Solved

Netscreen 5XP: Allowing Ping Request only from internal and known IP addresses

Posted on 2006-06-16
8
661 Views
Last Modified: 2012-05-05
I would like to configure Netscreen firewall so that it allows the ping request to be made only from internal and few other IP addresses. Please let me know if this can be done.

-Nauman.
0
Comment
Question by:nauman_ahmed
  • 5
  • 2
8 Comments
 
LVL 9

Expert Comment

by:jabiii
ID: 16922666
Just create a policy. allowing ping from ping from ping_group to any.
0
 
LVL 9

Expert Comment

by:jabiii
ID: 16922669
after re-reading you mean through the NS not to right?
0
 
LVL 25

Author Comment

by:nauman_ahmed
ID: 16922739
I want to enable ping only from the network where netscreen firewall is and from my office location but not from anywhere else.

-Nauman.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 32

Expert Comment

by:rsivanandan
ID: 16923047
As stated by Jabii, create a policy from trust to untrust with the ping-group, allowing all.

Cheers,
Rajesh
0
 
LVL 9

Accepted Solution

by:
jabiii earned 500 total points
ID: 16923362
set address "(Interface)" "Office_Location" 1.1.1.1 255.255.255.255 "Office_Location"
set address "(Interface)" "Office_Location2" 1.1.1.1 255.255.255.255 "Office_Location2"
Set address "(Interface)" "Office_Network" 2.2.2.0 255.255.255.0 "Office_Network"

set group address "(Interface) "GRP: Office_Location"
set group address "(Interface)" "GRP: Office_Location" add "Office_Location"
set group address "(Interface)" "GRP: Office_Location" add "Office_Location2"

set policy id 1 from "(Interface)" to "(Interface)"  "Office_Location" "Any" "PING" permit log
set policy id 2 from "(Interface)" to "(Interface)"  "Office_Network" "Any" "PING" permit log
set policy id 3 from "(Interface)" to "(Interface)"  "GRP: Office_Location" "Any" "PING" permit log


You can also make ping a member of a service group with other ports allowed too. But these examples should get yo going.
0
 
LVL 9

Expert Comment

by:jabiii
ID: 16923365
woops with the exception office location2 should be 1.1.1.2 sorry :P
0
 
LVL 9

Expert Comment

by:jabiii
ID: 16995685
Tx :)
0
 
LVL 25

Author Comment

by:nauman_ahmed
ID: 17027029
jabiii,

Thanks for your answer. I have a question if you can help. We have Netscreen 5XP and after upgrading Windows 2003 server, we are facing issues where Windows 2003 Network card connected to WAN stop responding time to time. Upon reset it starts working again and is pingable from outside. I have removed SP1 and did not experience any issues after that. The MS KB article where this is described is http://support.microsoft.com/kb/899148/. Should I get a new netscreen firewall or just upgrade NS5XP OS to 5.X.X from 4.X.X?

Much thanks,
Nauman.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange OWA - failed logins and brute force monitor 7 262
Opening Port 80 10 66
how  to upgrade  to windows 10 56 145
Failover and load Balancing WLB Resource Failed 2 359
Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This Micro Tutorial will give you a basic overview how to record your screen with Microsoft Expression Encoder. This program is still free and open for the public to download. This will be demonstrated using Microsoft Expression Encoder 4.
This Micro Tutorial demonstrates using Microsoft Excel pivot tables, how to reverse engineer competitors' marketing strategies through backlinks.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question