netscreen 25 routing question

netscreen 25 routing question

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
netscreen 25 routing question <nospam 05-11-2005
Posted by on May 11, 2005, 6:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Inherited a Netscreen 25 , and from what appears to be the factory default
configuration,

I have configured eth3 as my untrust network , and can ping sites from the
router on the internet from
eth3:

....ns25-> ping 209.68.22.220 from eth3
....Sending 5, 100-byte ICMP Echos to 209.68.22.220, timeout is 1 seconds
....!!!!!
....Success Rate is 100 percent (5/5), round-trip time min/avg/max=44/44/44
ms

However, despite adding the policy below to an otherwise empty policy list,
:

set policy top from "Trust" to "Untrust" "Any" "Any" "ANY" nat src dip-id 2
Permit log

I am unable to ping from the VLAN interface to the outside world.


Interface list below:

Name IP/Netmask Zone Type Link Configure
ethernet1 0.0.0.0/0 V1-Trust Layer2 up Edit
ethernet2 0.0.0.0/0 V1-DMZ Layer2 down Edit
ethernet3 192.168.2.8/24 Untrust Layer3 up Edit
ethernet4 0.0.0.0/0 Null Unused down Edit
vlan1 192.168.1.1/24 VLAN Layer3 up Edit


I desire to set this up as a standard router / firewall, with eth1 being my
"trusted" network, and eth3 being the Internet,
but have been unable to get the router to ping between interfaces, much less
route traffic between the networks...




Posted by Munpe Q on May 11, 2005, 2:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Well this config is FUBAR if you want it to be a router. You have eth1
setup in transparent mode and in the V1-Trust zone, and then you have
eth3 in Untrust with a Private address.

You've got this config freakin' twisted to be a router. And of course
you didn't show each individual interface. I'm not even gonna touch
this one. If you want some serious help on the 25, pay somebody that
knows what they are doing. And of course I'd be glad to accept a check
and get a config written for you, but not like this.

Word.

MQ



Posted by Sunny on May 11, 2005, 7:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


nospam@killspam.org wrote:

> Inherited a Netscreen 25 , and from what appears to be the factory default
> configuration,
>
> I have configured eth3 as my untrust network , and can ping sites from the
> router on the internet from
> eth3:
>
> ...ns25-> ping 209.68.22.220 from eth3
> ...Sending 5, 100-byte ICMP Echos to 209.68.22.220, timeout is 1 seconds
> ...!!!!!
> ...Success Rate is 100 percent (5/5), round-trip time min/avg/max=44/44/44
> ms
>
> However, despite adding the policy below to an otherwise empty policy list,
> :
>
> set policy top from "Trust" to "Untrust" "Any" "Any" "ANY" nat src dip-id 2
> Permit log
>
> I am unable to ping from the VLAN interface to the outside world.
>
>
> Interface list below:
>
> Name IP/Netmask Zone Type Link Configure
> ethernet1 0.0.0.0/0 V1-Trust Layer2 up Edit
> ethernet2 0.0.0.0/0 V1-DMZ Layer2 down Edit
> ethernet3 192.168.2.8/24 Untrust Layer3 up Edit
> ethernet4 0.0.0.0/0 Null Unused down Edit
> vlan1 192.168.1.1/24 VLAN Layer3 up Edit
>
>
> I desire to set this up as a standard router / firewall, with eth1 being my
> "trusted" network, and eth3 being the Internet,
> but have been unable to get the router to ping between interfaces, much less
> route traffic between the networks...

As MQ said, your current config is a mess that won't do anything useful.

I recommend RTFM - there are worked examples close to what you are
trying to achieve - and retain a professional consultant if still unsure.

Sunny


Posted by on May 12, 2005, 12:14 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Well, from FUBAR to functional in two quick commands.

1) Define eth1 as belonging to trust interface , rather than the previously
configured v1-trust

2) define desired ip parameters for above interface.

I've configured routers and firewalls from a lot of different vendors, I
find the netscreen's
implementation more obtuse than most, though it seems remarkably
full-featured





Similar ThreadsPosted
Routing on Netscreen 5XP July 29, 2005, 11:57 am
Netscreen 25 DMZ Routing August 25, 2007, 1:38 pm
To Alan Strassberg - Routing On Netscreen 5XP August 3, 2005, 10:51 am
Routing question.. October 25, 2005, 2:00 pm
Simple (?) routing question November 23, 2004, 12:36 am
TCP Routing/IPTABLES question. February 23, 2005, 10:00 am
routing between vpn sites question August 13, 2007, 1:24 pm
NetScreen NAT/VPN question April 22, 2005, 12:18 pm
Question about Netscreen 5 GT firewall / VPN March 14, 2005, 3:36 pm
Netscreen Failover question May 11, 2005, 11:37 pm

The site map in XML format XML site map

Contact Us | Privacy Policy