Netscreen High Availability & IP Tracking problem.

Netscreen High Availability & IP Tracking problem.

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Netscreen High Availability & IP Tracking problem. jfizer 05-18-2007
Posted by on May 18, 2007, 12:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I have two Netscreen 100s with ScreenOS 2.6 setup in a HA failover
configuration. The problem I'm having is that when I sync the two
units, the slave box gets an exact copy of the masters configuration
and then shuts down all duplicate IP addresses, including the external
untrusted port. This means that the slave cant ping anything, and thus
will allways generate failures when I set it up to track an IP.

Do I need to give the salve box a unique public IP via a serial
reconfiguration of the masters setup? If so, why isn't this talked
about in any of the documentation?


Posted by Jens Hoffmann on May 18, 2007, 4:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

> I have two Netscreen 100s with ScreenOS 2.6

ScreenOS 2.6 is more than outdated.

Cheers,
Jens

Posted by Wolfgang Kueter on May 18, 2007, 8:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Jens Hoffmann wrote:

> Hi,
>
>> I have two Netscreen 100s with ScreenOS 2.6
>
> ScreenOS 2.6 is more than outdated.

Typical, people like to spend money for a shiny device (in this case even
for two of them) but do not like to buy a service contract to get software
updates for their shiny box(es).

Wolfgang





Posted by on May 24, 2007, 4:48 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hi,
>
> > I have twoNetscreen100s with ScreenOS 2.6
>
> ScreenOS 2.6 is more than outdated.
>
> Cheers,
> Jens


ScreenOS 2.6 has no known security problems and has all the features I
need. I dont see why I should spend thousands of dollars upgrading.

But thanks for not answering my question or even making an attempt to
help.


Posted by Jens Hoffmann on May 25, 2007, 1:53 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

jfizer@klassy.com schrieb:
> ScreenOS 2.6 has no known security problems

http://securityvulns.com/docs2436.html
http://www.juniper.net/support/security/alerts/ip_spoof_protection_failure.html
http://www.juniper.net/support/security/alerts/10_01_03_57983_v003.html
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-0891

_no_ known is defined a bit differently.
It may be so, that you are not affected.


> and has all the features I
> need. I dont see why I should spend thousands of dollars upgrading.

So that there is anyone besides historians who can help you.
2.6 was current when I started using netscreens, hmm, 5 years ago?
Last time I check, it was something like 5.x. There is not
much similarity left.

> But thanks for not answering my question or even making an attempt to
> help.

I did, you just didn't get the answer you wanted to hear.

Cheers,
Jens

Similar ThreadsPosted
Zone Alarm - free to Pro and back, now high is problem November 22, 2004, 6:19 pm
Netscreen NAT problem April 16, 2007, 6:30 am
Limewire tracking November 14, 2007, 2:22 pm
tracking network slowdown September 24, 2007, 1:45 pm
Netscreen and SonicWall interoperate problem April 16, 2005, 12:28 am
Netscreen 5400 configuration problem May 19, 2006, 6:43 am
Netscreen 50 and RedHat Linux Syslog problem August 5, 2005, 2:07 am
host availability January 10, 2006, 6:27 pm
ANy high volume PIX admins out there? November 16, 2005, 11:09 pm
DOS Attack & High load June 29, 2007, 5:58 am

The site map in XML format XML site map

Contact Us | Privacy Policy