Re: [j-nsp] SecurID netscreen problem

2008-07-22 Thread sunnyday
I don't use tunnel interface just configured the vpn through the Autokey Advanced Gateway and Autokey Ike and then a bidirectional policy from Dial-Up VPN to any Action=Tunnel And that's it.After that the user is configured locally. And that thing that you said with netscreen remote how can

Re: [j-nsp] SecurID netscreen problem

2008-07-22 Thread sunnyday
Ok I managed to got it working thanks for your help Stefan. -Original Message- From: Stefan Fouant [mailto:[EMAIL PROTECTED] Sent: Monday, July 21, 2008 8:03 PM To: sunnyday Cc: Juniper-Nsp; [EMAIL PROTECTED] Subject: Re: [j-nsp] SecurID netscreen problem The tunnel can be treated as

Re: [j-nsp] Enforcing CLI Idle-Timeouts

2008-07-22 Thread Boyd, Benjamin R
I think he meant the difference in the changes is negligible (like 3 set statements). Either solution you deploy (both set scripts) you'll still have to deploy to hundreds of routers. Look into Shrubbery's RANCID for a super-fast way to do that. -Ben -Original Message- From: [EMAIL

Re: [j-nsp] PAT on a single external IP Address?

2008-07-22 Thread Sven Juergensen (KielNET)
Well, although not documented to my knowledge, assigning a static IP via ppp to a pppoe interface and referencing it in a mip seems to work. ScreenOS somehow holds the last ppp-assigned IP sticky in the config so the MIP is valid even after a reboot. Surely this is a dirty hack though ;) Is

[j-nsp] PAT on a single external IP Address?

2008-07-22 Thread Sven Juergensen (KielNET)
Hi list, is it possible to have a static PAT on ScreenOS when the external (public/WAN) IP-Address is dynamic and point-to-point? E.g. have port 25 on the external IP map to a single private (1918) internal host? VIPs seem to always reference a static IP (destination PAT) and, like MIPs,

[j-nsp] generic ospf question

2008-07-22 Thread Ying Zhang
Hi list, Just wondering, if an area is configured as NSSA with no summaries, in case any router in OSPF area 0 reboots or fails, will it cause SPF algorithm to re-run in this NSSA? Of course, routing across area 0 will be affected, but will routing WITHIN the NSSA be affected as well? Thanks.

Re: [j-nsp] PAT on a single external IP Address?

2008-07-22 Thread GIULIANO (UOL)
You can use VIP and the option: use the IP from the external interface And you can use and external DynDNS service to map the dynamic address to a fixed name. Well, although not documented to my knowledge, assigning a static IP via ppp to a pppoe interface and referencing it in a mip seems

[j-nsp] Supporting Audit Requirements in JUNOS

2008-07-22 Thread Stefan Fouant
Hi folks, As part of SAS 70 Audit requirements, I need to ensure that anytime a firewall change is made on my routers a description of that change is recorded. I suppose I could force this by using commit scripts and forcing the use of annotate on anything in the firewall-filters stanza,

Re: [j-nsp] Supporting Audit Requirements in JUNOS

2008-07-22 Thread Christian Koch
Hello Stefan - I have been going through multiple SAS70's for the past year now... however, we have a change management process, which changes need to go through in order for a change to be allowed. so everything is all documented.. submit change request - review - approve - push change -

[j-nsp] ERX DPFE version issue

2008-07-22 Thread Dr Rocco DiSanto
Hi All, I am hoping someone can offer me a suggestion on an issue I'm having with a legacy Duel Port Fast Ethernet (DPFE) line card in an ERX 1410. I have a DPFE that was last working in a chassis running JUNOSe 2.61(been sitting in the lab for a while but booted successfully to the prompt