由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
EmergingNetworking版 - transparant mode in netscreen 5gt
相关主题
netscreen: help!关键词:raw socket, python, sec tunnel, twisted (转载)
Juniper/NetScreen 5GT-WLAN for homeSite-to-Site VPN 路由器的配置是必须的是吧?
问高手们一个cisco问题palo alto networks怎么样啊
现在virtulization似乎很火啊大家可否推荐下vpn solution
[合集] heart attackCisco DMVPN alternative?
Juniper Kills Its Session Controllers and laid off 200问一个ASA的问题。
请教一个VPN的问题cisco to lay off
大牛们推荐个VPN+FIREWALL的路由器吧安全是整个市场最迷惑的板块。
相关话题的讨论汇总
话题: mode话题: arp话题: netscreen话题: 5gt
进入EmergingNetworking版参与讨论
1 (共1页)
l***y
发帖数: 791
1
i just can't see transparant mode as an option on the gui, there are just nat
and route. trying to do it via the cli by setting the ips to be 0.0.0.0 and
setting trust interface to be in zone V1-trust, etc.
m**t
发帖数: 1292
2
what do you mean transparent mode? transport mode or tunnel mode?

nat

【在 l***y 的大作中提到】
: i just can't see transparant mode as an option on the gui, there are just nat
: and route. trying to do it via the cli by setting the ips to be 0.0.0.0 and
: setting trust interface to be in zone V1-trust, etc.

z**r
发帖数: 17771
3
还有interface mode是什么?俺对具体命令也不熟悉,厚厚

l***y
发帖数: 791
4
yes, we've got the full get tech-support output and verified system is in
transparant mode. box is in trust-untrust mode, etc, etc. in utter
motification. just opened a case with juniper. i have a feeling it's some
configuration problem. =/
z**r
发帖数: 17771
5
还有interface mode是什么?俺对具体命令也不熟悉,厚厚



【在 z**r 的大作中提到】
: 还有interface mode是什么?俺对具体命令也不熟悉,厚厚
:
: 必

l***y
发帖数: 791
6
okay, it is official, i'm not a he. :D
z**r
发帖数: 17771
7
why not get a document? it should be a basic issue, do you have juniper.net
account? if no, I can help to download the document, hehe

let
the
flood.
V1-
.
is
康王的仪容,但乘坐的龙辇被黄缦红绫遮挡得严严实实,百姓们其实半点也无法看见。
看来,一行车驾在急急赶路,通知也不及时,百姓们都没被郡中安排做具体的反应。
但车驾排场已经惊骇到了所有人的心,百姓们无不高呼:“我王万岁!”接着比次拜服,
连郡守带领下的小吏们都晚了百姓半分。
谁也没有想到的是,这场宏大的场面在通山公国的贵族后裔子弟姬垩的心上种上了一
句话。通山公国,据说是兽人的杂种,可渐渐却成了中大陆诸国的一部分。姬氏是国中一
姓,族中曾经出过几代名将。靖康取其地后,移民戍出,调当地大族入,这就有了姬族的
今日。
姬垩这年十六岁,正处于一个充满幻想的年代。世家的回顾让他这样的年轻人常以名
门自诩,把威镇列国的西定将军姬羽作为血脉中的因子。他这就这样站在一边看着,突然
有种博钱的

【在 l***y 的大作中提到】
: okay, it is official, i'm not a he. :D
z**r
发帖数: 17771
8
no, he means the layer2 transparent mode, basically, the firewall will
function like a bridge instead of a router.

【在 m**t 的大作中提到】
: what do you mean transparent mode? transport mode or tunnel mode?
:
: nat

l***y
发帖数: 791
9
okay, it is official, i'm not a he. :D
B*****R
发帖数: 1539
10
isn't this the way basic firewall would act like?

.
is

【在 l***y 的大作中提到】
: okay, it is official, i'm not a he. :D
相关主题
Juniper Kills Its Session Controllers and laid off 200关键词:raw socket, python, sec tunnel, twisted (转载)
请教一个VPN的问题Site-to-Site VPN 路由器的配置是必须的是吧?
大牛们推荐个VPN+FIREWALL的路由器吧palo alto networks怎么样啊
进入EmergingNetworking版参与讨论
l***y
发帖数: 791
11
man, i've got the full documentaion CD. we've gone through it multiple times.
hehe
c*a
发帖数: 806
12
good point. Read her original post again, seems that .25 can always ping .26
not vice versa, even by swapping two endpoints to different zones.
I was originally thinking of "unset interface vlan1 bypass-non-ip", but now
looks like .26 is not responding to ping anyway
also she might want to check forwarding table (arp table)

