<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7239465075038378345</id><updated>2011-07-08T14:33:10.854+01:00</updated><category term='NAT'/><category term='Juniper'/><category term='firewall'/><category term='screenos'/><category term='security'/><category term='netscreen'/><title type='text'>IT Bowl</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://itbowl.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7239465075038378345/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://itbowl.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Sami</name><uri>http://www.blogger.com/profile/16220278599783428465</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7239465075038378345.post-5281977427431734022</id><published>2010-06-28T11:48:00.001+01:00</published><updated>2010-06-28T12:29:45.735+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='netscreen'/><category scheme='http://www.blogger.com/atom/ns#' term='screenos'/><title type='text'>Configuring Routing Between 2 custom VSYS</title><content type='html'>As I really had some difficulty to implement routing between two custom VSYS and didn't found any valuable help on the net, I decided to put here a configuration example for those who may need it. This doesn't mean it's the only or the best way to do it but it does the job. Any comments would be welcome.&lt;br /&gt;&lt;br /&gt;So, we have two subnets, each of them having a custom VSYS on a NS5200 firewall as a gateway. We want to allow any traffic to flow from subnet A (192.168.0.0/24)  to subnet B (192.168.1.0/24) and vice-versa.&lt;br /&gt;&lt;br /&gt;Here are the basic steps:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Root VSYS configuration : As trafic leaving a  a VSYS is considered to have the shared root  "Untrust" zone as destination, we have to put this zone in the  untrust-vr for the routing to take place. The tricky part of the  configuration is a shared interface must exist in the "Untrust" zone to  loop the traffic for intervsys communication. You can create a loopback  interface without assigning it an IP, in which you should disable NAT on  the incoming interface.&lt;/li&gt;&lt;li&gt;Configuring routing in custom VSYSs : After configuring interfaces, the next step is to configure routes. Each  VSYS should route trafic destined to the other subnet through the  shared root virtual router untrust-vr. The untrust-vr should have the  correct routes added.&lt;/li&gt;&lt;li&gt;Configuring policies in custom VSYS : Last thing to do is to configure policies on each VSYS to allow incoming  and outgoing traffic to and from "Untrust" zone.&lt;/li&gt;&lt;/ol&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_swHX6K_5efs/TCh_077IKxI/AAAAAAAAACA/Hx37h4_QRRc/s1600/inter-vsys+routing.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 320px; height: 318px;" src="http://2.bp.blogspot.com/_swHX6K_5efs/TCh_077IKxI/AAAAAAAAACA/Hx37h4_QRRc/s320/inter-vsys+routing.jpg" alt="" id="BLOGGER_PHOTO_ID_5487776693366565650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The detailed configuration commands are listed below:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;##Root VSYS&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set zone "Untrust" vrouter "untrust-vr"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set interface "loopback.1" zone "Untrust"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;##VSYS-A&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set vsys VSYS-A&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set zone name zone-A&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set interface ethernet2/1.100 tag 100 zone zone-A&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set interface ethernet2/1.100 ip 192.168.0.1/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set interface ethernet2/1.100 route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set vrouter "VSYS-A-vr" route 192.168.1.0/24 vrouter untrust-vr&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set vrouter "untrust-vr" route 192.168.0.0/24 vrouter VSYS-A-vr&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set policy from zone-A to Untrust any any any permit log&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set policy from Untrust to zone-A any any any permit log&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;##VSYS-B&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set vsys VSYS-B&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set zone name zone-B&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set interface ethernet2/2.101 tag 101 zone zone-B&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set interface ethernet2/2.101 ip 192.168.1.1/24&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;Set interface ethernet2/2.101 route&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set vrouter "VSYS-B-vr" route 192.168.0.0/24 vrouter untrust-vr&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set vrouter "untrust-vr" route 192.168.1.0/24 vrouter VSYS-B-vr&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set policy from zone-B to Untrust any any any permit log&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;set policy from Untrust to zone-B any any any permit log&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7239465075038378345-5281977427431734022?l=itbowl.