Netscreen Firewall 5GT Route

Posted on 2010-09-22
Last Modified: 2012-05-10
Hi All. We have a small network of about 45 computers and server and at present they are all simply setup so that they all point to the Default Gateway of the Netscreen 5GT firewall if wanting to go outside of our LAN ie to the world wide web (untrust). We have recently just downloaded a trial edition of GFI Web Monitor and installed it onto one of our servers. We want to assign certain users from specific ip addresses to be forwarded from the firwall to the GFI web Monitor so that these specific Ip Addresses can have the content filtered.
A way of doing it would be to point all of our computers to the GFI as the Default gateway before that goes out of the Netscreen. We do not want to do it this way. As we want to control the policies and traffic and schedueing from the Netscreen before going anywhere.
 I assume all that need to be done is create a policy of some form that see traffic coming from these defined ip addresse, wanting to use port 80 or port 433 and therefore forward this traffic to the CFI Server's Ip Address rather than going straight out. I hope my details mentioned above make sense.  
Question by:GenieMaster
  • 2
  • 2
LVL 18

Expert Comment

by:Sanga Collins
ID: 33739752
Policy based routing will allow you to do this. You can take traffic that matches a specific condition ( in this case HTTP and specific ip range or subnet ) and route it to the ip address of the web filtering server

Author Comment

ID: 33744087
Hi Sangamc. Somone else mentioned that Policy Based routing is the easiest way to do this. I do not have a clue on how to do this. Can you please provide me a step by step guide on how to do this, that would be much appreciated.
LVL 18

Accepted Solution

Sanga Collins earned 250 total points
ID: 33744293
It is way too much info to put into this post. Here is a link to a page describing how to set it up as well as how and why it works

you should also download the screenOS chapter on routing from the Juniper website. there is a very descriptive example on setting up PBR.

Author Comment

ID: 33747454
Thanks Sangamc. I am not familar at all with Netscreen as its all new to me. I have checked the link you provided and will try and see if there is a detailed step by step guide to set what I need. If any other experts are able to provide a detailed guide that would be much appreciated. Thanks
LVL 68

Expert Comment

ID: 34399070
This question has been classified as abandoned and is being closed as part of the Cleanup Program.  See my comment at the end of the question for more details.

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now