Attachment 'Netscreen-5GT_cfg.txt'
Download 1 Total Config size 5590:
2 set clock timezone 1
3 set vrouter trust-vr sharable
4 set vrouter "untrust-vr"
5 exit
6 set vrouter "trust-vr"
7 unset auto-route-export
8 exit
9 set auth-server "Local" id 0
10 set auth-server "Local" server-name "Local"
11 set auth default auth server "Local"
12 set auth radius accounting port 1646
13 set admin name "netscreen"
14 set admin password <removed>
15 set admin manager-ip 192.168.101.12 255.255.255.255
16 set admin manager-ip 192.168.1.0 255.255.255.0
17 set admin auth timeout 10
18 set admin auth server "Local"
19 set admin format dos
20 set zone "Trust" vrouter "trust-vr"
21 set zone "Untrust" vrouter "trust-vr"
22 set zone "VLAN" vrouter "trust-vr"
23 set zone "Untrust-Tun" vrouter "trust-vr"
24 unset zone "Trust" tcp-rst
25 unset zone "Untrust" block
26 unset zone "Untrust" tcp-rst
27 set zone "MGT" block
28 set zone "VLAN" block
29 unset zone "VLAN" tcp-rst
30 set zone "Untrust" screen tear-drop
31 set zone "Untrust" screen syn-flood
32 set zone "Untrust" screen ping-death
33 set zone "Untrust" screen ip-filter-src
34 set zone "Untrust" screen land
35 set zone "V1-Untrust" screen tear-drop
36 set zone "V1-Untrust" screen syn-flood
37 set zone "V1-Untrust" screen ping-death
38 set zone "V1-Untrust" screen ip-filter-src
39 set zone "V1-Untrust" screen land
40 set interface "trust" zone "Trust"
41 set interface "untrust" zone "Untrust"
42 unset interface vlan1 ip
43 set interface "vlan1" ipv6 mode "router"
44 set interface "vlan1" ipv6 enable
45 set interface trust ip 192.168.1.1/24
46 set interface "trust" ipv6 mode "router"
47 set interface "trust" ipv6 enable
48 set interface trust nat
49 set interface untrust ip 192.168.103.109/32
50 set interface "untrust" ipv6 mode "host"
51 set interface "untrust" ipv6 enable
52 set interface untrust route
53 set interface trust bandwidth egress mbw 10000
54 unset interface vlan1 bypass-others-ipsec
55 unset interface vlan1 bypass-non-ip
56 set interface trust ip manageable
57 set interface untrust ip manageable
58 set interface untrust manage ping
59 set interface untrust manage ssh
60 set interface untrust manage telnet
61 set interface untrust manage snmp
62 set interface untrust manage ssl
63 set interface untrust manage web
64 set interface untrust manage mtrace
65 set interface vlan1 ipv6 ra link-address
66 set interface trust ipv6 ra link-address
67 set interface untrust ipv6 ra accept
68 set interface vlan1 ipv6 nd nud
69 set interface trust ipv6 nd nud
70 unset interface untrust ipv6 nd nud
71 set interface trust dhcp6 server
72 set interface trust dhcp6 server options client-duid 00:03:00:00:00:00:00:01
73 set interface trust dhcp6 server preference 0
74 set interface trust dhcp6 server options search-list name comlab 0
75 set interface trust dhcp6 server enable
76 set interface untrust dhcp6 client
77 set interface untrust dhcp6 client options request dns
78 set interface untrust dhcp6 client options request search-list
79 set interface untrust dhcp6 client options request pd
80 set interface untrust dhcp6 client enable
81 set interface trust dhcp server service
82 set interface trust dhcp server enable
83 set interface trust dhcp server option lease 1440
84 set interface trust dhcp server option dns1 192.168.101.12
85 set interface trust dhcp server ip 192.168.1.10 to 192.168.1.20
86 unset interface trust dhcp server config next-server-ip
87 set flow tcp-mss
88 set flow all-tcp-mss 1304
89 unset flow no-tcp-seq-check
90 set flow tcp-syn-check
91 set domain comlab
92
93 set pki authority default scep mode "auto"
94 set pki x509 default cert-path partial
95 set dns host dns1 0.0.0.0
96 set dns host dns2 0.0.0.0
97 set dns host dns3 0.0.0.0
98 set ike respond-bad-spi 1
99 unset ike ikeid-enumeration
100 unset ipsec access-session enable
101 set ipsec access-session maximum 5000
102 set ipsec access-session upper-threshold 0
103 set ipsec access-session lower-threshold 0
104 set ipsec access-session dead-p2-sa-timeout 0
105 unset ipsec access-session log-error
106 unset ipsec access-session info-exch-connected
107 unset ipsec access-session use-error-log
108 unset av http keep-alive
109 set av http webmail enable
110 set av profile "scan-mgr"
111 set ftp scan-mode scan-all
112 set ftp decompress-layer 2
113 set http scan-mode scan-all
114 set imap scan-mode scan-all
115 set imap decompress-layer 2
116 set pop3 scan-mode scan-all
117 set pop3 decompress-layer 2
118 set smtp scan-mode scan-all
119 set smtp decompress-layer 2
120 exit
121 set url protocol websense
122 exit
123 set policy id 6 from "Untrust" to "Trust" "Any-IPv4" "Any-IPv4" "ANY" permit
124 set policy id 6
125 exit
126 set policy id 5 from "Trust" to "Untrust" "Any-IPv4" "Any-IPv4" "ANY" permit
127 set policy id 5
128 exit
129 set policy id 7 from "Trust" to "Untrust" "Any-IPv6" "Any-IPv6" "ANY" permit
130 set policy id 7
131 exit
132 set policy id 8 from "Untrust" to "Trust" "Any-IPv6" "Any-IPv6" "ANY" permit
133 set policy id 8
134 exit
135 set pppoe name "Test_ipv6"
136 set pppoe name "Test_ipv6" username "5gt@ipv6_jnpr" password "GcQtV85xNCiJTnsN+KCdlIbObonwNztVuA=="
137 set pppoe name "Test_ipv6" interface untrust
138 set pppoe name "Test_ipv6" ppp lcp-echo-retries 3
139 set pppoe name "Test_ipv6" ppp lcp-echo-timeout 10
140 set pppoe name "Test_ipv6" clear-on-disconnect
141 set monitor cpu 100
142 set global-pro policy-manager primary outgoing-interface untrust
143 set global-pro policy-manager secondary outgoing-interface untrust
144 set nsmgmt bulkcli reboot-timeout 60
145 set ssh version v2
146 set config lock timeout 5
147 set modem speed 115200
148 set modem retry 3
149 set modem interval 10
150 set modem idle-time 10
151 set snmp port listen 161
152 set snmp port trap 162
153 set vrouter "untrust-vr"
154 exit
155 set vrouter "trust-vr"
156 unset add-default-route
157 exit
158 set vrouter "untrust-vr"
159 exit
160 set vrouter "trust-vr"
161 exit
162 ns5gt->
Attached Files
To refer to attachments on a page, use attachment:filename, as shown below in the list of files. Do NOT use the URL of the [get] link, since this is subject to change and can break easily.You are not allowed to attach a file to this page.