Netscreen SSG5 Firewall

I have been using Netscreen devices at the Enterprise level for a few years but only in the area of editing existing policies created by the corporate gurus of firewalls, which brings me to my question. I have an SSG5 for my home firewall, currently it has only one policy in place. That is to allow any traffic from the untrusted zone to the trusted zone. 2 things are happening that I can't get my head wrapped around. First issue is after 20 days or so, FTP traffic will cease to flow out bound. I get a time out error. The fix seems to be to reset the SSG5 and all is well again. Second is that TCP port 5001 traffic is being blocked somehow and I am not sure why. I admit to being new at creating the policies and I am looking for some guidance.
Bob ConklinConfiguration/TEST TechnicianAsked:
Who is Participating?
Sanga CollinsConnect With a Mentor Systems AdminCommented:
For the port 5000-5001 traffic you will need to create a MIP or VIP that basically maps your public IP address to the device that will be receiving the traffic. Then you need to create an untrust to trust policy with the MIP/VIP as the destination to allow that traffic through the firewall.

If you do not have a block of public IP's a VIP will be the best course of action. The juniper KB has a great article with steps for creating one.

bookmark, It has great articles on how to do almost anything on their devices with pictures good descriptions and accounts for variables in different setups.
The FTP issue sounds like a bug, not cleaning the firewalls session table from old connections. Check if you can get a more recent firmware.
In regard of port 5001, is that outbound or inbound?
Bob ConklinConfiguration/TEST TechnicianAuthor Commented:
The firmware is at the last version supported by Juniper, the 5001 traffic is used to access a Slingbox streaming system. From what I gather at Slingbox support, it is an inbound request to the box to open a session to the client system.
Will You Be GDPR Compliant by 5/28/2018?

GDPR? That's a regulation for the European Union. But, if you collect data from customers or employees within the EU, then you need to know about GDPR and make sure your organization is compliant by May 2018. Check out our preparation checklist to make sure you're on track today!

Sanga CollinsSystems AdminCommented:
Normally SSG devices block all traffic by default. Having just one policy from untrust to trust seems strange since you would not be able to send any traffic outbound.

2nd point is a policy from untrusted to trusted will not work unless you have a mapped ip (MIP) or virtual ip (VIP). inbound traffic will not actually reach any device on your network with just this policy.

