Re: Netscreen 5400 configuration problem

One of the best features (in my opinion) of the NetScreen firewalls is
the ability to have multiple interfaces with the same, or overlapping
network ranges. This is possible by NetScreen supporting multiple
virtual routers (VRs)

For the firewall to support overlapping ranges you will need to
configure the two interfaces on a different VRs.

NetScreens don't support that configuration. Think about it, what would the
routing table look like?

The routing is not so much of an issue, but it is the NAT that will
need careful consideration!


I'm using google groups, so my messages might out of date.

Somebody. wrote:
"Vilar" <paulo.vilar@xxxxxxxxxxx> wrote in message
Hi all,

I'm trying to configure 2 ports of the 5400 firewall with the same
subnet but I dont know how.
I have the same subnet in diferent buildings so I have to connect the 2
buildings to 2 different ports...and aggregate is not the answer.

Can someone please help me ?

Thank you,
Paulo Vilar

NetScreens don't support that configuration. Think about it, what would the
routing table look like?



Relevant Pages

  • Connectivity issues with NetScreen Firewalls and Linux/Solaris
    ... a summary posting once the issue is resolved. ... NetScreens filters packets and the manner in which Solaris creates them. ... packet payload to a size greater than the TCP segment. ... all match and a failure causes the firewall to drop the packet. ...
  • Re: [fw-wiz] NetScreen Logging with NSRP
    ... Do you have an idea how many sessions you have on these machines? ... Having a cluster you cannot do logging on the backup machine. ... Alternatively you could mirror the ports where the netscreens are ... passive/active firewall setup with NSRP. ...
  • RE: What firewall?
    ... Subject: What firewall? ... One of our clients is pushing 30-40mb/s through ... a HA set of NetScreens and we have nothing but success with these devices. ... VPN using around 10mb/s of traffic. ...
  • Re: Virus risk via VPN
    ... Netscreens Firewall will look into Java/ActiveX and even URLs if you want. ... > sent from the VPN gateway/firewall that checks the client pc to be sure ... > I know Nortel Contivity will support tunnel guard capability in the near ...