interfaces { ge-0/0/0 { unit 0 { description Trust; family inet { address 10.110.1.1/22; } } } ge-0/0/1 { unit 0 { family inet { address 10.170.167.1/32; } } } ge-0/0/2 { speed 1g; link-mode full-duplex; unit 0 { description Untrust; family inet { address XXX.XXX.14.81/28; } } } ge-0/0/3 { speed 1g; link-mode full-duplex; unit 0 { family inet { address 10.19.250.2/28; } } } } routing-options { static { route 0.0.0.0/0 next-hop XXX.XXX.14.94; } auto-export { disable; } } nat { source { pool OutboundNATPool { address { XXX.XXX.14.82/32; } } rule-set OutboundNATfromTrust { from zone Trust; to zone Untrust; rule OutboundNATfromTrust { match { source-address 10.110.1.1/22; destination-address 0.0.0.0/0; } then { source-nat { pool { OutboundNATPool; } } } } } rule-set source-nat-1 { from zone AMAG; to zone Untrust; rule matchAny { match { source-address 0.0.0.0/0; destination-address 0.0.0.0/0; } then { source-nat { interface; } } } } } static { rule-set static-nat-Trust { from zone Trust; rule matchMIP82 { match { destination-address XXX.XXX.14.82/32; } then { static-nat { prefix { 10.110.0.1/32; } } } } } rule-set static-nat-Untrust { from zone Untrust; rule matchMIP83 { match { destination-address XXX.XXX.14.83/32; } then { static-nat { prefix { 10.110.1.21/32; } } } } rule matchMIP84 { match { destination-address XXX.XXX.14.84/32; } then { static-nat { prefix { 10.110.1.24/32; } } } } rule matchMIP85 { match { destination-address XXX.XXX.14.85/32; } then { static-nat { prefix { 10.110.1.28/32; } } } } rule matchMIP86 { match { destination-address XXX.XXX.14.86/32; } then { static-nat { prefix { 10.110.1.27/32; } } } } rule matchMIP87 { match { destination-address XXX.XXX.14.87/32; } then { static-nat { prefix { 10.110.0.31/32; } } } } rule matchMIP88 { match { destination-address XXX.XXX.14.88/32; } then { static-nat { prefix { 10.110.0.37/32; } } } } rule matchMIP89 { match { destination-address XXX.XXX.14.89/32; } then { static-nat { prefix { 10.110.0.50/32; } } } } } } proxy-arp { interface ge-0/0/2.0 { address { XXX.XXX.14.82/32; XXX.XXX.14.83/32; XXX.XXX.14.84/32; XXX.XXX.14.85/32; XXX.XXX.14.86/32; XXX.XXX.14.87/32; XXX.XXX.14.88/32; XXX.XXX.14.89/32; } } interface ge-0/0/0.0 { address { 10.110.10.3/32; } } } } zones { security-zone Trust { tcp-rst; address-book { address MIPXXX.XXX.14.82 XXX.XXX.14.82/32; address MIPXXX.XXX.14.83 XXX.XXX.14.83/32; address MIPXXX.XXX.14.84 XXX.XXX.14.84/32; address MIPXXX.XXX.14.85 XXX.XXX.14.85/32; address MIPXXX.XXX.14.86 XXX.XXX.14.86/32; address MIPXXX.XXX.14.87 XXX.XXX.14.87/32; address MIPXXX.XXX.14.88 XXX.XXX.14.88/32; address MIPXXX.XXX.14.89 XXX.XXX.14.89/32; address 10.110.0.0/16 10.110.0.0/16; address 10.110.0.0/22 10.110.0.0/22; address 10.110.0.1/32 10.110.0.1/32; address 10.110.0.30/32 10.110.0.30/32; address 10.110.0.31/32 10.110.0.31/32; address 10.110.0.50/32 10.110.0.50/32; address 10.110.1.176/32 10.110.1.176/32; address 10.110.1.21/32 10.110.1.21/32; address 10.110.10.3/32 10.110.10.3/32; address 10.110.3.101/32 10.110.3.101/32; address 10.110.3.102/32 10.110.3.102/32; address 10.110.3.103/32 10.110.3.103/32; address 10.110.3.106/32 10.110.3.106/32; address 10.110.3.107/32 10.110.3.107/32; address 10.110.3.108/32 10.110.3.108/32; address 10.110.3.55/32 10.110.3.55/32; address 10.110.3.74/32 10.110.3.74/32; address 192.168.0.0/16 192.168.0.0/16; address 192.168.1.255/24 192.168.1.255/32; address 192.168.255.255/16 192.168.255.255/32; } host-inbound-traffic { system-services { http; https; ping; ssh; telnet; } } interfaces { ge-0/0/0.0; } } security-zone Untrust { address-book { address MIPXXX.XXX.14.82 XXX.XXX.14.82/32; address MIPXXX.XXX.14.83 XXX.XXX.14.83/32; address MIPXXX.XXX.14.84 XXX.XXX.14.84/32; address MIPXXX.XXX.14.85 XXX.XXX.14.85/32; address MIPXXX.XXX.14.86 XXX.XXX.14.86/32; address MIPXXX.XXX.14.87 XXX.XXX.14.87/32; address MIPXXX.XXX.14.88 XXX.XXX.14.88/32; address MIPXXX.XXX.14.89 XXX.XXX.14.89/32; address XXX.XXX.14.82/32 XXX.XXX.14.82/32; address XXX.XXX.14.83/32 XXX.XXX.14.83/32; address XXX.XXX.14.84/32 XXX.XXX.14.84/32; address XXX.XXX.14.85/32 XXX.XXX.14.85/32; address XXX.XXX.14.86/32 XXX.XXX.14.86/32; address XXX.XXX.14.87/32 XXX.XXX.14.87/32; address XXX.XXX.14.88/32 XXX.XXX.14.88/32; address XXX.XXX.14.89/32 XXX.XXX.14.89/32; } } screen Untrust_screen; interfaces { ge-0/0/2.0 { host-inbound-traffic { system-services { ping; } } } } }