help with roadrunner+netscreen firewall+cisco router

Discussion in 'Hardware' started by ssjchris_29, Jan 12, 2006.

  1. ssjchris_29

    ssjchris_29 Private E-2

    Ok - after my router got hacked into a few months ago - i took it out of the network and used my computer as a residential gateway/firewall for my network. I recently aquired a netscreen 5GT firewall (only has the console, trust, and untrust ports). I also have a Cisco 831 broadband router. My biggest problem is that i cannot seem to configure the firewall properly to allow any access past it. I've tinkered and toyed with everything i can think of but I cannot seem to get the device to let my computer through it to the internet. Does anyone know what i may be missing? Here is the config for the netscreen (after the basic setup and a small amount of experimentation):

    Total Config size 2704:
    set clock timezone 0
    set vrouter trust-vr sharable
    unset vrouter "trust-vr" auto-route-export
    set auth-server "Local" id 0
    set auth-server "Local" server-name "Local"
    set auth default auth server "Local"
    set admin name "******"
    set admin password "******"
    set admin auth t
    set admin auth server "Local"
    set admin format dos
    set zone "Trust" vrouter "trust-vr"
    set zone "Untrust" vrouter "trust-vr"
    set zone "VLAN" vrouter "trust-vr"
    set zone "Trust" tcp-rst
    set zone "Untrust" block
    unset zone "Untrust" tcp-rst
    set zone "MGT" block
    set zone "VLAN" block
    set zone "VLAN" tcp-rst
    set zone "Untrust" screen winnuke
    set zone "Untrust" screen port-scan
    set zone "Untrust" screen ip-sweep
    set zone "Untrust" screen tear-drop
    set zone "Untrust" screen syn-flood
    set zone "Untrust" screen
    set zone "Untrust" screen ping-death
    set zone "Untrust" screen ip-filter-src
    set zone "Untrust" screen land
    set zone "Untrust" screen syn-frag
    set zone "Untrust" screen tcp-no-flag
    set zone "Untrust" screen ip-bad-option
    set zone "Untrust" screen syn-fin
    set zone "Untrust" screen fin-no-ack
    set zone "Untrust" screen syn-ack-ack-proxy
    set zone "V1-Untrust" screen tear-drop
    set zone "V1-Untrust" screen syn-flood
    set zone "V1-Untrust" screen ping-death
    set zone "V1-Untrust" screen ip-filter-src
    set zone "V1-Untrust"
    set interface "trust" zone "Trust"
    set interface "untrust" zone "Untrust"
    unset interface vlan1 ip
    set interface trust ip 10.1.1.1/8
    set interface trust nat
    set interface untrust ip 65.25.76.47/22
    set interface untrust route
    set interface trust bandwidth 4096
    set interface untrust bandwidth 4096
    unset interface vlan1 bypass-others-ipsec
    unset interface vlan1 bypass-non-ip
    set interface trust ip manageable
    unset interface untrust ip manageable
    set interface trust dhcp server service
    set interface trust
    set interface trust dhcp server option lease 1440000
    set interface trust dhcp server option gateway 65.25.76.47
    set interface trust dhcp server option netmask 255.255.252.0
    set interface trust dhcp server option domainname neo.rr.com
    set interface trust dhcp server option dns1 65.24.7.3
    set interface untrust dhcp-client enable
    set flow tcp-mss
    set domain neo.rr.com
    set hostname ******
    set dns host dns1 65.24.7.3
    set ike respond-bad-spi 1
    set pki authority default scep mode "auto"
    set pki x509 default cert-path partial
    set ssh version v2
    set config lock timeout 5
    set snmp port listen 161
    set snmp port trap 162
    set vrouter "untrust-vr"
    exit
    set vrouter "trust-vr"
    set add-default-route vrouter "untrust-vr"
    exit


    The router I should be able to manage once i find my old Cisco book and remember how to configure one from scratch from the command line (the CRWS doesn't work anymore). If anyone can help me with the firewall (essentially that's all i want it for is for the firewall/filtering options - I use my cisco router for the home network internet access) I would be most grateful! Thank you for any help!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds