Questions tagged [screenos]

18 questions
5
votes
1 answer

Juniper SSG20 - Bridge ADSL to ethernet interface

We're trying to reuse some leftover equipment we've got. I've got a Juniper SSG20 with 2x ADSL2/2+ mini-PIMs and we've already got a firewall solution (Which will act as the PPPoE Client) but what we need is the ADSL functionality. Is it possible to…
MarksyF
  • 51
  • 2
5
votes
2 answers

ScreenOS ip6in4 tunnel over transport mode ipsec?

I have setup a point to point transport ipsec session between a ScreenOS router (SSG-5) and a Cisco 3925. The ipsec transport itself works great, but as soon as I try to direct the protocol 41 traffic over the transport, the packets don't transit…
Peter Grace
  • 3,446
  • 1
  • 26
  • 42
3
votes
1 answer

How do I bring up an interface on a netscreen router

I took down an interface using set interface ethernet0/0 phy link-down with the intention of cycling it back up - but now I can;'t figure out how to bring it up.
jwoolard
  • 145
  • 1
  • 6
2
votes
3 answers

Easily obtain list of sessions from Juniper Netscreen

I've got a Juniper Netscreen SSG-5 that occasionally gets a high session count. I've got 4096 licensed sessions, and there are times I see 3000+ for a small office (a dozen or so people). This is higher than I would like, and it makes me a bit more…
Matt Simmons
  • 20,218
  • 10
  • 67
  • 114
2
votes
5 answers

How do I keep a Juniper ScreenOS interface IP up when no one is plugged into it?

I have a VPN connection to a remote site and whenever nothing is plugged into the remote sites LAN bgroup the interface IP isn't managable or pingable. Anyone know what command I skipped on CLI for setting this up? Or if there is a checkbox on…
sclarson
  • 3,624
  • 21
  • 20
2
votes
1 answer

Does Juniper ScreenOS support IPCOMP?

Given an oldish Juniper Netscreen device running ScreenOS 6.2 (Juniper NS5GT-ADSL), would it support IPCOMP payload compression (RFC 2393) in IPSEC tunnels? If so, any reference on how to set it up?
the-wabbit
  • 40,319
  • 13
  • 105
  • 169
1
vote
1 answer

ScreenOS MIP selection for outbound connections

Given a ScreenOS 6.3.0 firewall with this configuration: unset flow reverse-route clear-text set interface "ethernet0/0" zone "Trust" set interface ethernet0/0 ip 192.168.1.1/24 set interface ethernet0/2 ip 10.0.0.1/24 set interface ethernet0/2…
David Mackintosh
  • 14,223
  • 6
  • 46
  • 77
1
vote
1 answer

How can I expire non-active sessions on my Netscreen SSG140?

I have a Juniper Netscreen SSG-140. While experimenting with a VoIP service, I defined a custom policy that was to be used to permit the possible ports in use to be sent back to the VoIP server from systems connecting across the internet. Because…
David Mackintosh
  • 14,223
  • 6
  • 46
  • 77
1
vote
0 answers

OpenVPN & Juniper SSG-140

I asked this question over on some Juniper Forums but they seem to be pretty dead as in over a week it hasn't had that many hits and no one has had any advice. I figure if I can find someone familiar with Juniper routers they can direct me into the…
sxanness
  • 137
  • 1
  • 17
0
votes
1 answer

What is the use of the 'exit' statement in a screenOS juniper firewall config?

I want to audit a screenOS juniper firewall. I have been provided with the configuration file, but I am not familiar with the syntax. I am wondering about the 'exit' command. In the config file, most policies are followed by one or two additional…
0
votes
1 answer

ScreenOS Failover tunnel

I have a route-based vpn from my site (Netscreen204) to a customer site (Fortinet) . They want a second, backup tunnel in case of failure, and will be using the Fortune there too. The only thing I don't quite get is how best to set up vpn monitor.…
user202243
  • 13
  • 4
0
votes
2 answers

How to restict telnet from Juniper firewall?

Can telnet everywhere from the appliance without any traffic / event logs. It seems to disregard the global policy we have set for blocking all traffic unless specifically permitted.
Alex
  • 1,768
  • 4
  • 30
  • 51
0
votes
2 answers

Can Juniper SSG be used as DNS recursor?

As per title. e.g. 1. client asks example.com <--> Juniper_SSG_140 2. Juniper_SSG_140 <--> DNS root servers 3. <--> Specific DNS returned by root server 4. client receives answer from Juniper_SSG_140 5. Juniper_SSG_140 caches the…
Alex
  • 1,768
  • 4
  • 30
  • 51
0
votes
1 answer

Juniper ScreenOS Windows 7 Vpn client

I'd like to configure my Juniper firewall so users can VPN from the windows built in client. Can anyone provide me with that information on how to go about configuring this? (I'm somewhat new to juniper firewalls)
Chris Kooken
  • 301
  • 4
  • 16
0
votes
2 answers

Juniper ScreenOS vlan configuration

Trying to configure my first Juniper firewall, an SSG5 (running 6.2.0r11.0), but having some trouble with the vlans. I haven't found much documentation relating to what I'm trying to do; possibly because it's not possible, or perhaps I'm just…
Demelziraptor
  • 479
  • 1
  • 4
  • 11
1
2