Security

last person joined: 2 days ago 

Ask questions and share experiences with Juniper Connected Security. Discuss Advanced Threat Protection, SecIntel, Secure Analytics, Secure Connect, Security Director, and all things related to Juniper security technologies.
  • 1.  L2 zone configuration on NSM

    Posted 11-14-2008 05:22

    Hi,

     

    I'm not sure is this NSM or firewall issue, but I'll try here.

    I've configured wireless and trust interface to use V1-Trust zone, and imported configuration on NSM.

    But when I do Summarize Delta Config od NSM I get this message:

     

    Config on Device but not on NSM:

      set interface wireless2 zone v1-trust

      set interface trust zone v1-trust


    Config on NSM but not on Device:

      set interface wireless2 zone trust

      set interface trust zone trust


    Config on both Device and NSM but reordered:  


    Config to be sent to Device on next Update Device:

      unset interface wireless2 zone

      unset interface trust zone

      set interface wireless2 zone trust

      set interface trust zone trust


    CA Certificate to be removed from Device:

    CRL to be removed from Device:

     

    And when i try to change zone for trust and wireless2 interfaces on NSM,  I cant even find L2 zones?!?!

    I have 2007.3r4  build LGB9z4ag, 1.9_040_61 shema update, and NS5GTwlan 5.4.0r6



  • 2.  RE: L2 zone configuration on NSM

    Posted 12-19-2008 07:37

     

    Hi  kliker,

     

    Within NSM, if you go to the Device Manager-->click on and edit the device in question-->go to "Info" tab - when you see 'Transparent mode', does it say 'true' or not?

     

    Regards,

    Andy



  • 3.  RE: L2 zone configuration on NSM

    Posted 12-22-2008 00:11

    Hi Andy,

     

    It says "false".



  • 4.  RE: L2 zone configuration on NSM
    Best Answer

    Posted 12-22-2008 05:34

     

    Hi Kliker,

     

    Okay, that's the problem then. To fix it, you either need to ensure that the firewall is fully in transparent mode ("get sys" and check that it says transparent mode), or delete the current device in device manager, and recreate it as a modelled device, but clicking the box that says 'transparent mode'.....there's no option within the current device to just switch it to transparent mode unfortunately. Only transparent mode can support L2 zones.

     

    Regards

    Andy