DIFFERENCE BETWEEN MIP,VIP AND DIP IN JUNIPER

Rashmi Bhardwaj | Blog,BUZZ,Routing & Switching
Advertisements

difference-between-mipvip-and-dip-in-juniper

 

Juniper ScreenOS platform supports Source NAT as well as Destination NAT and hence utilizes following terminologies – MIP , VIP and DIP.

The abbreviation for each term is –

  • Mapped IP (MIP)
  • Virtual IP (VIP)
  • Dynamic IP (DIP)

An MIP maps one external IP address to one internal IP address and does not alter the port information. A VIP maps one external IP address and one external port to a multiple number of possible IP addresses and ports. It can also translate external port to same or different internal port. DIP can enable policy-based NAT, and NAT, before VPN encapsulation; in which overlapping private IP addresses exist in a VPN network. Notable is that VIP and DIP is unidirectional whereas MIP is bidirectional.

Advertisements

Below comparison table will differentiate between MIP,VIP and DIP terms used in ScreenOS –

PARAMETER

MIP

VIP

DIP

PhilosophyA one-to-one mapping of one address to another.                                                                                                                                                                                                                  aA virtual IP (VIP) address maps traffic received at one IP address to another address based on the destination port number in the TCP or UDP protocol                                          sA dynamic IP (DIP) address pool is a range of IP addresses from which the device can dynamically take addresses to use when performing NAT on the source IP address of outgoing or incoming IP packets.
NAT TypeDestination NAT and Source NATDestination NATSource NAT
UsageStatic NAT to/from ServersOutgoing NAT instead of using egress Interface IPPort forwarding to Servers
Port usageNoYesYes
Mapping TypeOne-to-OneOne-to-ManyOne-to-Many and Many-to-One
Flow DirectionBidirectional.Traffic can be initiated from inside source or Outside SourceUnidirectional.Traffic can be initiated from inside source only for VIP to take effectUnidirectional.Traffic can be initiated from outside source only for DIP to take effect

                     

References –

https://kb.juniper.net/InfoCenter/index?page=content&id=KB6085

ABOUT THE AUTHOR


Leave a Comment

Your email address will not be published. Required fields are marked *

Shopping Cart