• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 583
  • Last Modified:

netscreen 5xt and cisco 1800 series firewall configuration.

i assigned my server internal ip address: 172.30.6.5
in netscreen 5xt, i added Trust external address 66.253.99.135
i created a new policy from trust to untrust > source address is 172.30.6.5 and destination address is 66.253.99.135. under service, i allowed multiple such as http and other.

when i try to access 66.253.99.135, it should take me to my server externally but it does not work at all.

Please help.
0
cuc888
Asked:
cuc888
  • 8
  • 4
  • 3
1 Solution
 
cuc888Author Commented:
is there no one can help?
0
 
rsivanandanCommented:
Provide more details as to what services are you allowing and how are you accessing this machine from the trust network pc ?

Cheers,
Rajesh
0
 
cuc888Author Commented:
i got it figured out. netscreen untrust interface is 66.253.99.130 > here i added MIP 66.253.99.135 mapped to 172.30.6.5.

my current problem is Ping. i can't ping 66.253.99.135 either from inside or outside.
0
Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

 
rsivanandanCommented:
Ok, so in your policy do you have this MIP enabled for echo requests ? You should bind this MIP to a policy and as well you should allow the services you want along with ICMP (untrust to trust)

Cheers,
Rajesh
0
 
cuc888Author Commented:
in its policy > Service > i added Ping but nothing is yet to work.

is this where you are talking about?
0
 
rsivanandanCommented:
Yes, that should be good. So you are still not able to ping from external ?

Can you post your get config output here ?

Cheers,
Rajesh
0
 
cuc888Author Commented:
C:\Documents and Settings\john.000>ping 66.253.99.135

Pinging 66.253.99.135 with 32 bytes of data:

Request timed out.
Request timed out.
Request timed out.
Request timed out.

Ping statistics for 66.253.99.135:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
0
 
Salah Eddine ELMRABETTechnical Lead Manager (Owner)Commented:
Hello,

Did you try to ping your server from the inside(trust) using the translated Ip addresse? if yes this is normal have a look here

http://www.experts-exchange.com/Security/Firewalls/Q_22024323.html
http://www.experts-exchange.com/Networking/Q_22021398.html

else if you cannot ping your server from the outside and you have permit  ICMP this is a problem, so could you post your config and draw the network.

Regards,
0
 
cuc888Author Commented:
ping is fine now. it takes a few minutes but finally it works.

i now have another problem. i tried to add another MIP just like i did previously: netscreen untrust interface is 66.253.99.130 > here i added MIP 66.253.99.136 mapped to 172.30.6.6.

i won't be able too because it keeps giving me this alert messege: "The netmask is invalid"
it doesn't matter what i do, i changed different ip addresses for both but still got the same alert message without going any further.

any idea?
0
 
Salah Eddine ELMRABETTechnical Lead Manager (Owner)Commented:
Hello,

Witch netmask are you using 255.255.255.255??

Regards
0
 
cuc888Author Commented:
i am using 255.255.255.224 which is given by ISP. this is the mask i used earlier.
0
 
Salah Eddine ELMRABETTechnical Lead Manager (Owner)Commented:
Hello,

I mean witch mask are you using when configuring a satic nat!

Regards
0
 
cuc888Author Commented:
255.255.254.0
0
 
cuc888Author Commented:
i got it figured it out.
0
 
Salah Eddine ELMRABETTechnical Lead Manager (Owner)Commented:
When creating the MAP for single IP you have to use 255.255.255.255 mask!!

Regards,
0

Featured Post

The eGuide to Automating Firewall Change Control

Today‚Äôs IT environment is constantly changing, which affects security policies and firewall rules. Discover tips to help you embrace this change through process improvement & identify areas where automation & actionable intelligence can enhance both security and business agility.

  • 8
  • 4
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now