Posts Topics Forums Images
Search videos from message boards Videos Search messages from microblogs Microblogs Search messages from imdb.com Imdb Search messages from yuku.com Yuku Search messages from lefora.com (free forums) Lefora
My account: Login | Sign Up
Loading... 

Firewalls | Forum profile

Forum profile page for Firewalls on http://www.juniper.net. This report page is the aggregated overview from a single forum: Firewalls, located on the Message Board at http://www.juniper.net. This forum profile page summarizes the general forum statistics such as: Users Activity, Forum Activity, and Top Authors, which are reported in either a table or graph below for a given reporting time period. Additional forum profile information for "Firewalls" on the Message Board at http://www.juniper.net is also shown in the following ways:

1) Latest Active Threads
2) Hot Threads for Last Week

Warning: These statistics are generated using 'best efforts' and can experience delays and reporting errors at times. Please note that such statistics do not constitute a forum's popularity and/or exact posting volumes at any given reporting period.

Site: Forums - J-Net Community - Firewalls (site profile, domain info juniper.net)
Title: Firewalls
Url: http://forums.juniper.net/t5/Firewalls/bd-p/Fir...
Users activity: 18 post per thread
Forum activity: 71 active thread during last week
 

Posting activity on Firewalls:

  Week Month 3 Months
Threads: 71 233 750
Post: 104 418 1,337
 

Firewalls Posting activity graph:

Posts by:  day  week  month 

Top authors during last week:

Name
Posts
muttbarker
8
user's latest post:
DMZ Setup issues - J-Net Community
Published (2009-11-27 08:31:00)
OK - Dumb question time - did you configure the DMZ I/F to allow for ping?
alagarn
5
user's latest post:
Web Filtering URL Wildcard...
Published (2009-11-25 20:45:00)
Hi,   Am not bale to get that KB article 10888. Am attching the snapshot of the error am getting. Could you help me out.   Thnaks and regards, Narayanan
TSG
5
user's latest post:
DMZ Setup issues - J-Net Community
Published (2009-11-27 13:31:00)
Hi   No i haddnt enabled the Management option is that a requirment..?
SSHSSH
5
user's latest post:
DMZ Setup issues - J-Net Community
Published (2009-11-28 17:10:00)
yes ,  for ex to enable ping on that intarface : check managable box check ping
J_Vansen_S
4
user's latest post:
HA physical interface - J-Net...
Published (2009-11-26 17:55:00)
Thanks for your reply.   Ive read thru NetScreen OS manual, there seem to be a paragragh about HA Virtual Interface, that does not make use of the physical interface. Was wondering if anyone comes across HA Virtual Interface.    
amol_waghmare
4
user's latest post:
Fun with Dual VR'S! - J-Net...
Published (2009-11-27 00:46:00)
Now facing problem that if the untrust link goes down why the default route is not going   IPv4 Dest-Routes for <untrust-vr> (3 entries) -------------------------------------------------- ------------------------------------          ID          IP-Prefix      Interface         Gateway   P Pref    Mtr     Vsys --------------------------------------------------...
sangamc
3
user's latest post:
Upgrade from screenOS 4 to...
Published (2009-11-19 13:42:00)
never mind all i found the problem. needed to goto 5.0 first since the file structure changes.
ssg20
3
user's latest post:
SSG 20- Startup Problem - J-Net...
Published (2009-11-21 11:24:00)
hello Abhi,   for the first problem, you will need to check the default gateway for your ip address in the PC, if dynamic, configure it as static 192.168.1.33 255.255.255.0 192.168.1.1 >>>>>>Default gateway.  go to the web and enter this https:// 192.168.1.1 >>>>>> if you redirect http to https.   For the second problem I think it is a DNS Problem. try the...
Optimist
3
user's latest post:
SSG 20 Quick Questions. - J-Net...
Published (2009-11-20 07:10:00)
1- fine 2- you have to move the new policy before the deny policy. Policies will be searched in top-down order. 3- the ssg has a self signed certificate for https which is not trusted by your browser.It is ok if you tust it.     Otherwise you need to buy a certificate from a trust authority. 4- check the logging checkbox on every policy, where you want to log traffic 5- the default settings on the untrust zone are already set to harden the...
arizvi
3
user's latest post:
Dialup VPN and Windows 7 - J-Net...
Published (2009-11-22 12:09:00)
Hi,   Please use the following KB which will helps to create the Dial VPN by using L2Tp with IPsec tunnel. http://kb.juniper.net/KB10939  or http://kb.juniper.net/kb/documents/public/VPN/Scre enOS_Windows_L2TP_IPSec.pdf   Use the same configuration but please use certificate as mention in the above links , L2TP with IPsec tunnel using pre-share key will not work with Juniper firewall.   Thanks Atif
 

