Netscreen SSG5 Firewall

Posted on 2015-02-19
Last Modified: 2015-03-02
I have been using Netscreen devices at the Enterprise level for a few years but only in the area of editing existing policies created by the corporate gurus of firewalls, which brings me to my question. I have an SSG5 for my home firewall, currently it has only one policy in place. That is to allow any traffic from the untrusted zone to the trusted zone. 2 things are happening that I can't get my head wrapped around. First issue is after 20 days or so, FTP traffic will cease to flow out bound. I get a time out error. The fix seems to be to reset the SSG5 and all is well again. Second is that TCP port 5001 traffic is being blocked somehow and I am not sure why. I admit to being new at creating the policies and I am looking for some guidance.
Question by:Bob Conklin
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
  • 4
LVL 70

Expert Comment

ID: 40619676
The FTP issue sounds like a bug, not cleaning the firewalls session table from old connections. Check if you can get a more recent firmware.
In regard of port 5001, is that outbound or inbound?

Author Comment

by:Bob Conklin
ID: 40619729
The firmware is at the last version supported by Juniper, the 5001 traffic is used to access a Slingbox streaming system. From what I gather at Slingbox support, it is an inbound request to the box to open a session to the client system.
LVL 18

Expert Comment

by:Sanga Collins
ID: 40619743
Normally SSG devices block all traffic by default. Having just one policy from untrust to trust seems strange since you would not be able to send any traffic outbound.

2nd point is a policy from untrusted to trusted will not work unless you have a mapped ip (MIP) or virtual ip (VIP). inbound traffic will not actually reach any device on your network with just this policy.

For the outbound FTP traffic. You should have a policy from trust zone to untrust, can you paste that here so we can take a look at it? And for the port 5001 being blocked, is this inbound or outbound? That will help determine where to trouble shoot.
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!


Author Comment

by:Bob Conklin
ID: 40619759
I was taught that too, all traffic is blocked and you have to allow what you want. I will post what is currently on the system when I get home tonight. I currently do not have remote access to the device enabled.
LVL 18

Expert Comment

by:Sanga Collins
ID: 40619764
not a problem, We are here to assist so whenever you get a chance.

Author Comment

by:Bob Conklin
ID: 40621007
Here is the current config file from the my SSG5: (Public IPs edited)
set clock ntp
set clock timezone -5
set vrouter trust-vr sharable
set vrouter "untrust-vr"
set vrouter "trust-vr"
unset auto-route-export
set service "Sling" protocol tcp src-port 5000-5001 dst-port 5000-5001 
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"
set auth radius accounting port 1646
set admin auth timeout 10
set admin auth server "Local"
set admin format dos
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "DMZ" vrouter "trust-vr"
set zone "VLAN" vrouter "trust-vr"
set zone "Untrust-Tun" vrouter "trust-vr"
set zone "Trust" tcp-rst 
set zone "Untrust" block 
unset zone "Untrust" tcp-rst 
set zone "DMZ" tcp-rst 
set zone "VLAN" block 
unset zone "VLAN" tcp-rst 
set zone "Untrust" screen icmp-flood
set zone "Untrust" screen udp-flood
set zone "Untrust" screen winnuke
set zone "Untrust" screen port-scan
set zone "Untrust" screen ip-sweep
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ip-spoofing
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "Untrust" screen tcp-no-flag
set zone "Untrust" screen unknown-protocol
set zone "Untrust" screen ip-bad-option
set zone "Untrust" screen fin-no-ack
set zone "Untrust" screen block-frag
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
set interface "ethernet0/0" zone "Untrust"
set interface "ethernet0/1" zone "Null"
set interface "bgroup0" zone "Trust"
set interface bgroup0 port ethernet0/2
set interface bgroup0 port ethernet0/3
set interface bgroup0 port ethernet0/4
set interface bgroup0 port ethernet0/5
set interface bgroup0 port ethernet0/6
unset interface vlan1 ip
set interface ethernet0/0 ip 72.12.X.X/22
set interface ethernet0/0 route
set interface bgroup0 ip
set interface bgroup0 nat
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface ethernet0/0 ip manageable
set interface bgroup0 ip manageable
set interface ethernet0/0 manage ping
set interface ethernet0/0 manage ssh
set interface ethernet0/0 manage telnet
set interface ethernet0/0 manage web
set interface bgroup0 manage mtrace
set interface ethernet0/0 dhcp client enable
set interface bgroup0 dhcp server service
set interface bgroup0 dhcp server auto
set interface bgroup0 dhcp server option domainname  xxxxx
set interface bgroup0 dhcp server option dns1 69.49.X.X 
set interface bgroup0 dhcp server option dns2 72.55.X.X 
set interface bgroup0 dhcp server ip to 
unset interface bgroup0 dhcp server config next-server-ip
set interface "serial0/0" modem settings "USR" init "AT&F"
set interface "serial0/0" modem settings "USR" active
set interface "serial0/0" modem speed 115200
set interface "serial0/0" modem retry 3
set interface "serial0/0" modem interval 10
set interface "serial0/0" modem idle-time 10
set flow tcp-mss
unset flow tcp-syn-check
set domain xxxxxxxxxx
set hostname RMS-FW02
set pki authority default scep mode "auto"
set pki x509 default cert-path partial
set dns host dns1 69.49.X.X src-interface ethernet0/0
set dns host dns2 72.55.X.X src-interface ethernet0/0
set dns host dns3
set dns host schedule 06:28 interval 4
set address "Trust" ""
set ike respond-bad-spi 1
unset ike ikeid-enumeration
unset ike dos-protection
unset ipsec access-session enable
set ipsec access-session maximum 5000
set ipsec access-session upper-threshold 0
set ipsec access-session lower-threshold 0
set ipsec access-session dead-p2-sa-timeout 0
unset ipsec access-session log-error
unset ipsec access-session info-exch-connected
unset ipsec access-session use-error-log
set url protocol websense
set policy id 1 from "Trust" to "Untrust"  "Any" "Any" "ANY" permit log 
set policy id 1
set nsmgmt bulkcli reboot-timeout 60
set ssh version v2
set ssh enable
set config lock timeout 5
set ntp server " "
set ntp server src-interface "ethernet0/0"
set ntp server backup1 " "
set ntp server backup2 ""
set snmp port listen 161
set snmp port trap 162
set vrouter "untrust-vr"
set vrouter "trust-vr"
unset add-default-route
set vrouter "untrust-vr"
set vrouter "trust-vr"

