netscreen@srx-240# show interfaces interface-range interfaces-trust { member ge-0/0/4; member ge-0/0/5; member ge-0/0/6; member ge-0/0/7; member ge-0/0/8; member ge-0/0/9; member ge-0/0/10; member ge-0/0/11; member ge-0/0/12; member ge-0/0/13; member ge-0/0/14; member ge-0/0/15; member ge-0/0/2; unit 0 { family ethernet-switching { vlan { members vlan-trust; } } } } ge-0/0/0 { unit 0 { family inet { address XX.XX.123.194/28 { primary; } } } } ge-0/0/1 { unit 0 { family inet; } } ge-0/0/3 { unit 0 { family inet; } } lo0 { unit 0 { family inet { address 127.0.0.1/32; } } } vlan { unit 0 { family inet { address 192.168.2.2/24; } } } NAT: netscreen@srx-240# show security nat source { rule-set trust-to-untrust { from zone trust; to zone untrust; rule source-nat-rule { match { source-address 0.0.0.0/0; } then { source-nat { interface; } } } } } static { rule-set st-mail-dns { from zone untrust; rule rule1 { match { destination-address XX.XX.123.195/32; } then { static-nat prefix 192.168.2.20/32; } } } } proxy-arp { interface ge-0/0/0.0 { address { XX.XX.123.195/32; } } } netscreen@srx-hqekb# show security policies from-zone trust to-zone untrust { policy any { match { source-address any; destination-address any; application any; } then { permit; } } } from-zone untrust to-zone trust { policy st-mail-dns { match { source-address any; destination-address mailsrv; application junos-icmp-ping; } then { permit; } } }