Latest active threads on Firewalls::

Forums - J-Net Community
Started 3 days, 3 hours ago (2009-11-27 08:31:00)  by muttbarker
OK - Dumb question time - did you configure the DMZ I/F to allow for ping?
Thread:  Show this thread (6 posts)   Thread info: DMZ Setup issues - J-Net Community Size: 83 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: DMZ Setup issues :: Firewalls :: Forums - J-Net Community"
Forums - J-Net Community
Started 6 days, 4 hours ago (2009-11-24 06:46:00)  by SSHSSH
yes , you are right in case of Dedicated management ports , you should give ecah of them a different ip
Thread:  Show this thread (4 posts)   Thread info: MGT interface - J-Net Community Size: 120 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: MGT interface :: Firewalls :: Forums - J-Net Community"
Forums - J-Net Community
Started 3 days, 4 hours ago (2009-11-27 07:08:00)  by mehdi
hi dkrut i have met the same situation, last mounth, i have  did that :  I have dowload the config files for the both devic, after that i have opned it with winmerge application for editing the files , i have replaced only  old  ip address to new ip address  for iterfaces untrust "IP ISP" and all mip and vip. and after that i  compared the old file and  a  new file with Winmerge application. ...
Thread:  Show this thread (2 posts)   Thread info: Best Practice for changing External IP address? - J-Net Community Size: 910 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: Best Practice for changing External IP address? :: Firewalls :: Forums - J-Net Community"
Forums - J-Net Community
Started 3 days, 5 hours ago (2009-11-27 06:22:00)  by Diggers
The major difference is that the SRX will run on JUNOS
Thread:  Show this thread (2 posts)   Thread info: SSG140 vs SRX 240 - J-Net Community Size: 63 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: SSG140 vs SRX 240 :: Firewalls :: Forums - J-Net Community"
Forums - J-Net Community
Started 3 months, 1 week ago (2009-08-19 17:44:00)  by firewall72
Hi, The only way I know to accomplish this is to move your egress interfaces to a single VR.  For example, E1 would be in the trust-vr, E3 and E4 would be in the untrust-vr.  You would then have a default route in the trust-vr that points to the untrust-vr and two default routes in the untrust-vr (via each ISP gateway).  I've configured equal metrics across ISP's using ECMP and unequal metrics...
Thread:  Show this thread (9 posts)   Thread info: Fun with Dual VR'S! - J-Net Community Size: 847 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: Fun with Dual VR'S! :: Firewalls :: Forums - J-Net Community"
Forums - J-Net Community
Started 3 days, 17 hours ago (2009-11-26 18:02:00)  by dkraut
SFTP - Filezilla
Thread:  Show this thread (2 posts)   Thread info: ftp over ssl - J-Net Community Size: 25 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: ftp over ssl :: Firewalls :: Forums - J-Net Community"
Forums - J-Net Community
Started 6 days, 4 hours ago (2009-11-24 06:57:00)  by yuvaraj
No, HA is working on L2, So Physical HA link is mandatory for High Availablity.   You need one physical interface atleast to send control messages and sync RTO/configurations.
Thread:  Show this thread (3 posts)   Thread info: HA physical interface - J-Net Community Size: 203 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: HA physical interface :: Firewalls :: Forums - J-Net Community"
Forums - J-Net Community
Started 1 week ago (2009-11-22 19:40:00)  by ITSupport
I am also new to Junipers but I have learnt something in last few months. In your situation the traffic is not going out from TRUST to UNTRUST. As you mentioned you must check your route and policy configuration. You must have proper route and policy as below:   ROUTE:   FROM ----- TRUST LAN ------TO ---- UNTRUST ------VIA GE-0/0/1   POLICY:   FROM ----- TRUST LAN TO UNTRUST --- ALLOW  ...
Thread:  Show this thread (3 posts)   Thread info: Problems trust to untrust - J-Net Community Size: 1,089 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: Problems trust to untrust :: Firewalls :: Forums - J-Net Community"
 

Hot threads for last week on Firewalls::