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itbowl.blogspot.com/feeds/5281977427431734022/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://itbowl.blogspot.com/2010/06/configuring-routing-between-2-custom.html#comment-form' title='2 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7239465075038378345/posts/default/5281977427431734022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7239465075038378345/posts/default/5281977427431734022'/><link rel='alternate' type='text/html' href='http://itbowl.blogspot.com/2010/06/configuring-routing-between-2-custom.html' title='Configuring Routing Between 2 custom VSYS'/><author><name>Sami</name><uri>http://www.blogger.com/profile/16220278599783428465</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_swHX6K_5efs/TCh_077IKxI/AAAAAAAAACA/Hx37h4_QRRc/s72-c/inter-vsys+routing.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7239465075038378345.post-1691920021687270598</id><published>2010-06-09T01:35:00.000+01:00</published><updated>2010-06-09T01:36:43.566+01:00</updated><title type='text'>Some topics to know in broadband networks</title><content type='html'>PPPoE initiation process&lt;br /&gt;PPP, NCP and LCP&lt;br /&gt;Wholesale model&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7239465075038378345-1691920021687270598?l=itbowl.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itbowl.blogspot.com/feeds/1691920021687270598/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://itbowl.blogspot.com/2010/06/some-topics-to-know-in-broadband.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7239465075038378345/posts/default/1691920021687270598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7239465075038378345/posts/default/1691920021687270598'/><link rel='alternate' type='text/html' href='http://itbowl.blogspot.com/2010/06/some-topics-to-know-in-broadband.html' title='Some topics to know in broadband networks'/><author><name>Sami</name><uri>http://www.blogger.com/profile/16220278599783428465</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7239465075038378345.post-4946643477775281618</id><published>2010-03-01T01:48:00.000+01:00</published><updated>2010-03-01T02:15:51.483+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='NAT'/><category scheme='http://www.blogger.com/atom/ns#' term='firewall'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='Juniper'/><category scheme='http://www.blogger.com/atom/ns#' term='screenos'/><title type='text'>Port mapping/forwarding avec screenos</title><content type='html'>Problème :&lt;br /&gt;J'ai plusieurs serveurs dans mon LAN d'entreprise que je voudrais rendre accessible à partir d'Internet en utilisant une connexion ADSL et un firewall Juniper Networks SSG20. Je dispose d'une seule adresse IP publique attribuée à l'interface ADSL de mon firewall.&lt;br /&gt;&lt;br /&gt;La solution est évidemment de configurer le NPAT afin de translater le couple IP publique/port vers IP privée/port. Le souci est que screenos propose plusieurs manières d'implémenter le NAT des adresses destination, à savoir les policies, les MIP et les VIP; laquelle de ces méthodes choisir ?&lt;br /&gt;Dans ce cas de figure, étant donné que l'adresse publique des serveurs est l'adresse ip de l'interface, la seule solution possible est la création d'une VIP (Virtual IP).&lt;br /&gt;La procédure de configuration est expliquée sur le site de Juniper Networks à cette adresse : &lt;a href="http://kb.juniper.net/KB12608"&gt;http://kb.juniper.net/KB12608&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7239465075038378345-4946643477775281618?l=itbowl.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://itbowl.blogspot.com/feeds/4946643477775281618/comments/default' title='Publier les commentaires'/><link rel='replies' type='text/html' href='http://itbowl.blogspot.com/2010/02/port-mappingforwarding-avec-screenos.html#comment-form' title='0 commentaires'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7239465075038378345/posts/default/4946643477775281618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7239465075038378345/posts/default/4946643477775281618'/><link rel='alternate' type='text/html' href='http://itbowl.blogspot.com/2010/02/port-mappingforwarding-avec-screenos.html' title='Port mapping/forwarding avec screenos'/><author><name>Sami</name><uri>http://www.blogger.com/profile/16220278599783428465</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
