<- zone "Trust" ->|<------------------- NetScreen -------------------->|<- zone "Untrust" ->
[Host1]--+ +--[Host4]
| |
[Host2]--+--[vrouter "trust-vr"]-[Firewall]-[vrouter "untrust-vr"]--+--[Host5]
| |
[Host3]--+ +--[Host6]
ns-> set zone src-zone vrouter vrouterex)定義済み仮想ルータを利用する場合。![]()
ns-> set zone Trust vrouter trust-vrns-> set zone Untrust vrouter untrust-vr
![]()
ns-> set interface if zone "zone"ex)trustにTrustゾーンを割り当てる場合![]()
ns-> set interface trust zone Trust![]()
ns-> set interface i/f ip ip_addr[/netmask| netmask]ex)trustに192.168.1.1を割り当てる場合![]()
ns-> set interface trust ip 192.168.1.1/24![]()
ns-> set address zone addr-name ip-addr netmask [comment]![]()
ns-> set address "Trust" "ADDR_Foo" 192.168.2.0 255.255.255.0 "Foo Network"![]()
ns-> set group address zone addr_grp_name [comment "comment"]![]()
ns-> set group address zone addr_grp_name add addr_nameex)Trustゾーン側に、ADDR_GRP_Foo Barを定義する![]()
ns-> set group address Trust "ADDR_GRP_Foo Bar" comment "Foo Bar Network"ns-> set group address "Trust" "ADDR_GRP_Foo Bar" add "ADDR_Foo"
ns-> set group address "Trust" "ADDR_GRP_Foo Bar" add "ADDR_Bar"
![]()
ns-> set service service protocol tcp|udp src-port port dst-port port[timeout time]![]()
ex)特殊なサービスを定義
ns-> set service "SVC_HIGH" protocol tcp src-port 0-65535 dst-port 2048![]()
ns-> set policy [name name] from src-zone to dst-zone src-addr dst_addr svc Permit|Denyex) Trust から Untrust に対する HTTP 通信を許可する![]()
ns-> set policy id 0 name "HTTP Deny" from "Trust" to "Untrust" "ADDR_Foo" "ADDR_Bar" "HTTP" Permit![]()
set policy move move_id before|after idex) 10 番のポリシーを5番の次に移動したい場合![]()
set policy move 10 after 5![]()
ns-> set route network_addr interface i/f gateway rouet
ns-> set route 192.168.3.0/24 interface untrust gateway 192.168.2.1
ns-> set vrouter trust-vr protocol ospf area 10 stub
set zone zone vrouter vrouterex)![]()
set zone trust vrouter trust-vr![]()
ns-> set vrouter vrouterex)
ns-> set vrouter trust-vr![]()
ns(trust-vr)-> set protocol {OSPF|BGP}ex)![]()
ns(trust-vr)-> set protocol ospf![]()
ns(trust-vr/ospf)-> set area 10 stub![]()
ns-> set policy from src-zone to dst-zone src-addr-name dst-addr-name service nat src permit
ns-> set interface if dip id start-ip-addr end-ip-addr [fix-port]
ns-> set policy from src-zone to dst-zone src-addr-name dst-addr-name service nat src dip-id id permit
ns-> set address trust host1 ip-addr1/32 ns-> set address trust host2 ip-addr2/32 ns-> set address trust host3 ip-addr3/32 ns-> set group address src-zone src-addr-group add host1 ns-> set group address src-zone src-addr-group add host2 ns-> set group address src-zone src-addr-group add host3
ns-> set interface if dip id shift-from ip-addr1 to start-ip-addr end-ip-addr
ns-> set policy from src-zone to dst-zone src-addr-group dst-addr-name service nat src dip-id id permit
ns-> set interface "engress-if" mip mip-addr host ip-addr netmask netmask vr "vrouter"
ns-> set url protocol type sc-cpa
ns-> set url protocol sc-cpa ns(url:sc-cpa)-> set enable
ns(url:sc-cpa)-> set category category-name url url1 ns(url:sc-cpa)-> set category category-name url url2
ns(url:sc-cpa)-> set profile prof-name category-name black-list ns(url:sc-cpa)-> set profile prof-name category-name white-list ns(url:sc-cpa)-> set profile prof-name category-name [permit|block] ns(url:sc-cpa)-> set profile prof-name other [permit|block] ns(url:sc-cpa)-> exit
