Hello,
I have a requirement to pass a Public IP (site has a /28) directly to a device behind an MX250 (without NAT). My understanding is this is not possible under the current 14.X firmware release.
As an alternative solution, I'm considering connecting the WAN connection into a VLAN on the MS425, and then connect the WAN connection on the MX250 to that VLAN. The configuration of the MX250 WAN would not change, and the management IP on the MS425 would remain a private IP NATed by the MX250.
As long as the WAN connection is in a dedicated VLAN, are there any security concerns on this? As long as the MS425 doesn't have a layer 3 interface in the VLAN, I'm thinking this wouldn't really be a concern?
Is there anything I can do in the MS to verify only the permitted IP for that device is used? This will be managed by a 3rd party, so I am concerned about the possibility that a misconfiguration of their device (with wrong IP info, for example) could knock our device offline.
Any feedback or input is appreciated. Thanks