For the outbound FTP traffic. You should have a policy from trust zone to untrust, can you paste that here so we can take a look at it? And for the port 5001 being blocked, is this inbound or outbound? That will help determine where to trouble shoot.
Bob ConklinConfiguration/TEST TechnicianAuthor Commented:
I was taught that too, all traffic is blocked and you have to allow what you want. I will post what is currently on the system when I get home tonight. I currently do not have remote access to the device enabled.
Sanga CollinsSystems AdminCommented:
not a problem, We are here to assist so whenever you get a chance.
Bob ConklinConfiguration/TEST TechnicianAuthor Commented:
Here is the current config file from the my SSG5: (Public IPs edited)
set clock ntp
set clock timezone -5
set vrouter trust-vr sharable
set vrouter "untrust-vr"
set vrouter "trust-vr"
unset auto-route-export
set service "Sling" protocol tcp src-port 5000-5001 dst-port 5000-5001 
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"
set auth radius accounting port 1646
set admin auth timeout 10
set admin auth server "Local"
set admin format dos
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "DMZ" vrouter "trust-vr"
set zone "VLAN" vrouter "trust-vr"
set zone "Untrust-Tun" vrouter "trust-vr"
set zone "Trust" tcp-rst 
set zone "Untrust" block 
unset zone "Untrust" tcp-rst 
set zone "DMZ" tcp-rst 
set zone "VLAN" block 
unset zone "VLAN" tcp-rst 
set zone "Untrust" screen icmp-flood
set zone "Untrust" screen udp-flood
set zone "Untrust" screen winnuke
set zone "Untrust" screen port-scan
set zone "Untrust" screen ip-sweep
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ip-spoofing
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "Untrust" screen tcp-no-flag
set zone "Untrust" screen unknown-protocol
set zone "Untrust" screen ip-bad-option
set zone "Untrust" screen fin-no-ack
set zone "Untrust" screen block-frag
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
set interface "ethernet0/0" zone "Untrust"
set interface "ethernet0/1" zone "Null"
set interface "bgroup0" zone "Trust"
set interface bgroup0 port ethernet0/2
set interface bgroup0 port ethernet0/3
set interface bgroup0 port ethernet0/4
set interface bgroup0 port ethernet0/5
set interface bgroup0 port ethernet0/6
unset interface vlan1 ip
set interface ethernet0/0 ip 72.12.X.X/22
set interface ethernet0/0 route
set interface bgroup0 ip
set interface bgroup0 nat
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface ethernet0/0 ip manageable
set interface bgroup0 ip manageable
set interface ethernet0/0 manage ping
set interface ethernet0/0 manage ssh
set interface ethernet0/0 manage telnet
set interface ethernet0/0 manage web
set interface bgroup0 manage mtrace
set interface ethernet0/0 dhcp client enable
set interface bgroup0 dhcp server service
set interface bgroup0 dhcp server auto
set interface bgroup0 dhcp server option domainname  xxxxx
set interface bgroup0 dhcp server option dns1 69.49.X.X 
set interface bgroup0 dhcp server option dns2 72.55.X.X 
set interface bgroup0 dhcp server ip to 
unset interface bgroup0 dhcp server config next-server-ip
set interface "serial0/0" modem settings "USR" init "AT&F"
set interface "serial0/0" modem settings "USR" active
set interface "serial0/0" modem speed 115200
set interface "serial0/0" modem retry 3
set interface "serial0/0" modem interval 10
set interface "serial0/0" modem idle-time 10
set flow tcp-mss
unset flow tcp-syn-check
set domain xxxxxxxxxx
set hostname RMS-FW02
set pki authority default scep mode "auto"
set pki x509 default cert-path partial
set dns host dns1 69.49.X.X src-interface ethernet0/0
set dns host dns2 72.55.X.X src-interface ethernet0/0
set dns host dns3
set dns host schedule 06:28 interval 4
set address "Trust" ""
set ike respond-bad-spi 1
unset ike ikeid-enumeration
unset ike dos-protection
unset ipsec access-session enable
set ipsec access-session maximum 5000
set ipsec access-session upper-threshold 0
set ipsec access-session lower-threshold 0
set ipsec access-session dead-p2-sa-timeout 0
unset ipsec access-session log-error
unset ipsec access-session info-exch-connected
unset ipsec access-session use-error-log
set url protocol websense
set policy id 1 from "Trust" to "Untrust"  "Any" "Any" "ANY" permit log 
set policy id 1
set nsmgmt bulkcli reboot-timeout 60
set ssh version v2
set ssh enable
set config lock timeout 5
set ntp server " "
set ntp server src-interface "ethernet0/0"
set ntp server backup1 " "
set ntp server backup2 ""
set snmp port listen 161
set snmp port trap 162
set vrouter "untrust-vr"
set vrouter "trust-vr"
unset add-default-route
set vrouter "untrust-vr"
set vrouter "trust-vr"

Open in new window

Bob ConklinConfiguration/TEST TechnicianAuthor Commented:
Thank you, I apologize for not formatting it correctly
You only have one policy, Trust to Untrust, allow all. There is nothing for inbound traffic, and hence traffic will only flow if it is initiated from your LAN, and kept active within 30 minutes (the TCP default session timeout for SSG devices).

Please also make sure you have FTP ALG active (in WebUI: Security » ALG).

I'm not sure about the Slingbox, so add a policy Untrust to Trust, permit, for the Sling service you've definded, and with session logging ("at Session Beginning"). Then try access, and monitor the logs of both policies to see the traffic.
Bob ConklinConfiguration/TEST TechnicianAuthor Commented:
Ok, I will try your suggestions, as I recall in the Juniper world best practices dictate the final policy should be from the un-trust to trust with a deny all?
QlemoConnect With a Mentor DeveloperCommented:
Yes, you should have an explicit deny policy as last one for each zone.
Sanga CollinsSystems AdminCommented:
Hi Qlemo, I usually make the last policy global to global:deny all. Is this incorrect or accomplishes the same as explicit policies for each zone?
The reason for separate explicit policies is that you can enable logging and change position in a more specific way.
Sanga CollinsSystems AdminCommented:
Ahh, that makes sense. I normally use NSM so the filters take care of that for me. Sorry for Hijacking the thread.
Bob ConklinConfiguration/TEST TechnicianAuthor Commented:
While I have not been able to actually put into place the expert's suggestions. They did reinforce what I had been taught many years ago but due to centralization I have long since forgotten how to do these things.  I will post additional follow up questions if necessary.
All Courses

From novice to tech pro — start learning today.