hi Tony, thanks for replying. The problem I have is that we use a Alcatel voip system and every handset needs to talk directly rather being proxy-ed....
So I have a SIP server and the voip handset on my side and a partner has a sip and handsets on there side. The "Recipe 8.2. Configure Hide NAT with VoIP" in the screenos cookbook works fine for trust to untrust, but the problem I have is the partner inititated voice traffic. The interface DIP wont work as it doesn't know what to NAT the incoming traffic to..... thanks for any help Ivan On Tue, Nov 17, 2009 at 5:33 PM, Tony Frank <[email protected]> wrote: > Hi Ivan, > >> Is there a way to do a ANY to a single IP that is not in the egress >> interface range? > > Have you looked at extended interface DIP? > See "Using DIP in a Different Subnet" in C&E volume 2, ScreenOS 6.1.0 and > probably later as well. > > You could also look at using a loopback interface and applying the MIP/DIP > there. > > Regards, > Tony > _______________________________________________ juniper-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/juniper-nsp

