Hi Gourami,
For accessing internet , you need these basic configuration;
1. Interfaces for Untrust and Trust:
set interfaces ge-0/0/2 unit 0 family inet address 192.168.100.1/24
set interfaces ge-0/0/1 unit 0 family inet address 74.XXX.XXX.34/30
2. security Zones
set security zones security-zone Trust interfaces ge-0/0/2.0 host-inbound-traffic system-services all
set security zones security-zone Trust interfaces ge-0/0/2.0 host-inbound-traffic protocols all
set security zones security-zone Untrust interfaces ge-0/0/1.0 host-inbound-traffic system-services all
set security zones security-zone Untrust interfaces ge-0/0/1.0 host-inbound-traffic protocols all
3. Routing:
set routing-options static route 0/0 next-hop 74.XXX.XXX.33
4. Source NAT for Allowing Internet access to Trust subnet:
set security nat source rule-set rs1 from zone Trust
set security nat source rule-set rs1 to zone Untrust
set security nat source rule-set rs1 rule Internet-Trust match destination-address 0.0.0.0/0
set security nat source rule-set rs1 rule Internet-Trust then source-nat interface
5. security policy:
set security policies from-zone Trust to-zone Untrust policy test-policy match source-address any
set security policies from-zone Trust to-zone Untrust policy test-policy match destination-address any
set security policies from-zone Trust to-zone Untrust policy test-policy match application any
set security policies from-zone Trust to-zone Untrust policy test-policy then permit
Regards,
rparthi
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated Too