ScreenOS Firewalls (NOT SRX)
Reply
Distinguished Expert
spuluka
Posts: 2,235
Registered: ‎03-30-2009
0

Re: Traversing subnets from one netscreen ns5gt to another

The policy is what has the mip in use.  To rebuild you'll need to remove the policy first.

Steve Puluka BSEET
Juniper Ambassador
Senior Network Engineer - UPMC Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC
JNCIS-FWV JNCIS-SSL
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home
Contributor
it@shiftwise
Posts: 15
Registered: ‎07-09-2010
0

Re: Traversing subnets from one netscreen ns5gt to another

Hey there.

 

Finally getting back to this.  After some further research I see that the NetScreen log shows entries for Close reason :  Close - TCP Fin.  On the client I get errors 800 and 721.  Research indicates that this is the result of the firewall not allowing GRE protocoal traffic on 47 and TCP traffic on 1723.

 

For the record I spoke with a Juniper tech support rep earlier who helped me with this.  It was not til after I hung up that I did some more research and suspect the firewall is the problem and the RRAS server.  The ticket # is 201011010644.

 

Do I open those ports from the policy that relates to the MIP or do I it globally?  How do I verify the correct ports are open?

Contributor
it@shiftwise
Posts: 15
Registered: ‎07-09-2010
0

Re: Traversing subnets from one netscreen ns5gt to another

I went into the Policy and ensured GRE, PPTP, and TCP all were allowed.  I tried to connect again and instead a new close reason of Close - TCP RST from 2 different services, SQL*NET V2 and PPTP.  Research on Juniper forums indicates that 

Dsabling SQL ALG  may  solve the issue

 

FW> get alg  ( to see the list of ALGs )

 

FW> unset alg SQL enable

FW > save

 

This is from post http://communities.juniper.net/t5/ScreenOS-Firewalls-NOT-SRX/Close-Reason-Close-TCP-RST/td-p/43003

 

Thoughts?

Distinguished Expert
spuluka
Posts: 2,235
Registered: ‎03-30-2009
0

Re: Traversing subnets from one netscreen ns5gt to another

It does sound like you are hitting the alg by accident.  The log message is saying that the traffic is being identified by the firewall as meeting that profile.  If it is really not sql alg traffic this will cause problems so you can disable the alg to let the traffic pass unprocessed.

Steve Puluka BSEET
Juniper Ambassador
Senior Network Engineer - UPMC Pittsburgh, PA
JNCIA-ER JNCIA-EX JNCIS-SEC JNCIP-SEC
JNCIS-FWV JNCIS-SSL
MCP - Managing Server 2003 MCP - Windows XP Professional
MCTS Windows 7
http://puluka.com/home
Contributor
it@shiftwise
Posts: 15
Registered: ‎07-09-2010
0

Re: Traversing subnets from one netscreen ns5gt to another

The actual problem was in the policy set up for the MIP that would allow VPN traffic for GRE and PPTP traffic.  In the setting for the policy the Application field needed to be set to IGNORE

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.