ScreenOS Firewalls (NOT SRX)
Reply
Contributor
faycal
Posts: 50
Registered: ‎11-26-2007
0

Access Problem to HTTP Server in DMZ on SSG320M

Hello;

 

I can't access to  HTTP Server installed in DMZ_vr from Trust_vr

I open a "Any policy" in the two direction but I still have the same problem.
When i bypass the Fierwall (Access directly to the Http Server) it's working fine !!

 

all the other protocols (ssh, ftp) work fine!!

 

As it's the first time we deploy SSG320M, I guess that there is a specific configuration for HTTP trafic or anything else ?

 

Please, did you have any idea regarding this case.

thanks

Super Contributor
sylvain
Posts: 162
Registered: ‎12-20-2007
0

Re: Access Problem to HTTP Server in DMZ on SSG320M

Hi Faycal,

 

Did you set a route beetween your DMZ VR and trust VR ? I suppose yes because everything working for ssh and ftp :-/

Are you using Policy base routing ? It could have a link with your issue ...

 

 

Sylvain

Contributor
faycal
Posts: 50
Registered: ‎11-26-2007
0

Re: Access Problem to HTTP Server in DMZ on SSG320M

Hi Sylvain;

 

All the route exist between the Trust-vr and Dmz_vr, and we can SSH and FTP to it without any problem.

it concerns only the HTTP traffic !!

it seems like the FW block the HTTP trafic.

 

Is there any specific option which must be checked on the SSG320M?

Super Contributor
sylvain
Posts: 162
Registered: ‎12-20-2007
0

Re: Access Problem to HTTP Server in DMZ on SSG320M

Did you set  PBR on this device ? HTTP does not require a "Special" config !

 

Sylvain 

Contributor
faycal
Posts: 50
Registered: ‎11-26-2007
0

Re: Access Problem to HTTP Server in DMZ on SSG320M

Hi;

 

The problem was fixed by changing the value of MTU on the interface of the Web Server (from 1500 to 1200). 
Contributor
frank3427
Posts: 16
Registered: ‎06-10-2008
0

Re: Access Problem to HTTP Server in DMZ on SSG320M

what verions of ScrenOS are you running, I had a similar problem and the resolution was to get a a patched version from JTAC. this is a know issue

 

 

Frank Dias
Contributor
faycal
Posts: 50
Registered: ‎11-26-2007
0

Re: Access Problem to HTTP Server in DMZ on SSG320M

Hi Frank;

i have an SSG320M with SreenOS 6.0.0r4.0

 

is this the version of ScreenOS you used ?

thanks

 

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.