ARP

【在 m**t 的大作中提到】
: what do you mean transparent mode? transport mode or tunnel mode?
:
: nat

l***y
发帖数: 791
13
man, i've got the full documentaion CD. we've gone through it multiple times.
hehe
z**r
发帖数: 17771
14
还有interface mode是什么?俺对具体命令也不熟悉,厚厚



【在 z**r 的大作中提到】
: no, he means the layer2 transparent mode, basically, the firewall will
: function like a bridge instead of a router.

z**r
发帖数: 17771
15
why not get a document? it should be a basic issue, do you have juniper.net
account? if no, I can help to download the document, hehe

let
the
flood.
V1-
.
is
康王的仪容,但乘坐的龙辇被黄缦红绫遮挡得严严实实,百姓们其实半点也无法看见。
看来,一行车驾在急急赶路,通知也不及时,百姓们都没被郡中安排做具体的反应。
但车驾排场已经惊骇到了所有人的心,百姓们无不高呼:“我王万岁!”接着比次拜服,
连郡守带领下的小吏们都晚了百姓半分。
谁也没有想到的是,这场宏大的场面在通山公国的贵族后裔子弟姬垩的心上种上了一
句话。通山公国,据说是兽人的杂种,可渐渐却成了中大陆诸国的一部分。姬氏是国中一
姓,族中曾经出过几代名将。靖康取其地后,移民戍出,调当地大族入,这就有了姬族的
今日。
姬垩这年十六岁,正处于一个充满幻想的年代。世家的回顾让他这样的年轻人常以名
门自诩,把威镇列国的西定将军姬羽作为血脉中的因子。他这就这样站在一边看着,突然
有种博钱的

【在 l***y 的大作中提到】
: man, i've got the full documentaion CD. we've gone through it multiple times.
: hehe

l***y
发帖数: 791
16
it's frustrating. we have pc1(10.1.1.10)- untrust port ------trust port ---
pc2(10.1.1.11),
pc1 can see pc2's arp; pc2 can see pc1's arp. netscreen has both of their arp
entry. however ping is one directional. swapped the port and the ping is still
one directional, and the direction didn't reverse as we thought it would.
swapped pc1 with another pc, same problem. verified both pc aren't running
firewall. the jtac guys said we'd have to do some debug. hopefully this gets
resolved today.
z**r
发帖数: 17771
17
you have the tcpdump output from both pc's?

arp
still

【在 l***y 的大作中提到】
: it's frustrating. we have pc1(10.1.1.10)- untrust port ------trust port ---
: pc2(10.1.1.11),
: pc1 can see pc2's arp; pc2 can see pc1's arp. netscreen has both of their arp
: entry. however ping is one directional. swapped the port and the ping is still
: one directional, and the direction didn't reverse as we thought it would.
: swapped pc1 with another pc, same problem. verified both pc aren't running
: firewall. the jtac guys said we'd have to do some debug. hopefully this gets
: resolved today.

l***y
发帖数: 791
18
okay, it is official, i'm not a he. :D

【在 c*a 的大作中提到】
: good point. Read her original post again, seems that .25 can always ping .26
: not vice versa, even by swapping two endpoints to different zones.
: I was originally thinking of "unset interface vlan1 bypass-non-ip", but now
: looks like .26 is not responding to ping anyway
: also she might want to check forwarding table (arp table)
:
: ARP

z**r
发帖数: 17771
19
no, he means the layer2 transparent mode, basically, the firewall will
function like a bridge instead of a router.

【在 m**t 的大作中提到】
: what do you mean transparent mode? transport mode or tunnel mode?
:
: nat

c*a
发帖数: 806
20
good point. Read her original post again, seems that .25 can always ping .26
not vice versa, even by swapping two endpoints to different zones.
I was originally thinking of "unset interface vlan1 bypass-non-ip", but now
looks like .26 is not responding to ping anyway
also she might want to check forwarding table (arp table)

ARP

【在 m**t 的大作中提到】
: what do you mean transparent mode? transport mode or tunnel mode?
:
: nat

1 (共1页)
进入EmergingNetworking版参与讨论
相关主题
安全是整个市场最迷惑的板块。[合集] heart attack
40/100G Throughput FirewallJuniper Kills Its Session Controllers and laid off 200
有人试过Netscreen 的backdoor么?请教一个VPN的问题
One question about VoIP system!!!!大牛们推荐个VPN+FIREWALL的路由器吧
netscreen: help!关键词:raw socket, python, sec tunnel, twisted (转载)
Juniper/NetScreen 5GT-WLAN for homeSite-to-Site VPN 路由器的配置是必须的是吧?
问高手们一个cisco问题palo alto networks怎么样啊
现在virtulization似乎很火啊大家可否推荐下vpn solution
相关话题的讨论汇总
话题: mode话题: arp话题: netscreen话题: 5gt