ScreenOS Firewalls (NOT SRX)
Reply
Visitor
chmod
Posts: 7
Registered: ‎05-26-2012
0
Accepted Solution

RESOLVED: SSG 5 as replacement for 5GT not working

[ Edited ]

Hello.

 

Struggling - actually fully in the weeds - attempting to get this replacement firewall to work. I

 

'll attach the new SSG5 .cfg file and the one from the existing 5GT which works fine. I have been preening this file compared to the 5GT, using gateway addresses, etc. and I am aware of interface naming changes, etc., to no avail.  

 

I need fresh eyes on this, please. I'm connecting to a 6MB DSL line from DSL Extreme, if that matters.

 

The issue: when connected fully to my LAN, or even singularly via ethernet 0/2, I cannot get "out". DNS fails, clearly it isn't happening. I have defaulted this device multiple times, using the Wizard as well as manual entry. 

 

thanks

Trusted Expert
sarab
Posts: 354
Registered: ‎05-12-2012
0

Re: SSG 5 as replacement for 5GT not working

As you mentioned the DNS fails, I could see the following difference in DNS config:

 

set interface trust dhcp server option dns2 216.146.35.35
set interface trust dhcp server option dns3 208.67.222.222

 

The above two DNS IPs are missing from SSG 5's DHCP config. So please try including these as well.

 

Few other things that you could test are :

 

1. Try pinging gateway from the firewall.

2. Try pining DNS server IPs you see on the LAN Machines to verify the connectivity.

 

Sarab [ JNCIS-FWV , JNCIA-SEC , CCIP , CCSA ]
------------------------------------------------------------------------------------

[If it helped please mark it as "Accepted Solution". Kudos will be appreciated too.]

Super Contributor
lanman
Posts: 68
Registered: ‎11-27-2010
0

Re: SSG 5 as replacement for 5GT not working

I don't see any routes defined, but you have defined a gateway on the untrust interface. Check if there is a route to 0.0.0.0 in your destination routing table. If there isn't, just add it as described here:

 

KB5712

 

Steve

 

Visitor
chmod
Posts: 7
Registered: ‎05-26-2012
0

Re: SSG 5 as replacement for 5GT not working

This had no impact. Still cannot poing or get out to Internet.

Visitor
chmod
Posts: 7
Registered: ‎05-26-2012
0

Re: SSG 5 as replacement for 5GT not working

Hello.

 

There is a route according the the web GUI, please see attached. I just took another snap of the .cfg.

 

I cannot ping anything outsiude of my LAN with the new SSG 5 in place. I drop the 5GT back in and it all works.

 

 

Visitor
chmod
Posts: 7
Registered: ‎05-26-2012
0

Re: SSG 5 as replacement for 5GT not working

I attach the most recent .cfg.

 

What am I missing? Other than the change in symantics between the two firewalls (no longer using trust and untrust in the actual configuration files) these are not grossly different.

 

I am running the latest version of the OS....ssG5ssG20.6.3.0r11.0

 

Is there some exotic order these commands must use in order to make it wwork?

 

I see a route defined in the web GUI that is exactly a duplicate of the existing 5GT.

 

?

 

Trusted Expert
sarab
Posts: 354
Registered: ‎05-12-2012
0

Re: SSG 5 as replacement for 5GT not working

Cud u pls try pinging ur gateway from firewall itself. If this is not pinging then pls try to clear arp on upstream device. As it might hv previous cached mac.
Visitor
chmod
Posts: 7
Registered: ‎05-26-2012
0

Re: SSG 5 as replacement for 5GT not working

OK, I did what you requested and no, I cannot ping the ISP's gateway from a telnet session on the SSG5.

 

With the 5GT in place, it pings properly.

 

As I am dealing with an ISP, I have no access to their system admins to request an ARP cache flush. Are you telling me this is the only solution?

 

 

 

Super Contributor
lanman
Posts: 68
Registered: ‎11-27-2010
0

Re: SSG 5 as replacement for 5GT not working

Looking at the screenshot of the routing table I noticed the the default route (0.0.0.0) isn't active. Also the routes on the untrust interface are inactive. Are you sure the ethernet0/0 interface is up?

 

Steve

 

Visitor
chmod
Posts: 7
Registered: ‎05-26-2012
0

Re: SSG 5 as replacement for 5GT not working

Yes, I took those shots with the device offline.

 

When connected they are all up.

 

I am pretty sure the issue is as the Juniper employee said - my ISP (like many) caches MAC addresses.

 

So I must wait out the DHCP lease (60 minutes) and then, as the MAXC will be different, I'll get a new lease with a new IP.

 

Right now, I can conect but as the MAC is different their server will not issue a new DHCP lease.

 

Stand by. Thank yu for your reply.

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.