on it:

vlan {
        unit 0 {
            family inet {

...then you need an explicit trust-to-trust policy to permit traffic to flow between the two subnets:

from-zone trust to-zone trust {
            policy trust-to-trust {
                match {
                    source-address any;
                    destination-address any;
                    application any;
                then {

I didn't find this obvious.

no comments | post comment
This is a collection of techical information, much of it learned the hard way. Consider it a lab book or a /info directory. I doubt much of it will be of use to anyone else.

Useful: | Copyright 2000-2002 Matthias L. Jugel and Stephan J. Schmidt