No access to CLI



  • I don’t have access to the CLI and was just wondering whether I would be able to do all these actions via the webgui ?

    http://kb.juniper.net/index?page=content&id=KB9924&actp=LIST

    The example isn’t very clear ? A picture showing the setup would’ve been good !

    Just wondering ? Can someone please confirm…
    25.34.5.7 = fixed ip of client outside firewall ?
    4.4.4.10 is the MIP. public ip ?
    is 20.20.20.5 the ip of the firewall ? or the internal ip ?

    set interface tunnel.1 zone Untrust-Tun
    --------- Untrust-Tun is the Tunnel type zone, carrier zone that helps encryption-decryption

    set interface tunnel.1 ip 4.4.4.10/24
    --------- Fixed IP on the tunnel interface

    Not sure whether the 2 set interfaces commands are 1 or 2 steps ? First step looks like
    Network --> Interfaces --> New (Tunnel IF)
    Should it be Fixed IP or Unnumbered ?

    And would I be able to set 1 ip address with subnet 32 instead of 24 ?

    set interface tunnel.1 mip 4.4.4.10 host 20.20.20.5 netmask 255.255.255.255
    ---------- MIP will be used by the cisco-remote network to connect to server behind the Juniper firewall’s local network

    set route 25.34.5.7 interface tunnel.1
    ---------- A route needs to be added to send the traffic to the tunnel interface

    Question, how can you redirect only certain Dial-Up VPN to a certain IP ?

    set ike gateway Netscreen-Cisco-IKE address 25.34.5.7 main outgoing-interface ethernet4 preshare test sec-level standard
    --------- Phase 1 configuration

    set vpn Netscreen-Cisco-VPN gateway Netscreen-Cisco-IKE sec-level standard
    --------- Phase 2 configuration

    set vpn Netscreen-Cisco-VPN bind zone Untrust-Tun
    --------- Bind Tunnel Zone (Juniper firewall will recognize the MIP configured on the tunnel interface)

    set policy from untrust to trust 25.34.5.7/32 MIP (4.4.4.10) any tunnel vpn Netscreen-Cisco-VPN log
    set policy from trust to untrust 20.20.20.5/32 25.34.5.7/32 any tunnel vpn Netscreen-Cisco-VPN log


 

26
Online

38.4k
Users

12.7k
Topics

44.5k
Posts