Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  polycy order or......?

    Posted 04-09-2014 23:04

    i have a problem when tesing policy on SSG-520M

    i setup 2 policies from trust to untrust,each contains different group of source IP addresses,with logging checked.

    i was stunned by the result that all tracffic went throught 1st policy disregarded source IP,LOG for 2nd policy kept empty.

    as a matter of fact,every PC is able to visit untrust zone whenever i set its GW to this 520M

     

    i guess i must have missed something?

    could anyone here give some hint?



  • 2.  RE: polycy order or......?

     
    Posted 04-09-2014 23:48

    Bit strange, because if a source is not specified in policy then device wont permit that.

     

    Could you please double check the source subnet applied in 1st policy and see if it has a wrong subnet mask which covers  all the hosts hence they are going via 1st policy ?



  • 3.  RE: polycy order or......?

    Posted 04-09-2014 23:51

    ssg20140410.jpgpls pay attention to policy ID3,ip172.20.28.229

     



  • 4.  RE: polycy order or......?

     
    Posted 04-10-2014 00:47

    Could you please share the config



  • 5.  RE: polycy order or......?

    Posted 04-10-2014 01:07

    pls give me your email address



  • 6.  RE: polycy order or......?

     
    Posted 04-10-2014 01:15
    You can either share config here on forum itself.
    Or else you can send me a private message via jnet forum.


  • 7.  RE: polycy order or......?
    Best Answer

     
    Posted 04-10-2014 03:25

    Thanks for sharing the config. I have verified and the issue is due to subnet mask for addresses used in policy 3.

     

    You have used /22 which include all the IPs mentioned in policy 6 as well.

     

    Please update the subnet mask for addresses used in policy 3 and issue should be fixed.

     

     

    Regards

    Sarab

     

    ------------------------------------------------------------------------------------

    [If it helped please mark it as "Accepted Solution". Kudos will be appreciated too.]



  • 8.  RE: polycy order or......?

    Posted 04-14-2014 00:59

    i thought that IP/mask(22)  indicated one IP,but actually it was a segment.

    I need to change all IP setting.

     

    thank you.