[Contents]
[Prev]
[Next]
[Index]
[Report an Error]
J-Web Configuration
To configure zones:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Zones, click Configure.
- Next to Security zones, click Add new entry.
- In the Name box, type external_subscriber.
- Next to Host inbound traffic, click Configure.
- Next to System services, click Add new entry.
- Next to Service name, select all and click OK.
- Next to Protocols, click Add new entry.
- Next to Protocol name box, select all and click OK.
- Next to Security zones, click Add new entry.
- In the Name box, type internal_ca.
- Next to Host inbound traffic, click Configure.
- Next to System services, click Add new entry.
- Next to Service name, select all and click OK.
- Next to Protocols, click Add new entry.
- Next to Protocol name box, select all and click OK.
- To save and commit the configuration, click Commit.
To configure addresses:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Zones, click Configure or Edit.
- Next to Security zone, click Add new entry.
- In the Name box, type internal_ca.
- Next to Address book, click Configure or Edit.
- Next to Address, click Add new entry.
- In the Address name box, type ca_agent1 10.1.1.101/32 and click OK.
- To configure another security zone external_subscriber,
repeat Step 2 through Step 9 and click OK.
- Next to Address book, click Configure.
- Next to Address, click Add new entry.
- In the Address name box, type SubscriberSubNet
2.2.2.1/24 and click OK.
- To save and commit the configuration, click Commit.
To configure interfaces:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Zones, click Configure.
- Next to Security zone, click Add new entry.
- In the Name box, type internal_ca
- Next to Interfaces, click Add new entry.
- In the Interface unit box, type ge-0/0/01 and click OK.
- Next to Interfaces, click Configure or Edit.
- Next to Interface, click Add new entry.
- In the Interface name box, type ge-0/0/1.
- Next to unit, click Add new entry.
- In the Interface unit number box, type 0.
- Under Family, next to Inet, select the check box, and
click Configure.
- Next to Address, click Add new entry.
- Next to Source, type 2.2.2.1/24 and click OK.
- To configure another security zone, external _subscriber,
and interface, ge-0/0/0, Step 1 through Step 7 and click OK.
- To configure another interface, ge-0/0/0, repeat Step
h to Step l.
- Under Family, next to Inet, select the check box and click OK.
- To save and commit the configuration, click Commit.
To configure internal-to-external zone policies:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Policies, select the check box and click Configure.
- Next to Policy, click Add new entry.
- In the From zone name box, type internal_ca.
- In the To zone name box, type external_subscriber.
- Next to Policy, click Add new entry.
- To specify the Policy name, next to Policy name box, type Pol-CA-To-Subscribers.
- Select the Match check box.
- Select the Then check box.
- Click Configure next to Match check box.
- From the Source address choice list, select Source
address.
- Next to Source address, click Add new entry.
- From the Value keyword list, select Enter Specific
Value.
- In the Address box, type ca-agent1 and click OK.
- From the Destination address choice list, select Destination
address.
- Next to Destination address, click Add new entry.
- Next to Value keyword list, select Enter Specific
Value.
- In the Address box, type SubscriberSubNet and click OK.
- From the Application choice list, select Application.
- Next to Application, click Add new entry.
- Next to Value keyword box, type junos-mgcp and click OK.
- Next to Then, click Configure.
- Next to Action, select permit and click OK.
- To save and commit the configuration, click Commit.
To configure from zone, external_subscriber, and to zone, internal_ca:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Policies, select the check box and click Configure.
- Next to Policy, click Add new entry.
- In the From zone name box, type external_subscriber.
- In the To zone name box, type internal_ca.
- Next to Policy, click Add new entry.
- In the Policy name box, type Pol-Subscribers-To-CA.
- Select the Match check box.
- Select the Then check box.
- Next to Match check box, click Configure.
- From the Source address choice list, select Source
address.
- Next to Source address, click Add new entry.
- From the Value keyword list, select Enter Specific
Value.
- In the Address name box, type SubscriberSubnet and click OK.
- From the Destination address choice list, select Destination
address.
- Next to Destination address, click Add new entry.
- Next to Value keyword list, select Enter Specific
Value.
- In the Address name box, type call_agent1 and click OK.
- From the Application choice list, select Application.
- Next to Application, click Add new entry.
- Next to Value keyword box, type junos-mgcp and click OK.
- Next to Then, click Configure.
- Next to Action, select permit and click OK.
- To save and commit the configuration, click Commit.
To configure from zone and to zone as internal_ca:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Policies, select the check box and click Configure.
- Next to Policy, click Add new entry.
- In the From zone name box, type internal_ca.
- In the To zone name box, type internal_ca.
- Next to Policy, click Add new entry.
- In the Policy name box, type Pol-Intra-CA.
- Select the Match check box.
- Select the Then check box.
- Next to Match check box, click Configure.
- From the Source address choice list, select Source
address.
- Next to Source address, click Add new entry.
- From the Value keyword list, select any and click OK.
- From the Destination address choice list, select Destination
address.
- Next to Destination address, click Add new entry.
- Next to Value keyword list, select any and click OK.
- From the Application choice list, select Application.
- Next to Application, click Add new entry.
- Next to Value keyword box, select any and click OK.
- Next to Then, click Configure.
- Next to Action, select permit.
- To save and commit the configuration, click Commit.
To configure from zone and to zone as external_subscriber:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Policies, select the check box and click Configure.
- Next to Policy, click Add new entry.
- In the From zone name box, type external_subscriber.
- In the To zone name box, type external_subscriber.
- Next to Policy, click Add new entry.
- In the Policy name box, type Pol-Intra-subscriber.
- Select the Match check box.
- Select the Then check box.
- Next to Match check box, click Configure.
- From the Source address choice list, select Source
address.
- Next to Source address, click Add new entry.
- From the Value keyword list, select any and click OK.
- From the Destination address choice list, select Destination
address.
- Next to Destination address, click Add new entry.
- Next to Value keyword list, select any and click OK.
- From the Application choice list, select Application.
- Next to Application, click Add new entry.
- Next to Value keyword box, select any and click OK.
- Next to Then, click Configure.
- Next to Action, select permit.
- To save and commit the configuration, click Commit.
[Contents]
[Prev]
[Next]
[Index]
[Report an Error]