Contributor
rutledgeIT
Posts: 26
Registered: 07-23-2009
0

NS5GT - only two zone available for an interface.

Hi

 

I have got NS5GT and created a new zone. I wanted to change ethernet2's zone to new zone but I have only two options there i.e. NULL or DMZ

 

How can I change it?

 

Regards

Rutledge

Super Contributor
arizvi
Posts: 211
Registered: 10-21-2008
0

Re: NS5GT - only two zone available for an interface.

Hi,

 

You change the firewall to combined mode like th following  , but you need unlimited( advance) limited:

 

ns5gt-> get int

A - Active, I - Inactive, U - Up, D - Down, R - Ready

Interfaces in vsys Root:
Name           IP Address                        Zone        MAC            VLAN State VSD     
eth1           192.168.1.1/24                    Work        0010.db74.ed92    -   D   - 
eth2           0.0.0.0/0                         Home        0010.db74.ed97    -   D   - 
eth3           0.0.0.0/0                         Untrust     0010.db74.ed98    -   D   - 
eth4           0.0.0.0/0                         Untrust     0010.db74.ed91    -   D   - 
vlan1          0.0.0.0/0                         VLAN        0010.db74.ed9f    1   D   - 
null           0.0.0.0/0                         Null        N/A               -   U   0 

Super Contributor
arizvi
Posts: 211
Registered: 10-21-2008
0

Re: NS5GT - only two zone available for an interface.

Hi,

 

You change the firewall to combined mode like th following  , but you need unlimited( advance) LICENSE:

 

ns5gt-> get int

A - Active, I - Inactive, U - Up, D - Down, R - Ready

Interfaces in vsys Root:
Name           IP Address                        Zone        MAC            VLAN State VSD     
eth1           192.168.1.1/24                    Work        0010.db74.ed92    -   D   - 
eth2           0.0.0.0/0                         Home        0010.db74.ed97    -   D   - 
eth3           0.0.0.0/0                         Untrust     0010.db74.ed98    -   D   - 
eth4           0.0.0.0/0                         Untrust     0010.db74.ed91    -   D   - 
vlan1          0.0.0.0/0                         VLAN        0010.db74.ed9f    1   D   - 
null           0.0.0.0/0                         Null        N/A               -   U   0 

Contributor
rutledgeIT
Posts: 26
Registered: 07-23-2009
0

Re: NS5GT - only two zone available for an interface.

Sorry Arizvi,

 

I didn't get you. What is combined mode?

 

In my case, ethernet2 has got only two zone options in dropdown box. If I try to set zone to something else via ssh then it says invaild command as I can choose either null or dmz.

 

Can you please exlpain combined mode a bit and how it is helpful in my case?

 

Cheers

Rutledge

Super Contributor
arizvi
Posts: 211
Registered: 10-21-2008
0

Re: NS5GT - only two zone available for an interface.

 

Please follow the KB:

 

http://kb.juniper.net/KB6111

 

http://kb.juniper.net/KB4783

 

http://kb.juniper.net/KB6117

 

 

I hope the above KB would help you.

 

Thnaks

ATif

Contributor
rutledgeIT
Posts: 26
Registered: 07-23-2009
0

Re: NS5GT - only two zone available for an interface.

None of the articles helped me.

 

Is there any other way I can check why do I have only two zones for eth2 in NS5GT?

 

Regards

Rutledge

Super Contributor
arizvi
Posts: 211
Registered: 10-21-2008
0

Re: NS5GT - only two zone available for an interface.

Hi,

 

Can you please past the following data:

1) get sys

2) get int

3) get lic

 

Thanks

Atif

Contributor
rutledgeIT
Posts: 26
Registered: 07-23-2009
0

Re: NS5GT - only two zone available for an interface.

Please check your inbox for password to open attached file.  

 

I had to remove public IPs and MAC addresses for security reasons.

 

Cheers

Rutledge

Super Contributor
arizvi
Posts: 211
Registered: 10-21-2008

Re: NS5GT - only two zone available for an interface.

Hi,

 

you can only used 3 zones and the zones are pre-defined for the interface.

 The zones available are trust , Dmz and 2 untrust zones. Unofrtunately you have to manage your topology between these zones.

 

Ns-5GT do not support custom zones.

 

Thanks

Atif

Kudos appreciated

Contributor
rutledgeIT
Posts: 26
Registered: 07-23-2009

Re: NS5GT - only two zone available for an interface.

Thanks Atif,

 

I understand that I can have only 3 zones. In my case, Eth2 ( which is physically Eth3) is bounded to DMZ. How can I change it to Untrust?

 

Regards

Angad