ns-> set policy from zone to zone src dst svc permit url-filter ns-> set policy id n ns(policy:n)-> set url protocol sc-cpa profile prof-name ns(policy:n)->
ns-> set url protocol type sc-cpa ns(url:sc-cpa)-> get profile profile-name
ns-> set dns host schedule
ns-> get dns host cache
ns-> get dns host report
ns-> set snmp ? auth-trap set SNMP AuthTrap community snmp community configuration contact set system contact host snmp host configuration location set system location name set system name port set SNMP listen & trap port vpn set SNMP VPN encryption
ns-> set policy [name name] from src-zone to dst-zone src-addr dst_addr svc Permit|Deny log
ns-> set policy id n ns(policy:n)-> set log [session-init] ns(policy:n)-> exit
ns-> get log traffic policy id PID id, from zone to zone, src src, dst dst, service svc, action Permit Total traffic entries matched under this policy = num ============================================================================================== Date Time Duration Source IP Port Destination IP Port Service SessionID Reason Xlated Src IP Port Xlated Dst IP Port ID ============================================================================================== 2000-01-01 00:00:00 0:00:23 192.168.0.1 3000 10.0.0.1 80 HTTP 7123 Close - AGE OUT
Reason | 理由 |
Creation | セッションが生成 (session-init 設定時のみ) |
Close - TCP FIN | TCP FIN でセッション終了 |
Close - TCP RST | TCP RST でセッション終了 |
Close - RESP | PING や DNS の特殊セッションの応答受信でセッション終了 |
Close - ICMP | ICMP エラーを受信 |
Close - AGE OUT | 通信がタイムアウトしセッション切断 |
Close - NSRP | NSRP の session close メッセージを受信 |
Close - AUTH | 認証失敗でセッション切断 |
Close - CLI | CLI コマンドでセッション切断 |
ns-> set policy [name name] from src-zone to dst-zone src-addr dst-addr svc Permit|Deny count
ns5xt-> get hostnameHostname: ns5xt nsNhoge-> set hostname ns
ns-> get hostname
Hostname: ns
ns-> set domain domain
ns-> set console timeout 0![]()
ns-> set admin auth banner console login "NetScreen Management Console"ns-> save
Save System Configuration ... Done ns-> exit
NetScreen Management Console login:
ns-> set admin auth banner telnet login "NetScreen Remote Management Console"/// # telnet 192.168.1.1 NetScreen Remote Management Console NetScreen Management Console login:
ns-> set clock ntpNTP有効化 ns-> set clock timezone 9
UTCとの時差 ns-> set ntp server ip_addr
ns-> set ntp server backup1 ip_addr
SOS5~ ns-> set ntp server backup2 ip_addr
ns-> set ntp interval min
更新間隔 デフォルト10分 ns-> set ntp max-adjustment sec
Stepする最大値 デフォルト3秒 SOS5~
ns-> saveSave System Configuration ... Done
ns-> save config from flash to tftp ip-addr file
ns-> save config from tftp ip-addr file
ns-> get system
login: Serial_Numberpassword: Serial_Number
!!! Lost Password Reset !!! You have initiated a command to reset the device to factory defaults, clearing all current configuration and settings. Would you lik e to continue? y/[n] y !! Reconfirm Lost Password Reset !! If you continue, the entire configuration of the device will be erased. In addition, a permanent counter will be incremented to signify that this device has been reset. This is your last chance to cancel this command. If you proceed, the device will return to factory default configur ation, which is: System IP: 192.168.1.1; username: netscreen, password: netscree n. Would you like to continue? y/[n] y In reset ...
login: netscreen password: netscreen ns5xt->