SRX Services Gateway
Highlighted
SRX Services Gateway

Netscreen to SRX policy migration doubt (global to global)

‎05-11-2015 11:56 AM

Hi everybody,

 

I'm new to the security field and I have to migrate a Netscreen cluster to a SRX cluster. I'm writing this post because I have some "global to global" zone policies that I'm not seeing how I can  translate to the new SRX configuration. I used the translation tool but it's not giving me any clue about how to perform the translation. Can you help with this please? Any docs to read, a little guide, anything will be fine for me. 

 

As an example I can show you a policy that is configured on the netscreen device. Here you go:

 

set policy global id 229 name "Policy test" from "Global" to "Global"  "Gi-GGSN" "Gi-GGSN" "ANY" permit log
set policy id 229
set src-address "Net-Vert-1.0"
set src-address "Net-Vert-2"
set src-address "Net-Vert-3"
set src-address "RedesClientes"
set log session-init
exit

 

Thanks in advance.

 

Regards,

 

Luis

2 REPLIES 2
Highlighted
SRX Services Gateway

Re: Netscreen to SRX policy migration doubt (global to global)

‎05-11-2015 05:35 PM

I don't really use global policies so I'm not positive about this.  But I'm pretty sure what you want to use is the junos-global zone which is an SRX default for these policies.

 

You will also need to create the necessary address objects in the address area for this same zone.

 

Understanding Security Zones

 

http://www.juniper.net/techpubs/software/junos-security/junos-security10.1/junos-security-swconfig-s...

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home
Highlighted
SRX Services Gateway

Re: Netscreen to SRX policy migration doubt (global to global)

‎05-12-2015 07:28 AM

Thanks for your reply Spuluka. I will look at the link you sent me. 

 

Regards,

 

Luis