Solved

Netscreen 5XP: Allowing Ping Request only from internal and known IP addresses

Posted on 2006-06-16
8
678 Views
Last Modified: 2012-05-05
I would like to configure Netscreen firewall so that it allows the ping request to be made only from internal and few other IP addresses. Please let me know if this can be done.

-Nauman.
0
Comment
Question by:nauman_ahmed
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
8 Comments
 
LVL 9

Expert Comment

by:jabiii
ID: 16922666
Just create a policy. allowing ping from ping from ping_group to any.
0
 
LVL 9

Expert Comment

by:jabiii
ID: 16922669
after re-reading you mean through the NS not to right?
0
 
LVL 25

Author Comment

by:nauman_ahmed
ID: 16922739
I want to enable ping only from the network where netscreen firewall is and from my office location but not from anywhere else.

-Nauman.
0
Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as the high-speed power of the cloud.

 
LVL 32

Expert Comment

by:rsivanandan
ID: 16923047
As stated by Jabii, create a policy from trust to untrust with the ping-group, allowing all.

Cheers,
Rajesh
0
 
LVL 9

Accepted Solution

by:
jabiii earned 500 total points
ID: 16923362
set address "(Interface)" "Office_Location" 1.1.1.1 255.255.255.255 "Office_Location"
set address "(Interface)" "Office_Location2" 1.1.1.1 255.255.255.255 "Office_Location2"
Set address "(Interface)" "Office_Network" 2.2.2.0 255.255.255.0 "Office_Network"

set group address "(Interface) "GRP: Office_Location"
set group address "(Interface)" "GRP: Office_Location" add "Office_Location"
set group address "(Interface)" "GRP: Office_Location" add "Office_Location2"

set policy id 1 from "(Interface)" to "(Interface)"  "Office_Location" "Any" "PING" permit log
set policy id 2 from "(Interface)" to "(Interface)"  "Office_Network" "Any" "PING" permit log
set policy id 3 from "(Interface)" to "(Interface)"  "GRP: Office_Location" "Any" "PING" permit log


You can also make ping a member of a service group with other ports allowed too. But these examples should get yo going.
0
 
LVL 9

Expert Comment

by:jabiii
ID: 16923365
woops with the exception office location2 should be 1.1.1.2 sorry :P
0
 
LVL 9

Expert Comment

by:jabiii
ID: 16995685
Tx :)
0
 
LVL 25

Author Comment

by:nauman_ahmed
ID: 17027029
jabiii,

Thanks for your answer. I have a question if you can help. We have Netscreen 5XP and after upgrading Windows 2003 server, we are facing issues where Windows 2003 Network card connected to WAN stop responding time to time. Upon reset it starts working again and is pingable from outside. I have removed SP1 and did not experience any issues after that. The MS KB article where this is described is http://support.microsoft.com/kb/899148/. Should I get a new netscreen firewall or just upgrade NS5XP OS to 5.X.X from 4.X.X?

Much thanks,
Nauman.
0

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as the high-speed power of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

690 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question