Solved

netscreen 5xt and cisco 1800 series firewall configuration.

Posted on 2006-10-20
15
577 Views
Last Modified: 2013-11-16
i assigned my server internal ip address: 172.30.6.5
in netscreen 5xt, i added Trust external address 66.253.99.135
i created a new policy from trust to untrust > source address is 172.30.6.5 and destination address is 66.253.99.135. under service, i allowed multiple such as http and other.

when i try to access 66.253.99.135, it should take me to my server externally but it does not work at all.

Please help.
0
Comment
Question by:cuc888
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 8
  • 4
  • 3
15 Comments
 

Author Comment

by:cuc888
ID: 17780860
is there no one can help?
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17780968
Provide more details as to what services are you allowing and how are you accessing this machine from the trust network pc ?

Cheers,
Rajesh
0
 

Author Comment

by:cuc888
ID: 17781039
i got it figured out. netscreen untrust interface is 66.253.99.130 > here i added MIP 66.253.99.135 mapped to 172.30.6.5.

my current problem is Ping. i can't ping 66.253.99.135 either from inside or outside.
0
How Do You Stack Up Against Your Peers?

With today’s modern enterprise so dependent on digital infrastructures, the impact of major incidents has increased dramatically. Grab the report now to gain insight into how your organization ranks against your peers and learn best-in-class strategies to resolve incidents.

 
LVL 32

Expert Comment

by:rsivanandan
ID: 17781064
Ok, so in your policy do you have this MIP enabled for echo requests ? You should bind this MIP to a policy and as well you should allow the services you want along with ICMP (untrust to trust)

Cheers,
Rajesh
0
 

Author Comment

by:cuc888
ID: 17781094
in its policy > Service > i added Ping but nothing is yet to work.

is this where you are talking about?
0
 
LVL 32

Expert Comment

by:rsivanandan
ID: 17781113
Yes, that should be good. So you are still not able to ping from external ?

Can you post your get config output here ?

Cheers,
Rajesh
0
 

Author Comment

by:cuc888
ID: 17781118
C:\Documents and Settings\john.000>ping 66.253.99.135

Pinging 66.253.99.135 with 32 bytes of data:

Request timed out.
Request timed out.
Request timed out.
Request timed out.

Ping statistics for 66.253.99.135:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
0
 
LVL 8

Accepted Solution

by:
Salah Eddine ELMRABET earned 500 total points
ID: 17782095
Hello,

Did you try to ping your server from the inside(trust) using the translated Ip addresse? if yes this is normal have a look here

http://www.experts-exchange.com/Security/Firewalls/Q_22024323.html
http://www.experts-exchange.com/Networking/Q_22021398.html

else if you cannot ping your server from the outside and you have permit  ICMP this is a problem, so could you post your config and draw the network.

Regards,
0
 

Author Comment

by:cuc888
ID: 17784366
ping is fine now. it takes a few minutes but finally it works.

i now have another problem. i tried to add another MIP just like i did previously: netscreen untrust interface is 66.253.99.130 > here i added MIP 66.253.99.136 mapped to 172.30.6.6.

i won't be able too because it keeps giving me this alert messege: "The netmask is invalid"
it doesn't matter what i do, i changed different ip addresses for both but still got the same alert message without going any further.

any idea?
0
 
LVL 8

Expert Comment

by:Salah Eddine ELMRABET
ID: 17784938
Hello,

Witch netmask are you using 255.255.255.255??

Regards
0
 

Author Comment

by:cuc888
ID: 17785330
i am using 255.255.255.224 which is given by ISP. this is the mask i used earlier.
0
 
LVL 8

Expert Comment

by:Salah Eddine ELMRABET
ID: 17785637
Hello,

I mean witch mask are you using when configuring a satic nat!

Regards
0
 

Author Comment

by:cuc888
ID: 17786103
255.255.254.0
0
 

Author Comment

by:cuc888
ID: 17791634
i got it figured it out.
0
 
LVL 8

Expert Comment

by:Salah Eddine ELMRABET
ID: 17792141
When creating the MAP for single IP you have to use 255.255.255.255 mask!!

Regards,
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
CLOUD SECURITY 3 78
Network Activities  please help 16 88
Bonjour traffic not going through sonicwall fw 6 156
Windows ADHow to restrict port 6881 bit Torrent 3 44
Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question