Quantcast
Viewing all articles
Browse latest Browse all 260

Juniper ScreenOS NSRP: Configuration via GUI, NSM, and CLI

Short step-by-step screenshot guide for an initial configuration of NSRP of two Juniper ScreenOS firewalls, such as the SSGs. One screenshot pack for the http GUI and another one for the Network and Security Manager (NSM) since I am always searching for the positions of the commands on it. Finally, I am listing the appropriate CLI commands.

The following commands have two HA interfaces configured (eth0/0 and eth0/1). Furthermore, two monitored interfaces were configured: eth0/8 and eth0/9.

GUI

SSG140, 6.3.0r17.0:

Image may be NSFW.
Clik here to view.
Juniper SSG NSRP GUI 01 Interfaces HA
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP GUI 02 Cluster
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP GUI 03 VSD Group
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP GUI 04 Monitor Interface
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP GUI 05 Link
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP GUI 06 Synchronization

NSM

Version 2012.R3:

Image may be NSFW.
Clik here to view.
Juniper SSG NSRP NSM 01 Interfaces HA
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP NSM 02 NSRP General
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP NSM 03 NSRP RTO Mirror
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP NSM 04 NSRP VSD Group Info
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP NSM 05 NSRP Cluster Member Info
Image may be NSFW.
Clik here to view.
Juniper SSG NSRP NSM 06 NSRP Cluster Member Monitoring

CLI

NSRP commands on the master device:

set interface "ethernet0/0" zone "HA"
set interface "ethernet0/1" zone "HA"
set nsrp cluster id 1
set nsrp rto-mirror sync
set nsrp rto-mirror route
set nsrp rto-mirror session ageout-ack
set nsrp vsd-group id 0 priority 50
set nsrp vsd-group id 0 preempt
set nsrp encrypt password hBsm8xVGdpqusGT
set nsrp auth password cGvVjn5gYUF2yJK
set nsrp secondary-path ethernet0/8
set nsrp monitor interface ethernet0/8
set nsrp monitor interface ethernet0/9

 

Links


Viewing all articles
Browse latest Browse all 260

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>