|
More site info...
Firewalls | Forum profile
|
|
Forum profile page for Firewalls on http://www.juniper.net.
This report page is the aggregated overview from a single forum: Firewalls, located on the Message Board at http://www.juniper.net.
This forum profile page summarizes the general forum statistics such as: Users Activity, Forum Activity, and Top Authors, which are reported in either a table or graph below for a given reporting time period.
Additional forum profile information for "Firewalls" on the Message Board at http://www.juniper.net is also shown in the following ways:
1) Latest Active Threads
2) Hot Threads for Last Week
Warning: These statistics are generated using 'best efforts' and can experience delays and reporting errors at times. Please note that such statistics do not constitute a forum's popularity and/or exact posting volumes at any given reporting period.
|
|
|
|
|
Posting activity on Firewalls:
|
|
Week
|
Month
|
3 Months
|
|
Threads:
|
71
|
233
|
750
|
|
Post:
|
104
|
418
|
1,337
|
|
|
Firewalls Posting activity graph:
|
Top authors during last week:
user's latest post:
Web Filtering URL Wildcard...
Published (2009-11-25 20:45:00)
Hi, Am not bale to get that KB article 10888. Am attching the snapshot of the error am getting. Could you help me out. Thnaks and regards, Narayanan
user's latest post:
HA physical interface - J-Net...
Published (2009-11-26 17:55:00)
Thanks for your reply. Ive read thru NetScreen OS manual, there seem to be a paragragh about HA Virtual Interface, that does not make use of the physical interface. Was wondering if anyone comes across HA Virtual Interface.
user's latest post:
Fun with Dual VR'S! - J-Net...
Published (2009-11-27 00:46:00)
Now facing problem that if the untrust link goes down why the default route is not going IPv4 Dest-Routes for <untrust-vr> (3 entries) -------------------------------------------------- ------------------------------------ ID IP-Prefix Interface Gateway P Pref Mtr Vsys --------------------------------------------------...
user's latest post:
Upgrade from screenOS 4 to...
Published (2009-11-19 13:42:00)
never mind all i found the problem. needed to goto 5.0 first since the file structure changes.
user's latest post:
SSG 20- Startup Problem - J-Net...
Published (2009-11-21 11:24:00)
hello Abhi, for the first problem, you will need to check the default gateway for your ip address in the PC, if dynamic, configure it as static 192.168.1.33 255.255.255.0 192.168.1.1 >>>>>>Default gateway. go to the web and enter this https:// 192.168.1.1 >>>>>> if you redirect http to https. For the second problem I think it is a DNS Problem. try the...
user's latest post:
SSG 20 Quick Questions. - J-Net...
Published (2009-11-20 07:10:00)
1- fine 2- you have to move the new policy before the deny policy. Policies will be searched in top-down order. 3- the ssg has a self signed certificate for https which is not trusted by your browser.It is ok if you tust it. Otherwise you need to buy a certificate from a trust authority. 4- check the logging checkbox on every policy, where you want to log traffic 5- the default settings on the untrust zone are already set to harden the...
user's latest post:
Dialup VPN and Windows 7 - J-Net...
Published (2009-11-22 12:09:00)
Hi, Please use the following KB which will helps to create the Dial VPN by using L2Tp with IPsec tunnel. http://kb.juniper.net/KB10939 or http://kb.juniper.net/kb/documents/public/VPN/Scre enOS_Windows_L2TP_IPSec.pdf Use the same configuration but please use certificate as mention in the above links , L2TP with IPsec tunnel using pre-share key will not work with Juniper firewall. Thanks Atif
|
|
|
|
Latest active threads on Firewalls::
Started 3 days, 3 hours ago (2009-11-27 08:31:00)
by muttbarker
OK - Dumb question time - did you configure the DMZ I/F to allow for ping?
Started 6 days, 4 hours ago (2009-11-24 06:46:00)
by SSHSSH
yes , you are right in case of Dedicated management ports , you should give ecah of them a different ip
Started 3 days, 4 hours ago (2009-11-27 07:08:00)
by mehdi
hi dkrut i have met the same situation, last mounth, i have did that : I have dowload the config files for the both devic, after that i have opned it with winmerge application for editing the files , i have replaced only old ip address to new ip address for iterfaces untrust "IP ISP" and all mip and vip. and after that i compared the old file and a new file with Winmerge application. ...
