ScreenOS Firewalls (NOT SRX)
Reply
TSG
Contributor
TSG
Posts: 13
Registered: ‎11-24-2009
0
Accepted Solution

DMZ Setup issues

Dear All

 

Im having some issues with my DMZ setup, basically i have configured my lan setup ok.

 

And im now setting up and testing my DMZ.

 

Ive assigned the Address 192.168.200.148/24  to my DMZ port

I have also set up a laptop for testing purposes with the IP 192.168.200.140/24

Ive configured allow all rules in both directions.

 

And have connected the laptop to the DMZ port but I cant even ping the DMZ port address (192.168.200.148) let alone try testing NAT or any advanced rules.

 

Any ideas what i may be missing..?

 

Many Thanks

P

Distinguished Expert
muttbarker
Posts: 2,377
Registered: ‎01-29-2008
0

Re: DMZ Setup issues

OK - Dumb question time - did you configure the DMZ I/F to allow for ping?

Kevin Barker
JNCIP-SEC
JNCIS-ENT, FWV, SSL, WLAN
JNCIA-ER, EX, IDP, UAC, WX
Juniper Networks Certified Instructor
Juniper Networks Ambassador

Juniper Elite Reseller
J-Partner Service Specialist - Implementation

If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.
TSG
Contributor
TSG
Posts: 13
Registered: ‎11-24-2009
0

Re: DMZ Setup issues

[ Edited ]

Rule is set as ANY-ANY alow and enabled for the DMZ

 

Network > Interfaces > list>DMZ>ping box is checked

 

I have no idea why this is failing all in the same network and same subnet....

 

Paul

Trusted Expert
SSHSSH
Posts: 601
Registered: ‎11-21-2009
0

Re: DMZ Setup issues

have you enabled the manageble option  under Network > Interfaces > list>DMZ>

TSG
Contributor
TSG
Posts: 13
Registered: ‎11-24-2009
0

Re: DMZ Setup issues

[ Edited ]

Hi

 

No i haddnt enabled the Management option is that a requirment..?

Trusted Expert
SSHSSH
Posts: 601
Registered: ‎11-21-2009
0

Re: DMZ Setup issues

yes ,  for ex to enable ping on that intarface :

check managable box

check ping

TSG
Contributor
TSG
Posts: 13
Registered: ‎11-24-2009
0

Re: DMZ Setup issues

Hi There,

 

Not sure if you misunderstand but i have a PC connected DIRECTLY to the port, and i cant ping the DMZ address from that PC.

 

Would that be classed as external, every other device ive encountered will ping immediatly when connected in this way.

 

Paul 

Trusted Expert
SSHSSH
Posts: 601
Registered: ‎11-21-2009
0

Re: DMZ Setup issues

Hi TSG

 i 'm just speaking about the following case

"  you are directly connected to the port & cannot ping its ip "

you need to do the following under the interface :

#check the box beside ping

#check the box named manageable beside the ip pf the interface

TSG
Contributor
TSG
Posts: 13
Registered: ‎11-24-2009
0

Re: DMZ Setup issues

Hi There

 

Thanks for claryfying

 

Yes that is my situation.

Yes both of those options are sellected.

 

Still times out..Even tried it with old faithfull X-over cable still nothing.

 

Paul

 

 

Trusted Expert
SSHSSH
Posts: 601
Registered: ‎11-21-2009
0

Re: DMZ Setup issues

ok

can you check if you have permitted ips configured

if permiteed ips confiured , these ips only can access the firewall

check if your configuration have  lines like that :

set admin manager-ip 172.16.40.42/32

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.