How to transfer traffic to the Router?
Hello all,I want to transfer traffic to the Router like below captured picture. All of 192.168.240.0/24 network which is come SSG-5 should go to the Router. The step that I configure is just "set route...
View ArticleUpdate Interface Address via CLI
Hello, I would like to update my SSG interface Address. However, I am not sure the correct steps and also this is running under production enviornment, so it cannot allow to try. Following is related...
View ArticleCan SSG-140 transfer traffic in case it?
Hello all,I want to know whether SSG-140 transfer traffic in case below captured picture. As you can see the picture, SSG-140's IP is 2.2.2.2Source IP is 1.1.1.1, and Destination IP is 3.3.3.3 From...
View ArticleDo you know how to configure PAT?
Hello all,I appreciate you guys according to continuously replying to me. This question is about PAT.I know Juniper Firewall has 3 options. (MIP, DIP, VIP). At first, I supposed to start PAT using...
View ArticleCreating GRE tunnel between juniper ssg and cisco firewall
Dears, i want to create a GRE tunnel between juniper ssg fw ans cisco fwactually its my first time to use GRE, could you please assisti want to know what requirements should i have to complete this...
View ArticleSSG20:serial1/0: LMI link is down due to errors over threshold(n392)
Hirecently I have noticed some of our SSG20 Firewalls with the below messages :Date Time Module Level Type Description2016-05-24 18:45:18 system notif 00569 [fr/lmi]: serial1/0.1 dlci(101)...
View ArticleRIP Protocol
Good Day Experts, i have two point to point links between two SSG350 juniper firewalls and i want to configure RIP protocol over these links so i can reach the other side even if one of the links went...
View ArticleVPN issue - matched tunnel-id packet dropped, no way(tunnel) out
HI all, We have a VPN set-up on a Juniper SSG to a remote site firewall, the VPN tunnel is up To paint the picture, we are trying to send ICMP traffic from a subnet behind the local juniper, the...
View ArticleHMAC-SHA256 backward compatibility to 128 bits
Hello Team, Hope you are doing well.I just want an advise from you. Indeed, I am using ScreenOS : Software Version: 6.3.0r13.0, Type: Firewall+VPN I am configuring a VPN and my partener is requiring...
View ArticleLow memorry on SSG5
Hi, Please look at the picture below. It just happned this morning that the system has low memorry. Could you please show me a way to check and fix ? Am I under an attack? Thanks Loc
View Articleannouncement of ext DIP prefix in BGP
Hi,I have an ISG2000 (6.3.0) with two L3 external interfaces, running BGP over both for redundancy. Outbound NAT is achieved by having both of these interfaces in a loopback-group, and then utilising a...
View ArticleSSG 140 Backup NSRP set to ineligible
Hi, I have an issue that in my NSRP pair one is set to ineligible. Whilst not normally a major issue, these devices were set for the same management IP so only the Master could be accessed....
View ArticleRoute based VPN Trust Zone Multiple Site IP range
Dear All Expert, Ive created route based VPN for 2 sites.The scenario as below: Site A (HQ) -Trust bgroup (LAN): 10.20.5.27/25 -Site A will connected to servers in LAN environment ie: 10.20.5.7/24 Site...
View ArticleSecurity Board x CPU x unresponsive Problem
Juniper ISG1000 showing Security Board x CPU x unresponsive on its event log with critical level.Software Version: 6.3.0r16a.0, Type: Firewall+VPN (Only as a Firewall no IDP, IDS).Active/Passive...
View Articlescreenos 6.0.0rx
I need the firmware 6.0.0rx because the SSG5 appliancce have the version 5.4.0r16 and I hope to pass to the version 6.2.0rxCan you send me the firmware or the linkk to download?Thanks a lot
View ArticleSite to Site VPN NAT between SSG Firewalls and Checkpoint
Hi, I have the following setup and would like to do VPN and NAT Public IP from VPN FW to Checkpoint: SSG 140 (VPN FW) -> SSG 20 (DMZ FW) --> INTERNET -->CHECKPOINT Any tips on this? Thanks in...
View ArticleSecondary IP Address
Hi, I'm trying configure VPN and NAT on SSG140 which behind a SSG20 DMZ firewall. Currently there is a public ip subnet on the primary interface on the Trust interface of the DMZ. I have to use a new...
View ArticleSC-CPA on SSG5 not function
HI PEOPLEthis is the issue, I have two zone trust and untrust, I have enable web-filtering with integrated surfcontrol, i have one policy from trust to untrust. and the configuraion of the custom...
View ArticleAccess not available on all interfaces
I recently inherited someone else's problem of 2 SSG-320 devices that were "supposed" to be in HA mode, but never were fully implemented. What I'm currently trying to figure out, before enabling HA...
View Article