Questions tagged [netscreen]

24 questions
3
votes
1 answer

VLAN isolation failure with HP Procurve, Juniper Netscreen

I'm having problems with hosts being able to ping other hosts they shouldn't be able to communicate with. Fairly simple network - relevant hardware: HP Procurve 2810-24G switch Juniper Netscreen 208 firewall Netgear GS-108PE switch I simply want…
Phil K
  • 61
  • 5
3
votes
1 answer

Cisco 3750 native vlan VLAN1 doesn't work in a Trunked configuration

I have two devices here, a Netscreen SSG520 and a Cisco 3750. #show ver Cisco IOS Software, C3750 Software (C3750-IPSERVICES-M), Version 12.2(35)SE5, RELEASE SOFTWARE (fc1) Copyright (c) 1986-2007 by Cisco Systems, Inc. The Cisco is currently being…
David Mackintosh
  • 14,223
  • 6
  • 46
  • 77
3
votes
6 answers

Cisco PIX to Juniper Netscreen Policy-based VPN fails Phase 2 Proposal

I've followed the instructions to configure a VPN between a netscreen device and a Cisco PIX as directed by Cisco's [netscreen to PIX VPN]http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a00801c4445.shtml…
elint
  • 82
  • 1
  • 2
  • 10
3
votes
1 answer

How do I bring up an interface on a netscreen router

I took down an interface using set interface ethernet0/0 phy link-down with the intention of cycling it back up - but now I can;'t figure out how to bring it up.
jwoolard
  • 145
  • 1
  • 6
2
votes
3 answers

Easily obtain list of sessions from Juniper Netscreen

I've got a Juniper Netscreen SSG-5 that occasionally gets a high session count. I've got 4096 licensed sessions, and there are times I see 3000+ for a small office (a dozen or so people). This is higher than I would like, and it makes me a bit more…
Matt Simmons
  • 20,218
  • 10
  • 67
  • 114
2
votes
5 answers

How do I keep a Juniper ScreenOS interface IP up when no one is plugged into it?

I have a VPN connection to a remote site and whenever nothing is plugged into the remote sites LAN bgroup the interface IP isn't managable or pingable. Anyone know what command I skipped on CLI for setting this up? Or if there is a checkbox on…
sclarson
  • 3,624
  • 21
  • 20
2
votes
1 answer

Does Juniper ScreenOS support IPCOMP?

Given an oldish Juniper Netscreen device running ScreenOS 6.2 (Juniper NS5GT-ADSL), would it support IPCOMP payload compression (RFC 2393) in IPSEC tunnels? If so, any reference on how to set it up?
the-wabbit
  • 40,319
  • 13
  • 105
  • 169
2
votes
5 answers

Juniper NetScreen NS-5GT traffic monitoring

I've done casual research into the subject and am truly dismayed at the lack of compatible tools for such a simple task. Maybe someone can provide assistance. We have a NetScreen NS-5GT in the office. I need to be able to get a glance of current…
blah
2
votes
3 answers

What's the best tool for usage reporting on a NetScreen Firewall?

Anyone got a good product for Usage Reporting for a NetScreen Firewall. I went looking for Webtrends Firewall Suite but it appears to have disappeared into the NetIQ product line up. I am going to try out ManageEngine (I think is also AdventNet)'s…
Rob Bergin
  • 842
  • 10
  • 14
1
vote
1 answer

ScreenOS MIP selection for outbound connections

Given a ScreenOS 6.3.0 firewall with this configuration: unset flow reverse-route clear-text set interface "ethernet0/0" zone "Trust" set interface ethernet0/0 ip 192.168.1.1/24 set interface ethernet0/2 ip 10.0.0.1/24 set interface ethernet0/2…
David Mackintosh
  • 14,223
  • 6
  • 46
  • 77
1
vote
6 answers

Can't get into Juniper Networks Netscreen Web interface

Have a Netscreen that appears to be functioning correctly (it's in production and has been for several years), but yet is not allowing me into the Web interface on port 80 or 443 (also tried 8080). Tried telneting to 22 and 23 as well. Any attempt…
gravyface
  • 13,947
  • 16
  • 65
  • 100
1
vote
1 answer

How can I expire non-active sessions on my Netscreen SSG140?

I have a Juniper Netscreen SSG-140. While experimenting with a VoIP service, I defined a custom policy that was to be used to permit the possible ports in use to be sent back to the VoIP server from systems connecting across the internet. Because…
David Mackintosh
  • 14,223
  • 6
  • 46
  • 77
1
vote
1 answer

Net Screen Remote RDP not working but vpn is

I have a problem regarding a connection with Netscreen-remote. First of all, to install the program I had to create a VM of XP x32b because of compatibility issues. Once it is installed, I imported the security policy created by the host. When I…
Azshlanar
  • 49
  • 1
  • 7
1
vote
1 answer

What is the default management state on Netscreen firewall interfaces?

in other words, is the command: unset interface ethernet1/1 ip manageable redundant? I was thinking that for security purposes, it would probably make sense for Netscreens to only enable management on the mgt port, but I can't find any reference to…
Adam Brand
  • 6,057
  • 2
  • 28
  • 40
1
vote
1 answer

Routing for IPSec tunnel

For Juniper NetScreen-NS25, I configured a site-to-site IPSec tunnnel. For the outside interface of remote site, I also needed to go through tunnel which has the same IP as IPSec gateway. Now, when I add static route to route that outside interface…
Emre A
1
2