ScreenOS Firewalls (NOT SRX)
Reply
Visitor
jimmyjames
Posts: 8
Registered: ‎12-03-2010
0

Re: Juniper SSG5 - ICW Help

Hey Spuluka

 

I'm not so good with command line, so I might see if I can download and install version 6 software and then get back to you if i get stuck :smileyhappy:

Visitor
jimmyjames
Posts: 8
Registered: ‎12-03-2010
0

Re: Juniper SSG5 - ICW Help

Hey Spuluka

 

I've updated to version 6.3 software which I believe is the lastest but I still don't get those options to change the nat route and policy. Quite strange!

 

So this means I might have to do it by command line! 
To run those commands, do I need to connect the Juniper by console to the serial port of my PC?

 

 

Distinguished Expert
spuluka
Posts: 2,566
Registered: ‎03-30-2009
0

Re: Juniper SSG5 - ICW Help

The cli is availabe from the console or by logging in with ssh or telnet to the trust interface setup for management using the same user/password as the web site.

 

I've attached screen shots of the areas in the interface for the web.  The nat/route selection is a section nearer the top of the interace page.  While the policy advancded button is on the very bottom of the policy edit page.

Steve Puluka BSEET
Juniper Ambassador
Senior Network Engineer - UPMC Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC
JNCIS-FWV JNCIS-SSL
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home
Visitor
jimmyjames
Posts: 8
Registered: ‎12-03-2010
0

Re: Juniper SSG5 - ICW Help

Hey spuluka

 

I'll try the cli config tonight.

I had a look at those images and I definately don't have those as an option.


Here are screenshots of my web config interface for those sections. The first image includes the firmware revision 6.3.

webconfig - main page

interface list

edit properties for eth0/0

 

Let me know if you can't view those images.

 

Regards

JimmyJames

Distinguished Expert
spuluka
Posts: 2,566
Registered: ‎03-30-2009
0

Re: Juniper SSG5 - ICW Help

Well I can see the images just fine and am confused.  It is clearly missing the one section.  I only have 6.3 deployed in a test location as 6.2 is still the JTAC recommendation.  But I have this section on that device.

 

Hopefully, the cli works for you.

Steve Puluka BSEET
Juniper Ambassador
Senior Network Engineer - UPMC Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC
JNCIS-FWV JNCIS-SSL
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home
Distinguished Expert
echidov
Posts: 858
Registered: ‎11-02-2009
0

Re: Juniper SSG5 - ICW Help

Hi Jimmy

 

You should configure an interface IP first and apply this change. After that you will be able to change the interface mode (route/NAT).  ScreenOS UI is very intelligent and flexible. All user inputs are analized, the changes that make no sense are blocked, many input fileds do not appear if certain settings are not configured yet.

Kind regards,
Edouard
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.