Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

How I configure juniper to access internet and branches in the same link?

Posted on 2010-08-16
12
914 Views
Last Modified: 2013-11-16
Hi,

Kindly I have this situation,

CoreSwitch connected to Internet and branches through two links from ISP one for internet by Juniper Firewall and another one to Branches by Cisco Router through MPLS network.

I need to combine the both link in one link. So I need to access the branches and internet through ISP link. And in this case the traffic which going to internet should be nat and the traffic what going to branches should be normal route.

Kindly see attached

This scenario is normal for me in ASA Cisco Firewall using nat control (nat 0) but in juniper it is a new setup for me.

So kindly I need any example with the same scenario using Juniper Firewall.

Best Regards

Juniper-Combine-Link.jpg
0
Comment
Question by:Migo50
  • 4
  • 3
12 Comments
 
LVL 32

Expert Comment

by:dpk_wal
ID: 33451742
>> I need to combine the both link in one link.
I am assuming that you would do away with MPLS as you would now be going through ISP internet link; if such is the case then you can create site-to-site VPN tunnels with remote branches; also remote VPN (if needed).

So all users behind the firewall would get internet through ISP when juniper firewall does NAT; also with site-to-site VPN tunnels users at different location would be able to share network resources as allowed by VPN policy.

If the firewall is a NS/ISG/SSG firewall then please have a look at link below:
http://kb.juniper.net/kb/documents/public/resolution_path/J_FW_VPN_Config_or_Trblsh.htm

Thank you.
0
 

Author Comment

by:Migo50
ID: 33456070
Dear,

The MPLS connection is terminated in ISP side Provider Edge (PE) and there is no MPLS traffic will reach to ISG and the site-to-site VPN is a good idea but it is not scalable idea because I have multiple branches and it will be grown in the future. Already I do it using nating control by Cisco Firewall and I'm looking to do the same concept but using juniper and I'm asking it is available by Juniper firewall to make nating control or not in case of YES are there any example or configuration using ISG to make nating control!!

Thank you
0
 
LVL 32

Accepted Solution

by:
dpk_wal earned 350 total points
ID: 33461669
Yes you can configure NAT on ISG; may be look at examples below:
http://kb.juniper.net/KB11909
http://kb.juniper.net/index?page=content&id=TN81&actp=search&searchid=1282110763524

If above is no help; then I would ask you to give some NAT CLIs from your current conf and can provide SOS CLIs.

Thank you.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 32

Expert Comment

by:dpk_wal
ID: 33859888
Need author comment to determine if solution worked on not.

Thank you.
0
 

Author Comment

by:Migo50
ID: 34186710
Sorry and kindly accept my appologize. I need to close the question but faild.
0
 

Author Comment

by:Migo50
ID: 34186723
I want to accept Genius's soultion and thanks for you all, and accept my appoligez again.
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 34188763
I have objected to my closing recommendation so you can close yourself.

Qlemo
Cleanup Volunteer
0
 
LVL 32

Expert Comment

by:dpk_wal
ID: 34193643
Hmm do not think "Delete/no refund" should be disposition; you would devoid me of rightful points! :)
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
GPR - Cannot telnet 15 88
Class Map is not matching traffic on Global Policy??? 2 52
iptables ubuntu BLOCK all 2 85
What's a good Free Firewall Program for Mac OS? 7 53
Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question