Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  Block inbound traffic

    Posted 03-18-2009 05:31

    Dear All,

     

    We have a juniper Netscreen 50 firewall configured in the transparent mode on top of ISA server. All the user has given access in the ISA server for browsing and only ISA server is allowed in the firewall for all outbound traffic.

     

    My question here is , how to create policies to control inbound connections? Some users in our office are connecting their office PC's from outside through some software. How to block such connection? i want to block all the listening ports except their browsing, how it is possible? any ideas? where can i configure this ? in ISA server or in NetScreen 50 firewall?

     

     

     

    Regards

     

    Abdul Rahuman.M



  • 2.  RE: Block inbound traffic
    Best Answer

    Posted 03-18-2009 05:49
    I'd do both. Create inbound services on the isa and write inbound policies from v1-untrust to v1-trust allowing the services you want on the Juniper device.