• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 675
  • Last Modified:

Juniper SSG5 - no connectivity

Hi, im am trying to setup a new SSG5. I have been given small /29 subnett with public IP's and I can not get it to work.

I have added a default route, but i cannot reach anything outside fram the inside.
Can anyonw see if have i have done something wrong here?  The Untrust Eth0/0 has this config:
set interface ethernet0/0 ip 87.110.178.210/29

And the default route looks like this:
set route 0.0.0.0/0 interface ethernet0/0 gateway 87.110.178.209


I can not ping anything on the outside.

I also have setup a test D-Link router which is working on IP 87.110.178.214 so i know that the subnet is working.
-cfg-2-.txt
0
xcomiii
Asked:
xcomiii
1 Solution
 
QlemoC++ DeveloperCommented:
Your config seems to be ok. Only note I have is that you have defined the same gateway twice - once for the interface, and another one in the trust-vr vrouter setup. I would only use the interface one, and allow adding the default gateway again:
set vrouter "trust-vr"
set add-default-route
unset route 0.0.0.0/0 interface ethernet0/0 gateway 87.110.178.209
exit

Open in new window

Did you check if policy 1 is hit at all? You have setup session logging, so you should see that.
And of course you checked you can reach your default gateway?!
0
 
xcomiiiAuthor Commented:
Thanks for your reply.
I did try to remove the second gateway, but "in use" error appeared.
However, you did point me in the right direction so i decided to restore the box to default setting and start over again, this time with only one gateway.

So now it works like dream, thank you.
0

Featured Post

The Firewall Audit Checklist

Preparing for a firewall audit today is almost impossible.
AlgoSec, together with some of the largest global organizations and auditors, has created a checklist to follow when preparing for your firewall audit. Simplify risk mitigation while staying compliant all of the time!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now