SSL VPN
Reply
Visitor
gabox
Posts: 5
Registered: ‎04-12-2010
0

2nd opinion about scenario on MAG4610 ?

Hi Team. I want to ask you about 2 scenarios. I have a Juniper Netscreen plus one MAG 4610 SA mode. I have not enough experience in how configure fw in transparent mode. My doubt is which scenario is better ?

 

thanks in advance.

Moderator
zanyterp
Posts: 2,274
Registered: ‎11-19-2007
0

Re: 2nd opinion about scenario on MAG4610 ?

what is transparent mode? probably the L3 scenario

Visitor
gabox
Posts: 5
Registered: ‎04-12-2010
0

Re: 2nd opinion about scenario on MAG4610 ?

Thanks for your Answer. Could you explain me, why you chose layer 3 ?

 

 

Moderator Moderator
Moderator
AJA
Posts: 130
Registered: ‎05-07-2010
0

Re: 2nd opinion about scenario on MAG4610 ?

Please read the admin guide which will help you in the SA deployment.

 

There are 2 modes - single arm and double arm mode.

Contributor
ed_gpc
Posts: 194
Registered: ‎09-21-2010
0

Re: 2nd opinion about scenario on MAG4610 ?

Transparent mode on screenos is L2 firewall

Moderator
zanyterp
Posts: 2,274
Registered: ‎11-19-2007
0

Re: 2nd opinion about scenario on MAG4610 ?

I went with L3 as I am not familiar with L2 details.
Visitor
gabox
Posts: 5
Registered: ‎04-12-2010
0

Re: 2nd opinion about scenario on MAG4610 ?

Thanks a lot for yours answer.

 

-Zany, Could you show me your scenario ? and if is it possible basic config ?

 

regards.

Recognized Expert
jayLaiz
Posts: 415
Registered: ‎11-25-2009
0

Re: 2nd opinion about scenario on MAG4610 ?

Hi,

 

The L3 config is what I would recommend, you can connect the dmz port of your firewall to the external intreface of the Juniper SA ands do a one-one NAT to NAT a public IP to the IP assigned to the external interface of the JUniper SA, users will be connecting to the SA using that public IP from the outside.You need to allow port 443 inbound to the extrenal interface of the Juniper SA and also port 4500 udp if you want to use ESP as the transport mode for network connect Users.The internal Port of the SA can be connected to the internal network(There would be no one-one NAT required here)

 

Regards,

Jay

Visitor
gabox
Posts: 5
Registered: ‎04-12-2010
0

Re: 2nd opinion about scenario on MAG4610 ?

ok, thanks a lot! i test all suggestion.

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.