avatar
transparant mode in netscreen 5gt# EmergingNetworking - 热门网络技术
l*y
1
i just can't see transparant mode as an option on the gui, there are just nat
and route. trying to do it via the cli by setting the ips to be 0.0.0.0 and
setting trust interface to be in zone V1-trust, etc.
avatar
m*t
2
what do you mean transparent mode? transport mode or tunnel mode?

nat

【在 l***y 的大作中提到】
: i just can't see transparant mode as an option on the gui, there are just nat
: and route. trying to do it via the cli by setting the ips to be 0.0.0.0 and
: setting trust interface to be in zone V1-trust, etc.

avatar
z*r
3
还有interface mode是什么?俺对具体命令也不熟悉,厚厚

avatar
l*y
4
yes, we've got the full get tech-support output and verified system is in
transparant mode. box is in trust-untrust mode, etc, etc. in utter
motification. just opened a case with juniper. i have a feeling it's some
configuration problem. =/
avatar
z*r
5
还有interface mode是什么?俺对具体命令也不熟悉,厚厚



【在 z**r 的大作中提到】
: 还有interface mode是什么?俺对具体命令也不熟悉,厚厚
:
: 必

avatar
l*y
6
okay, it is official, i'm not a he. :D
avatar
z*r
7
why not get a document? it should be a basic issue, do you have juniper.net
account? if no, I can help to download the document, hehe

let
the
flood.
V1-
.
is
康王的仪容,但乘坐的龙辇被黄缦红绫遮挡得严严实实,百姓们其实半点也无法看见。
看来,一行车驾在急急赶路,通知也不及时,百姓们都没被郡中安排做具体的反应。
但车驾排场已经惊骇到了所有人的心,百姓们无不高呼:“我王万岁!”接着比次拜服,
连郡守带领下的小吏们都晚了百姓半分。
谁也没有想到的是,这场宏大的场面在通山公国的贵族后裔子弟姬垩的心上种上了一
句话。通山公国,据说是兽人的杂种,可渐渐却成了中大陆诸国的一部分。姬氏是国中一
姓,族中曾经出过几代名将。靖康取其地后,移民戍出,调当地大族入,这就有了姬族的
今日。
姬垩这年十六岁,正处于一个充满幻想的年代。世家的回顾让他这样的年轻人常以名
门自诩,把威镇列国的西定将军姬羽作为血脉中的因子。他这就这样站在一边看着,突然
有种博钱的

【在 l***y 的大作中提到】
: okay, it is official, i'm not a he. :D
avatar
z*r
8
no, he means the layer2 transparent mode, basically, the firewall will
function like a bridge instead of a router.

【在 m**t 的大作中提到】
: what do you mean transparent mode? transport mode or tunnel mode?
:
: nat

avatar
l*y
9
okay, it is official, i'm not a he. :D
avatar
B*R
10
isn't this the way basic firewall would act like?

.
is

【在 l***y 的大作中提到】
: okay, it is official, i'm not a he. :D
avatar
l*y
11
man, i've got the full documentaion CD. we've gone through it multiple times.
hehe
avatar
c*a
12
good point. Read her original post again, seems that .25 can always ping .26
not vice versa, even by swapping two endpoints to different zones.
I was originally thinking of "unset interface vlan1 bypass-non-ip", but now
looks like .26 is not responding to ping anyway
also she might want to check forwarding table (arp table)

ARP

【在 m**t 的大作中提到】
: what do you mean transparent mode? transport mode or tunnel mode?
:
: nat

avatar
l*y
13
man, i've got the full documentaion CD. we've gone through it multiple times.
hehe
avatar
z*r
14
还有interface mode是什么?俺对具体命令也不熟悉,厚厚



【在 z**r 的大作中提到】
: no, he means the layer2 transparent mode, basically, the firewall will
: function like a bridge instead of a router.

avatar
z*r
15
why not get a document? it should be a basic issue, do you have juniper.net
account? if no, I can help to download the document, hehe

let
the
flood.
V1-
.
is
康王的仪容,但乘坐的龙辇被黄缦红绫遮挡得严严实实,百姓们其实半点也无法看见。
看来,一行车驾在急急赶路,通知也不及时,百姓们都没被郡中安排做具体的反应。
但车驾排场已经惊骇到了所有人的心,百姓们无不高呼:“我王万岁!”接着比次拜服,
连郡守带领下的小吏们都晚了百姓半分。
谁也没有想到的是,这场宏大的场面在通山公国的贵族后裔子弟姬垩的心上种上了一
句话。通山公国,据说是兽人的杂种,可渐渐却成了中大陆诸国的一部分。姬氏是国中一
姓,族中曾经出过几代名将。靖康取其地后,移民戍出,调当地大族入,这就有了姬族的
今日。
姬垩这年十六岁,正处于一个充满幻想的年代。世家的回顾让他这样的年轻人常以名
门自诩,把威镇列国的西定将军姬羽作为血脉中的因子。他这就这样站在一边看着,突然
有种博钱的

【在 l***y 的大作中提到】
: man, i've got the full documentaion CD. we've gone through it multiple times.
: hehe

avatar
l*y
16
it's frustrating. we have pc1(10.1.1.10)- untrust port ------trust port ---
pc2(10.1.1.11),
pc1 can see pc2's arp; pc2 can see pc1's arp. netscreen has both of their arp
entry. however ping is one directional. swapped the port and the ping is still
one directional, and the direction didn't reverse as we thought it would.
swapped pc1 with another pc, same problem. verified both pc aren't running
firewall. the jtac guys said we'd have to do some debug. hopefully this gets
resolved today.
avatar
z*r
17
you have the tcpdump output from both pc's?

arp
still

【在 l***y 的大作中提到】
: it's frustrating. we have pc1(10.1.1.10)- untrust port ------trust port ---
: pc2(10.1.1.11),
: pc1 can see pc2's arp; pc2 can see pc1's arp. netscreen has both of their arp
: entry. however ping is one directional. swapped the port and the ping is still
: one directional, and the direction didn't reverse as we thought it would.
: swapped pc1 with another pc, same problem. verified both pc aren't running
: firewall. the jtac guys said we'd have to do some debug. hopefully this gets
: resolved today.

avatar
l*y
18
okay, it is official, i'm not a he. :D

【在 c*a 的大作中提到】
: good point. Read her original post again, seems that .25 can always ping .26
: not vice versa, even by swapping two endpoints to different zones.
: I was originally thinking of "unset interface vlan1 bypass-non-ip", but now
: looks like .26 is not responding to ping anyway
: also she might want to check forwarding table (arp table)
:
: ARP

avatar
z*r
19
no, he means the layer2 transparent mode, basically, the firewall will
function like a bridge instead of a router.

【在 m**t 的大作中提到】
: what do you mean transparent mode? transport mode or tunnel mode?
:
: nat

avatar
c*a
20
good point. Read her original post again, seems that .25 can always ping .26
not vice versa, even by swapping two endpoints to different zones.
I was originally thinking of "unset interface vlan1 bypass-non-ip", but now
looks like .26 is not responding to ping anyway
also she might want to check forwarding table (arp table)

ARP

【在 m**t 的大作中提到】
: what do you mean transparent mode? transport mode or tunnel mode?
:
: nat

相关阅读
logo
联系我们隐私协议©2024 redian.news
Redian新闻
Redian.news刊载任何文章,不代表同意其说法或描述,仅为提供更多信息,也不构成任何建议。文章信息的合法性及真实性由其作者负责,与Redian.news及其运营公司无关。欢迎投稿,如发现稿件侵权,或作者不愿在本网发表文章,请版权拥有者通知本网处理。