Netscreen 5GT Extended DMZ setup

Netscreen 5GT Extended DMZ setup

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Netscreen 5GT Extended DMZ setup The other Mike 09-24-2005
Posted by The other Mike on September 24, 2005, 12:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Running a Netscreen 5GT Extended mode and want to configure the DMZ.
I have a FTP server in the DMZ and it can be accessed from the untrust
to the dmz zone no problem after putting a policy and a VIP in place.
My problem is I can't get from the DMZ to the Internet. I tried
putting a policy in place for DMZ to Untrust allowing anything (for
testing) and no go. In the log on the anything policy, I noticed that
the source address and translated address are the same and bytes are
being sent but not received...so I'm assuming NAT isn't working on the
DMZ addresses. Is this a correct assumption? I don't have alot of
netscreen knowledge so I can't figure out how or where to resolve
this. Any help would be appreciated.


Posted by Somebody. on September 25, 2005, 8:34 am
If you were  Registered and logged in, you could reply and use other advanced thread options

> Running a Netscreen 5GT Extended mode and want to configure the DMZ.
> I have a FTP server in the DMZ and it can be accessed from the untrust
> to the dmz zone no problem after putting a policy and a VIP in place.
> My problem is I can't get from the DMZ to the Internet. I tried
> putting a policy in place for DMZ to Untrust allowing anything (for
> testing) and no go. In the log on the anything policy, I noticed that
> the source address and translated address are the same and bytes are
> being sent but not received...so I'm assuming NAT isn't working on the
> DMZ addresses. Is this a correct assumption? I don't have alot of
> netscreen knowledge so I can't figure out how or where to resolve
> this. Any help would be appreciated.

Nat is enabled by interface OR by policy.

You likely have neither enabled on your DMZ interface and policy.

In the "dmz -> untrust dmz_subnet to any all permit" policy, click on
"advanced" and then put a check beside "NAT" and hit ok/ok.

The checkmark circle in the policy list should change from green (permit) to
blue (NAT) and you should be fine.

I don't recommend NAT by interface, *ever*. It's implemented less
efficiently in the box and prevents you from putting non-NATd traffic
through the interface. NAT should be enabled policy by policy as
appropriate.


-Russ.




Similar ThreadsPosted
Netscreen 5GT in Extended Mode May 17, 2005, 8:53 pm
Netscreen 5GT Extended - DMZ issues September 5, 2005, 6:24 am
Netscreen 5GT PC-Anywhere Setup Help! August 8, 2004, 11:47 pm
Transparent mode in NS 5GT (Port mode Extended) April 27, 2006, 3:41 am
VPN problems from Linksys WAG54G to Netscreen 208 using netscreen client November 28, 2005, 5:36 pm
DMZ Setup December 10, 2004, 4:44 am
IP Cop SetUP. February 7, 2005, 3:37 am
setup January 27, 2005, 8:36 am
PIX506 - SSH setup April 15, 2005, 8:39 pm
Firewall setup help with DMZ August 31, 2005, 3:59 pm

The site map in XML format XML site map

Contact Us | Privacy Policy