Firewalls
Started 5 days, 23 hours ago (2009-11-24 11:42:00)  by muttbarker
How did you create your whitelist URL's? Perhaps you have a problem with them. For example if you allow the following:   www.facebook.com and then you try and go to the French version fr-fr.facebook.com you will fail. You have to wildcard your entries IE - *.facebook.com
Thread:  Show this thread (7 posts)   Thread info: Web filtering issues with SSg20 - J-Net Community Size: 353 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: Web filtering issues with SSg20 :: Firewalls :: Forums - J-Net Community"
Firewalls
Started 1 week ago (2009-11-22 11:38:00)  by arizvi
Thread:  Show this thread (6 posts)   Thread info: Dialup VPN and Windows 7 - J-Net Community Size: 6 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: Dialup VPN and Windows 7 :: Firewalls :: Forums - J-Net Community"
Firewalls
Re: DMZ Setup issues - 6 new posts
Started 3 days, 3 hours ago (2009-11-27 08:31:00)  by muttbarker
OK - Dumb question time - did you configure the DMZ I/F to allow for ping?
Thread:  Show this thread (6 posts)   Thread info: DMZ Setup issues - J-Net Community Size: 83 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: DMZ Setup issues :: Firewalls :: Forums - J-Net Community"
Firewalls
Started 1 week ago (2009-11-22 14:50:00)  by contra
depending on your setup you could configure Bridge Groups   set interface bgroup0 zone "untrust"   set interface bgroup0 port ethernet0/1 set interface bgroup0 port ethernetx/x set interface bgroup0 port ethernetx/x set interface bgroup0 port ethernetx/x set interface bgroup0 port ethernetx/x  
Thread:  Show this thread (5 posts)   Thread info: True DMZ? Assigning Internet IP on the PC itself - J-Net Community Size: 379 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: True DMZ? Assigning Internet IP on the PC itself :: Firewalls :: Forums - J-Net Community"
Firewalls
Started 5 days, 23 hours ago (2009-11-24 11:47:00)  by muttbarker
At a high level you will need to do the following: 1- Create the NAT relationships - this is done on the outbound (untrusted) I/F. You have your choice between MIP, DIP and VIP entries. If you bring up the I/F you will see the options at the top of the page. Select one and then select the question mark in the upper right corner and you can get some nice help documentation on this.   2- You ...
Thread:  Show this thread (4 posts)   Thread info: Configure NAT rules on SSG55 - J-Net Community Size: 931 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: Configure NAT rules on SSG55 :: Firewalls :: Forums - J-Net Community"
Firewalls
Re: MGT interface - 4 new posts
Started 6 days, 4 hours ago (2009-11-24 06:46:00)  by SSHSSH
yes , you are right in case of Dedicated management ports , you should give ecah of them a different ip
Thread:  Show this thread (4 posts)   Thread info: MGT interface - J-Net Community Size: 120 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: MGT interface :: Firewalls :: Forums - J-Net Community"
Firewalls
Started 3 months, 1 week ago (2009-08-19 17:44:00)  by firewall72
Hi, The only way I know to accomplish this is to move your egress interfaces to a single VR.  For example, E1 would be in the trust-vr, E3 and E4 would be in the untrust-vr.  You would then have a default route in the trust-vr that points to the untrust-vr and two default routes in the untrust-vr (via each ISP gateway).  I've configured equal metrics across ISP's using ECMP and unequal metrics...
Thread:  Show this thread (9 posts)   Thread info: Fun with Dual VR'S! - J-Net Community Size: 847 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: Fun with Dual VR'S! :: Firewalls :: Forums - J-Net Community"
Firewalls
Started 1 week ago (2009-11-23 09:37:00)  by shadow
You need to make sure that your policy has the network address translation setup as well.     From the CLI   set policy from "DMZ" to "Untrust" "Any" "Any" "Any" nat src permit log save   From the Web Gui   Edit the rule you have already created, then click on advanced and make sure that source translation is checked with use egress interface IP.  Then click okay and give it a try. 
Thread:  Show this thread (3 posts)   Thread info: Netscreen ns25 DMZ internet access problems.... - J-Net Community Size: 473 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: Netscreen ns25 DMZ internet access problems.... :: Firewalls :: Forums - J-Net Community"
Firewalls
Started 2 weeks, 4 days ago (2009-11-12 06:52:00)  by muttbarker
Yes - I have setup W2K8 for Radius Auth - it is similiar to W2K3 but you have to configure the "NPS" Network Policy Server for your radius setup. This is comparable to the W2K3 setup you would do under Internet Authentication Services. Add "Network Policy and Access Services" to your DC and then configure network ports, clients and policies under Server Manager -> Roles -> Network Policy and ...
Thread:  Show this thread (10 posts)   Thread info: Netscreen and Windows 2008 - J-Net Community Size: 552 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: Netscreen and Windows 2008 :: Firewalls :: Forums - J-Net Community"
Firewalls
Started 6 days, 4 hours ago (2009-11-24 06:57:00)  by yuvaraj
No, HA is working on L2, So Physical HA link is mandatory for High Availablity.   You need one physical interface atleast to send control messages and sync RTO/configurations.
Thread:  Show this thread (3 posts)   Thread info: HA physical interface - J-Net Community Size: 203 bytes
Related Threads: Same Site | All Sites
Customize:  Customize "Re: HA physical interface :: Firewalls :: Forums - J-Net Community"