Holy crap! I can't believe that worked! OK, so if you want to do a LAN to LAN hairpin you can leverage the 1:Many NAT feature to make this happen. To test this I have a Raspberry Pi behind an MX on VLAN 10 with an IP of 192.168.100.5. I then created the following 1:Many Nat rule under Security appliance > firewall: So then as a test I then SSH'd to the 1:Many IP, which "hairpins" me back to the same Raspberry PI. Very cool. I expect this would work the same for a 1:1 NAT as well. So while not quite a true hairpin, it does the exact same thing.
... View more