Open in new window


Author Comment

by:Bob Conklin
ID: 40621070
Thank you, I apologize for not formatting it correctly
LVL 70

Expert Comment

ID: 40621110
You only have one policy, Trust to Untrust, allow all. There is nothing for inbound traffic, and hence traffic will only flow if it is initiated from your LAN, and kept active within 30 minutes (the TCP default session timeout for SSG devices).

Please also make sure you have FTP ALG active (in WebUI: Security » ALG).

I'm not sure about the Slingbox, so add a policy Untrust to Trust, permit, for the Sling service you've definded, and with session logging ("at Session Beginning"). Then try access, and monitor the logs of both policies to see the traffic.
LVL 18

Accepted Solution

Sanga Collins earned 350 total points
ID: 40621118
For the port 5000-5001 traffic you will need to create a MIP or VIP that basically maps your public IP address to the device that will be receiving the traffic. Then you need to create an untrust to trust policy with the MIP/VIP as the destination to allow that traffic through the firewall.

If you do not have a block of public IP's a VIP will be the best course of action. The juniper KB has a great article with steps for creating one.

bookmark, It has great articles on how to do almost anything on their devices with pictures good descriptions and accounts for variables in different setups.

Author Comment

by:Bob Conklin
ID: 40626391
Ok, I will try your suggestions, as I recall in the Juniper world best practices dictate the final policy should be from the un-trust to trust with a deny all?
LVL 70

Assisted Solution

Qlemo earned 150 total points
ID: 40626417
Yes, you should have an explicit deny policy as last one for each zone.
LVL 18

Expert Comment

by:Sanga Collins
ID: 40626617
Hi Qlemo, I usually make the last policy global to global:deny all. Is this incorrect or accomplishes the same as explicit policies for each zone?
LVL 70

Expert Comment

ID: 40626639
The reason for separate explicit policies is that you can enable logging and change position in a more specific way.
LVL 18

Expert Comment

by:Sanga Collins
ID: 40626652
Ahh, that makes sense. I normally use NSM so the filters take care of that for me. Sorry for Hijacking the thread.

Author Closing Comment

by:Bob Conklin
ID: 40640305
While I have not been able to actually put into place the expert's suggestions. They did reinforce what I had been taught many years ago but due to centralization I have long since forgotten how to do these things.  I will post additional follow up questions if necessary.

Featured Post

Are You Headed to Black Hat USA 2017?

Getting ready for Black Hat next week? Kick things off with the WatchGuard Badge Challenge and test your puzzle and cipher skills. Do you have what it takes to earn our limited edition Firebox Badge? Get started today -

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Large and small networks have one same need, Service monitoring. Service monitoring consists of watch services of the several servers in the network. To monitor means that the administrator will receive an alert when a service is down or it's state …
Network ports are the threads that hold network communication together. They are an essential part of networking that can be easily ignore or misunderstood, my goals is to show those who don't have a strong network foundation how network ports opera…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
Suggested Courses

631 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question