Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Netscreen 5XP: Allowing Ping Request only from internal and known IP addresses

Posted on 2006-06-16
8
Medium Priority
?
692 Views
Last Modified: 2012-05-05
I would like to configure Netscreen firewall so that it allows the ping request to be made only from internal and few other IP addresses. Please let me know if this can be done.

-Nauman.
0
Comment
Question by:nauman_ahmed
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
8 Comments
 
LVL 9

Expert Comment

by:jabiii
ID: 16922666
Just create a policy. allowing ping from ping from ping_group to any.
0
 
LVL 9

Expert Comment

by:jabiii
ID: 16922669
after re-reading you mean through the NS not to right?
0
 
LVL 25

Author Comment

by:nauman_ahmed
ID: 16922739
I want to enable ping only from the network where netscreen firewall is and from my office location but not from anywhere else.

-Nauman.
0
Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as high-speed processing of the cloud.

 
LVL 32

Expert Comment

by:rsivanandan
ID: 16923047
As stated by Jabii, create a policy from trust to untrust with the ping-group, allowing all.

Cheers,
Rajesh
0
 
LVL 9

Accepted Solution

by:
jabiii earned 2000 total points
ID: 16923362
set address "(Interface)" "Office_Location" 1.1.1.1 255.255.255.255 "Office_Location"
set address "(Interface)" "Office_Location2" 1.1.1.1 255.255.255.255 "Office_Location2"
Set address "(Interface)" "Office_Network" 2.2.2.0 255.255.255.0 "Office_Network"

set group address "(Interface) "GRP: Office_Location"
set group address "(Interface)" "GRP: Office_Location" add "Office_Location"
set group address "(Interface)" "GRP: Office_Location" add "Office_Location2"

set policy id 1 from "(Interface)" to "(Interface)"  "Office_Location" "Any" "PING" permit log
set policy id 2 from "(Interface)" to "(Interface)"  "Office_Network" "Any" "PING" permit log
set policy id 3 from "(Interface)" to "(Interface)"  "GRP: Office_Location" "Any" "PING" permit log


You can also make ping a member of a service group with other ports allowed too. But these examples should get yo going.
0
 
LVL 9

Expert Comment

by:jabiii
ID: 16923365
woops with the exception office location2 should be 1.1.1.2 sorry :P
0
 
LVL 9

Expert Comment

by:jabiii
ID: 16995685
Tx :)
0
 
LVL 25

Author Comment

by:nauman_ahmed
ID: 17027029
jabiii,

Thanks for your answer. I have a question if you can help. We have Netscreen 5XP and after upgrading Windows 2003 server, we are facing issues where Windows 2003 Network card connected to WAN stop responding time to time. Upon reset it starts working again and is pingable from outside. I have removed SP1 and did not experience any issues after that. The MS KB article where this is described is http://support.microsoft.com/kb/899148/. Should I get a new netscreen firewall or just upgrade NS5XP OS to 5.X.X from 4.X.X?

Much thanks,
Nauman.
0

Featured Post

What’s Wrong with Your Cloud Strategy ?

Even as many CIOs are embracing a cloud-first strategy, the reality is that moving to the cloud is a lengthy process and the end-state is likely to be a blend of multiple clouds—public and private. Learn why multicloud solutions matter in this webinar by Nimble Storage.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This course is ideal for IT System Administrators working with VMware vSphere and its associated products in their company infrastructure. This course teaches you how to install and maintain this virtualization technology to store data, prevent vuln…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question