[Contents]
[Prev]
[Next]
[Index]
[Report an Error]
J-Web Configuration
To set interfaces:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Interfaces, click Configure or Edit.
- Next to Interface, click Add new entry.
- In the Interface name box, type ge-0/0/0.
- Next to Unit, click Add new entry.
- Next to Interface unit number, type 0.
- Next to Inet, select the check box and click Configure.
- Next to Address, click Add new entry.
- Next to Source, type 1.2.2.1/24 and click OK.
- To configure another interface, fe-1/0/0, and address, 1.1.1.1/24, repeat Step
b through i and click OK.
- To save and commit the configuration, click Commit.
To configure a zone and assign an interface:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Zones, click Configure.
- Next to Security zone, click Add new entry.
- In the Name box, type zone_dmz.
- Next to Interfaces, click Add new entry.
- In the Interface unit box, type ge-0/0/0.0 and click OK.
- To configure another security zone, zone_external and assign an interface fe-1/0/0.0, repeat
Step 4 through Step 7 and click OK.
- To save and commit the configuration, click Commit.
To define an address:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Zones, click Configure.
- Next to Security zone, click Add new entry.
- In the Name box, type zone_dmz.
- Next to Address book, click Configure.
- Next to Address, click Add new entry.
- In the Address name box, type ws1 1.2.2.10/32 and click OK.
- To configure other address entries such as ws2 1.2.2.20/32, ws3 1.2.2.30/32, ws4 1.2.2.40/32, repeat Step 7 through
Step 8 and click OK.
- Next to Address set, click Add new entry.
- In the Address set name box, type web_servers.
- Next to Address, click Add new entry.
- In the Address name box, type ws1.
- To configure other address-set entries such as ws2, ws3,ws4, repeat Step l through Step m and click OK.
- To save and commit the configuration, click Commit.
To configure a policy:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Policies, select the check box and click Configure.
- Next to Policy, click Add new entry.
- In the From zone name box, type zone_external.
- In the To zone name box, type zone_dmz and click OK.
- Under the From zone name column, click private.
- Next to Policy, click Add new entry.
- In the Policy name box, type id_1.
- Select the Match check box.
- Select the Then check box.
- Next to Match, click Configure.
- Next to Source address choice list, select Source address.
- Next to Source address, click Add new entry.
- From the Value keyword list, select any and click OK.
- From the Destination address choice list, select Destination address.
- Next to Destination address, click Add new entry.
- From the Value keyword list, select Enter
Specific Value.
- In the Address box, type web_servers and click OK.
- From the Application choice list, select Application.
- Next to Application, click Add new entry.
- In the Value keyword box, type junos-http and click OK.
- Next to Then, click Configure.
- Next to Action, select permit and click OK.
- To save and commit the configuration, click Commit.
To configure screen options:
- Select Configuration > View and Edit > Edit Configuration. The Configuration page appears.
- Next to Security, click Configure or Edit.
- Next to Screen, click Configure.
- Next to Ids option, click Add new entry.
- In the Name box, type zone_external-syn-flood.
- Next to Tcp, click Configure.
- Next to Syn flood box, select the check box and click Configure.
- In the Alarm threshold box, type 250.
- In the Attack threshold box, type 625.
- In the Source threshold box, type 25.
- In the Timeout box, type 20.
- To save and commit the configuration, click Commit.
To configure zones:
- Select Configuration > View and
Edit > Edit Configuration. The Configuration page appears.
- Next to Zones, click Configure.
- Next to Security zone, click Add new entry.
- In the Name box, type zone_external.
- In the Screen box, type zone_external-syn-flood and click OK.
- To save and commit the configuration, click Commit.
[Contents]
[Prev]
[Next]
[Index]
[Report an Error]