SRX Services Gateway
Highlighted
SRX Services Gateway

Inband web-management SRX-1500

‎03-13-2018 02:29 AM

Hi dear everybody,

i'm trying to manage my SRX 1500 cluster in GUI via 2 interfaces (loopback and reth1.1) but i can't. I can access it via the management interface (fxp0)

This is the configuration. Am i missing something? Thanks in advance for your help

 

root@nrsvdrsrx-a0a-core01# show system services
ssh {
authentication-order [ radius password ];
root-login allow;
}
web-management {
https {
system-generated-certificate;
interface [ fxp0.0 lo0.0 reth1.1 ];

 

 

root@nrsvdrsrx-a0a-core01# show security zones security-zone XXX
interfaces {
reth1.1 {
host-inbound-traffic {
system-services {
all;

 

lo0.0 {
host-inbound-traffic {
system-services {
https;
ssh;
ping;
}
}
}

5 REPLIES
SRX Services Gateway

Re: Inband web-management SRX-1500

‎03-15-2018 12:23 AM

Whats the error you are getting on brwoser?  Can you also share "root> show log httpd.log |no-more " 

you may also try "root> restart web-management"

Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too
SRX Services Gateway

Re: Inband web-management SRX-1500

‎07-08-2018 03:12 PM

Hi Suraj,

Sorry sorry for my silence. i did not work on my project for a time.

i have restarted the web-management process

Find attached my configuration file and the results of log httpd.

I can web manage via the lo0 if i don't specify any interface in system services. If i specify interfaces (fxp0.0, lo0, ge-0/0/0.10), i can access via all interfaces specified except the lo0 and when i check the http log, i never see the lo interface working or not working.

The error message when i specify the interface => when i type the url (https://172.28.128.7) i have the warning message about the certificate since it is self generated and when i accept, the next page is "sorry we can access the page". 

https://172.28.128.7/servererror.php?code=401

 

Againt thanks in advance for your help!

Kindly yours,

Vanessa

 

Attachments

SRX Services Gateway

Re: Inband web-management SRX-1500

‎07-08-2018 03:14 PM

The config file

Attachments

SRX Services Gateway

Re: Inband web-management SRX-1500

‎07-09-2018 02:42 PM

Hi Suraj,

I think i finally got it!

Because i'm not coming from the same subnet as my target interface, i have to open also web-management to the interface i'm coming from. Is it right? Anyway, that's how it works for me. If right, then i have to block management traffic towards the unwanted interface with firewall filter, right?

Again thanks for your help!

Regards,

Vanessa

SRX Services Gateway

Re: Inband web-management SRX-1500

‎07-11-2018 09:27 PM

Glad to know issue is fixed and thanks for sharing the details, it will help other users Smiley Happy

Thanks,
Suraj
Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too