Solved

VIP and Port forwarding on JUNIPER ssg-140

Posted on 2009-07-10
5
2,348 Views
Last Modified: 2013-11-16
Well folks, up for grabs those delicious 500 points!

We have the following setup SSG140 with a range of external IP's, one of them i have to put on a VIP because i need port 443 pointing to my portal and i want to use this same IP to be my voip address.

The thing is, i need to forward the following ports:

UDP 10000-20000 - RTP (needed for SIP communications)
UDP 5004-5037 - SIP (needed for SIP communications)
UDP 5039-5082 - SIP (needed for SIP communications)
UDP 4569 - IAX2 (needed for IAX communications between Asterisk servers)

as far as i know SSG-140 on the  NETWORK > INTERFACES > VIP i have to do 1 forward at a time and dont know how to forward a range of ports.

After that i know i have to setup the POLICIES to allow traffic from the EXTERNAL NETWORK (UNTRUST) to the trust zone also.

THe main question is how to forward a range of ports from the external IP to an internal machine.

0
Comment
Question by:manolocruz
5 Comments
 
LVL 32

Accepted Solution

by:
dpk_wal earned 500 total points
Comment Utility
The CLI to configure port range with VIP is [based on SOS 6.x]:

set interface <interface-name> vip <vip-ip> port-range <low-port>-<high-port> server-ip <internal-server-ip> port-range <low-port>-<high-port> [protocol tcp/udp]

Example:

set int e1/1 vip 1.1.1.2 port-range 2-200 server-ip 2.2.2.2 port-range 2-200
OR
set int e1/1 vip 1.1.1.2 port-range 2-200 server-ip 2.2.2.2 port-range 2-200 protocol TCP

Please let know if you need more details.

Thank you.
0
 
LVL 7

Expert Comment

by:willbaclimon
Comment Utility
dpk_wal hit it right on target :)
0
 
LVL 18

Expert Comment

by:deimark
Comment Utility
Might be worth checking the zone assignment here, as I don't think Juniper will like you calling this a Check Pint question, hehe.

And yup, dpk_wal is bang on :P
0
 

Author Closing Comment

by:manolocruz
Comment Utility
Some people dont have access to the console.
some people use the WEB UI to do all mods.
0
 
LVL 32

Expert Comment

by:dpk_wal
Comment Utility
If you had updated; we could have given UI options too! ;)
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now