Re: External management on a netscreen-5

From: AM (arj.mahal_at_askarj.com)
Date: 05/27/05

  • Next message: Spack: "Re: what are 'host -based' vs OS-based firewalls?"
    Date: 27 May 2005 01:26:22 -0700
    
    

    If you have one external address,, externally, you can only manage the
    firewall on the same IP address as the external interface. Set the
    Manage-IP address to be 0.0.0.0 - (it defaults to the same IP as the
    untrust interface). Then enable ssh and web etc. Note however, that
    web and telnet are clear text so the admin login userid password and
    configuration changes are not encrypted, so not really meant for
    external connections. You should use ssh or ssl communications for the
    encrypted equivalent.

    Also have a look under admin, management and permitted IPs list. This
    allows you to restrict by source IP who can connect to manage the
    firewall in the first place. Remember to firstly add your internal
    IP/range othewise you may lock yourself out.

    Hope this is helpful.

    AM
    http://www.askarj.com


  • Next message: Spack: "Re: what are 'host -based' vs OS-based firewalls?"

    Relevant Pages

    • Re: Company Firewalls IP Address
      ... At the routing level packets will ALWAYS go to the next-hop which may ... The firewall translates this into and Externally ... routable IP address which lives on the external interface of the firewall. ... > The packets do not have to go directly to the source IP. ...
      (Security-Basics)
    • Re: Editing Windows firewall ruleset for 2003 Std ?
      ... > This works perfectly until I turn on the windows firewall. ... > configured both the loopback and external interface to accept ... > sending them out through the external interface. ...
      (microsoft.public.security)
    • ISA 2004 - Not processing rule?
      ... Edge Firewall template configuration. ... skeptical about letting DHCP Replies come from the External interface - ... The problem I am facing is that when I create a firewall policy with the ... My Custom Protocol is defined as TCP Outbound for port 5000 ...
      (microsoft.public.isa)
    • ISA 2004 - Not processing rule?
      ... Edge Firewall template configuration. ... skeptical about letting DHCP Replies come from the External interface - ... The problem I am facing is that when I create a firewall policy with the ... My Custom Protocol is defined as TCP Outbound for port 5000 ...
      (microsoft.public.isa.configuration)
    • Re: IP addessing of external interface
      ... My question is about the IP addressing of an external interface of a ... were to use a subnet from private IP address space on the external side ... of the firewall? ... I would only need one IP address on the external interface ...
      (comp.security.firewalls)