SRX

last person joined: 2 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  fxp0 interface should be accessed through SSH/HTTPS only

    Posted 05-04-2012 05:34

    Hi

     

    I have SRX3600 cluster. My requirement is that fxp0 interfaces should be accessed through SSH and HTTPS only. Can I put the fxp0 interface in some functional zone and enable the SSH/HTTPS services on that zone OR no need to put the fxp0 interface in functional zone, just enabling the HTTP/SSH only in system services is enough?

     

    Thanks for the input



  • 2.  RE: fxp0 interface should be accessed through SSH/HTTPS only

    Posted 05-04-2012 05:53
    fxp0 interface is outside the scope of security daemon(flow module) . We can not associate fxp0 with any zone . Just enabling required system services like ssh/https globally will work . No need of functional zone and corresponding host-inbound-traffic system-services settings .


  • 3.  RE: fxp0 interface should be accessed through SSH/HTTPS only

    Posted 05-04-2012 07:46

    Thanks Pradeep. But If I have SRX650 cluster then in this case also I do not need to put the fxp0 interface in functional zone?

     

    Thanks



  • 4.  RE: fxp0 interface should be accessed through SSH/HTTPS only
    Best Answer

    Posted 05-04-2012 08:36
    Its the same for SRX Branch as well as High-end platforms . No need of functional zones for fxp0 interface .


  • 5.  RE: fxp0 interface should be accessed through SSH/HTTPS only

    Posted 05-09-2012 06:51

    Hi All,

    Longing to ask a few questions about the SRX series gateway hopefully will get some answers over here

     

    Doubts :

     

    1. Can we increase the bandwidth of the internal interface joining RE and PFE or it is the same for all the device models or does it vary from model to model . I suppose that the bandwidth is 100 mbps as per juniper datasheets. Correct me if i am wrong

     

    2. Do we have any limit on the number of  terms i can define with in a routing policy and a firewall filter?

     

    3. What is the default interface mtu size in junos platforms?

     

    4. Maximum number of VLAN's that can be created on a physical interface ? Is it the 4096 or 1024 in Junos?

     

    5. The switch which is connected to the 2 physical interfaces , which are combined together to form a Reth interface should it necessarily be a L2 switch or an L3 switch will also do the same functionality?

     

    6. When i use Radius server in my authentication order , do i still need to have users mapped in my device? If yes how do i map only the usernames , because anyways authorization is already defined on the radius server

     

    7.In Firewall Authentication, lets say there is a NAT enabled device before the firewall , once the user who has the right credential gets authenticated subsequently all the users will be given access to my server because authentication table entry is stored based on the ip address and not usernames. So how do i restrict that other users who dont have the credentials without accessing my server?

     

    8. Shoud i use application as telnet , ftp and http in the security policy when i am using pass through authentication? Because pass through supports only ftp,http and telnet traffic?

     

    9. Can we use the primary interface ip address as the web authentication ip address or is it mandatory that we define one more ip address on the interface as web auth ip

     

    10. When is a real time scenario that we have 2 ip address defined on the interface and both being actually used?

     

    NAT questions : 

     

    11. How many actual translations can we have with 1 public IP when i disable PAT ?

     

    12. What does this actually mean D-NAT will generate allow incoming packets for voip algs?

     

    13. Can we use the same ip for S NAT and D NAT then wat is the use of static NAT?

     

    14. When we r doing Static NAT , can we have both the internal and external communication happen at the same time , because  there can be only one translation per one public IP when i disable PAT?

     

    15. In source NAT with address shifting , the user will bind private IP range to public ip range . 

     

    Lets imagine my private range starts from 10.1.10.5 to 10.1.10.254

    My public pool is from 100.1.1.1 to 100.1.1.200

     

    I map my private base address to public address from 10.1.10.5 to 100.1.1.1

    So lets say 10.1.10.5 gets translated to 100.1.1.1

     

    What happens if 10.1.10.7 intiates a session before 10.1.10.6 will he be assigned 100.1.1.3 or 100.1.1.2



  • 6.  RE: fxp0 interface should be accessed through SSH/HTTPS only

    Posted 05-10-2012 00:14

    Thanks Pradeep