To configure internal-to-external zone policies:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Policies, select the check box and click Configure.
- Next to Policy, click Add new entry.
- In the From zone name box, type internal_ca.
- In the To zone name box, type external_subscriber.
- Next to Policy, click Add new entry.
- To specify the Policy name, next to Policy name box, type Pol-CA-To-Subscribers.
- Select the Match check box.
- Select the Then check box.
- Click Configure next to Match check box.
- From the Source address choice list, select Source
address.
- Next to Source address, click Add new entry.
- From the Value keyword list, select Enter Specific
Value.
- In the Address box, type ca-agent1 and click OK.
- From the Destination address choice list, select Destination
address.
- Next to Destination address, click Add new entry.
- Next to Value keyword list, select Enter Specific
Value.
- In the Address box, type SubscriberSubNet and click OK.
- From the Application choice list, select Application.
- Next to Application, click Add new entry.
- Next to Value keyword box, type junos-mgcp and click OK.
- Next to Then, click Configure.
- Next to Action, select permit and click OK.
- To save and commit the configuration, click Commit.
To configure from zone, external_subscriber, and to zone, internal_ca,
follow the sequence of steps below:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Policies, select the check box and click Configure.
- Next to Policy, click Add new entry.
- In the From zone name box, type external_subscriber.
- In the To zone name box, type internal_ca.
- Next to Policy, click Add new entry.
- In the Policy name box, type Pol-Subscribers-To-CA.
- Select the Match check box.
- Select the Then check box.
- Next to Match check box, click Configure.
- From the Source address choice list, select Source
address.
- Next to Source address, click Add new entry.
- From the Value keyword list, select Enter Specific
Value.
- In the Address name box, type SubscriberSubnet and click OK.
- From the Destination address choice list, select Destination
address.
- Next to Destination address, click Add new entry.
- Next to Value keyword list, select Enter Specific
Value.
- In the Address name box, type call_agent1 and click OK.
- From the Application choice list, select Application.
- Next to Application, click Add new entry.
- Next to Value keyword box, type junos-mgcp and click OK.
- Next to Then, click Configure.
- Next to Action, select permit and click OK.
- To save and commit the configuration, click Commit.
To configure from zone and to zone as internal_ca, follow the
sequence of steps listed below:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Policies, select the check box and click Configure.
- Next to Policy, click Add new entry.
- In the From zone name box, type internal_ca.
- In the To zone name box, type internal_ca.
- Next to Policy, click Add new entry.
- In the Policy name box, type Pol-Intra-CA.
- Select the Match check box.
- Select the Then check box.
- Next to Match check box, click Configure.
- From the Source address choice list, select Source
address.
- Next to Source address, click Add new entry.
- From the Value keyword list, select any and click OK.
- From the Destination address choice list, select Destination
address.
- Next to Destination address, click Add new entry.
- Next to Value keyword list, select any and click OK.
- From the Application choice list, select Application.
- Next to Application, click Add new entry.
- Next to Value keyword box, select any and click OK.
- Next to Then, click Configure.
- Next to Action, select permit.
- To save and commit the configuration, click Commit.
To configure from zone and to zone as external_subscriber, follow
the sequence of steps below:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Policies, select the check box and click Configure.
- Next to Policy, click Add new entry.
- In the From zone name box, type external_subscriber.
- In the To zone name box, type external_subscriber.
- Next to Policy, click Add new entry.
- In the Policy name box, type Pol-Intra-subscriber.
- Select the Match check box.
- Select the Then check box.
- Next to Match check box, click Configure.
- From the Source address choice list, select Source
address.
- Next to Source address, click Add new entry.
- From the Value keyword list, select any and click OK.
- From the Destination address choice list, select Destination
address.
- Next to Destination address, click Add new entry.
- Next to Value keyword list, select any and click OK.
- From the Application choice list, select Application.
- Next to Application, click Add new entry.
- Next to Value keyword box, select any and click OK.
- Next to Then, click Configure.
- Next to Action, select permit.
- To save and commit the configuration, click Commit.