Started 3 days, 5 hours ago (2009-11-27 06:22:00)
by Diggers
The major difference is that the SRX will run on JUNOS
Started 3 months, 1 week ago (2009-08-19 17:44:00)
by firewall72
Hi, The only way I know to accomplish this is to move your egress interfaces to a single VR. For example, E1 would be in the trust-vr, E3 and E4 would be in the untrust-vr. You would then have a default route in the trust-vr that points to the untrust-vr and two default routes in the untrust-vr (via each ISP gateway). I've configured equal metrics across ISP's using ECMP and unequal metrics...
Started 3 days, 17 hours ago (2009-11-26 18:02:00)
by dkraut
Started 6 days, 4 hours ago (2009-11-24 06:57:00)
by yuvaraj
No, HA is working on L2, So Physical HA link is mandatory for High Availablity. You need one physical interface atleast to send control messages and sync RTO/configurations.
Started 1 week ago (2009-11-22 19:40:00)
by ITSupport
I am also new to Junipers but I have learnt something in last few months. In your situation the traffic is not going out from TRUST to UNTRUST. As you mentioned you must check your route and policy configuration. You must have proper route and policy as below: ROUTE: FROM ----- TRUST LAN ------TO ---- UNTRUST ------VIA GE-0/0/1 POLICY: FROM ----- TRUST LAN TO UNTRUST --- ALLOW ...
|
|
Hot threads for last week on Firewalls::
Started 5 days, 23 hours ago (2009-11-24 11:42:00)
by muttbarker
How did you create your whitelist URL's? Perhaps you have a problem with them. For example if you allow the following: www.facebook.com and then you try and go to the French version fr-fr.facebook.com you will fail. You have to wildcard your entries IE - *.facebook.com
Started 1 week ago (2009-11-22 11:38:00)
by arizvi
Started 3 days, 3 hours ago (2009-11-27 08:31:00)
by muttbarker
OK - Dumb question time - did you configure the DMZ I/F to allow for ping?
Started 1 week ago (2009-11-22 14:50:00)
by contra
depending on your setup you could configure Bridge Groups set interface bgroup0 zone "untrust" set interface bgroup0 port ethernet0/1 set interface bgroup0 port ethernetx/x set interface bgroup0 port ethernetx/x set interface bgroup0 port ethernetx/x set interface bgroup0 port ethernetx/x
Started 5 days, 23 hours ago (2009-11-24 11:47:00)
by muttbarker
At a high level you will need to do the following: 1- Create the NAT relationships - this is done on the outbound (untrusted) I/F. You have your choice between MIP, DIP and VIP entries. If you bring up the I/F you will see the options at the top of the page. Select one and then select the question mark in the upper right corner and you can get some nice help documentation on this. 2- You ...
Started 6 days, 4 hours ago (2009-11-24 06:46:00)
by SSHSSH
yes , you are right in case of Dedicated management ports , you should give ecah of them a different ip
Started 3 months, 1 week ago (2009-08-19 17:44:00)
by firewall72
Hi, The only way I know to accomplish this is to move your egress interfaces to a single VR. For example, E1 would be in the trust-vr, E3 and E4 would be in the untrust-vr. You would then have a default route in the trust-vr that points to the untrust-vr and two default routes in the untrust-vr (via each ISP gateway). I've configured equal metrics across ISP's using ECMP and unequal metrics...
Started 1 week ago (2009-11-23 09:37:00)
by shadow
You need to make sure that your policy has the network address translation setup as well. From the CLI set policy from "DMZ" to "Untrust" "Any" "Any" "Any" nat src permit log save From the Web Gui Edit the rule you have already created, then click on advanced and make sure that source translation is checked with use egress interface IP. Then click okay and give it a try.
Started 2 weeks, 4 days ago (2009-11-12 06:52:00)
by muttbarker
Yes - I have setup W2K8 for Radius Auth - it is similiar to W2K3 but you have to configure the "NPS" Network Policy Server for your radius setup. This is comparable to the W2K3 setup you would do under Internet Authentication Services. Add "Network Policy and Access Services" to your DC and then configure network ports, clients and policies under Server Manager -> Roles -> Network Policy and ...
Started 6 days, 4 hours ago (2009-11-24 06:57:00)
by yuvaraj
No, HA is working on L2, So Physical HA link is mandatory for High Availablity. You need one physical interface atleast to send control messages and sync RTO/configurations.
|
|