08-12-2009 11:09 PM
Hermes,
Can I see you security stanza also?
08-13-2009 05:25 AM
currently I have this:
security {
zones {
security-zone Trust {
address-book {
address Address_10.2.0.0_16 10.2.0.0/16;
address-set Core {
address Address_10.2.0.0_16;
}
}
host-inbound-traffic {
system-services {
all;
}
}
interfaces {
ge-2/0/7.0;
}
}
security-zone Internet-Untrust {
host-inbound-traffic {
system-services {
ping;
}
}
interfaces {
ge-2/0/3.0;
}
}
security-zone DMZ-Untrust {
host-inbound-traffic {
system-services {
ping;
}
}
interfaces {
ae0.0;
}
}
}
policies {
default-policy {
permit-all;
}
}
}