Semperfi2004
IS-IT--Management
all;
I changed out an NS100 for a NS208. I took the config on the NS100 and modified it to work on the NS208.
When we hooked up the NS208, I wasn't able to ping anything internally or externally. All Interfaces showed Up Up.
Does anyone know of any reason, why this wouldn't work ? below is my config. I did take out all VPN's, MIP, DIP's etc.. Below is the basic config on the NS208 that was modified from the NS100
thanks
set clock timezone -4
set vrouter trust-vr sharable
unset vrouter "trust-vr" auto-route-export
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"
set admin name "netsceen"
set admin password "nM6+CDrdNmVCckBDEsNJEmEtoMFrLn"
set admin port xxxxx
set admin mail alert
set admin mail server-name "mail.xxxx.com"
set admin mail mail-addr1 "mail@xxxx.com"
set admin mail traffic-log
set admin auth timeout 60
set admin auth server "Local"
set admin format dos
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "DMZ" vrouter "trust-vr"
set zone "VLAN" vrouter "trust-vr"
set zone "Trust" tcp-rst
set zone "Untrust" block
unset zone "Untrust" tcp-rst
set zone "MGT" block
set zone "DMZ" tcp-rst
set zone "VLAN" block
set zone "VLAN" tcp-rst
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
set interface ethernet1 phy full 100mb
set interface ethernet2 phy full 100mb
set interface ethernet3 phy full 100mb
set interface "ethernet1" zone "Trust"
set interface "ethernet2" zone "DMZ"
set interface "ethernet3" zone "Untrust"
set interface "ethernet8" zone "Null"
unset interface vlan1 ip
set interface ethernet1 ip 10.1.1.254/22
set interface ethernet1 nat
set interface ethernet1 ip 10.1.10.0 255.255.255.0 secondary
set interface ethernet2 ip 10.9.8.1/24
set interface ethernet2 nat
set interface ethernet3 ip 12.1.1.254/24
set interface ethernet3 route
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface ethernet1 ip manageable
set interface ethernet2 ip manageable
set interface ethernet3 ip manageable
set interface ethernet3 manage ping
set interface ethernet3 manage telnet
set interface ethernet3 manage web
set flow tcp-mss
set flow path-mtu
set domain xxxxx.com
set hostname ns208
set ike respond-bad-spi 1
set ike soft-lifetime-buffer 15
set dns host dns1 10.1.1.162
set dns host dns2 10.1.1.161
set pki authority default scep mode "auto"
set pki x509 default cert-path partial
set syslog config "10.1.1.52"
set syslog config "10.1.1.52" facilities local0 local0
set syslog enable
set ssh version v2
set config lock timeout 5
set snmp community "xxxxxxxx" Read-Only Trap-on version v1
set snmp host "xxxxxxx" 10.1.1.16 255.255.255.255 trap v1
set snmp name "ns100"
set snmp port listen 161
set snmp port trap 162
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset add-default-route
set route 0.0.0.0/0 interface ethernet3 gateway 12.1.1.1
exit
I changed out an NS100 for a NS208. I took the config on the NS100 and modified it to work on the NS208.
When we hooked up the NS208, I wasn't able to ping anything internally or externally. All Interfaces showed Up Up.
Does anyone know of any reason, why this wouldn't work ? below is my config. I did take out all VPN's, MIP, DIP's etc.. Below is the basic config on the NS208 that was modified from the NS100
thanks
set clock timezone -4
set vrouter trust-vr sharable
unset vrouter "trust-vr" auto-route-export
set auth-server "Local" id 0
set auth-server "Local" server-name "Local"
set auth default auth server "Local"
set admin name "netsceen"
set admin password "nM6+CDrdNmVCckBDEsNJEmEtoMFrLn"
set admin port xxxxx
set admin mail alert
set admin mail server-name "mail.xxxx.com"
set admin mail mail-addr1 "mail@xxxx.com"
set admin mail traffic-log
set admin auth timeout 60
set admin auth server "Local"
set admin format dos
set zone "Trust" vrouter "trust-vr"
set zone "Untrust" vrouter "trust-vr"
set zone "DMZ" vrouter "trust-vr"
set zone "VLAN" vrouter "trust-vr"
set zone "Trust" tcp-rst
set zone "Untrust" block
unset zone "Untrust" tcp-rst
set zone "MGT" block
set zone "DMZ" tcp-rst
set zone "VLAN" block
set zone "VLAN" tcp-rst
set zone "Untrust" screen tear-drop
set zone "Untrust" screen syn-flood
set zone "Untrust" screen ping-death
set zone "Untrust" screen ip-filter-src
set zone "Untrust" screen land
set zone "V1-Untrust" screen tear-drop
set zone "V1-Untrust" screen syn-flood
set zone "V1-Untrust" screen ping-death
set zone "V1-Untrust" screen ip-filter-src
set zone "V1-Untrust" screen land
set interface ethernet1 phy full 100mb
set interface ethernet2 phy full 100mb
set interface ethernet3 phy full 100mb
set interface "ethernet1" zone "Trust"
set interface "ethernet2" zone "DMZ"
set interface "ethernet3" zone "Untrust"
set interface "ethernet8" zone "Null"
unset interface vlan1 ip
set interface ethernet1 ip 10.1.1.254/22
set interface ethernet1 nat
set interface ethernet1 ip 10.1.10.0 255.255.255.0 secondary
set interface ethernet2 ip 10.9.8.1/24
set interface ethernet2 nat
set interface ethernet3 ip 12.1.1.254/24
set interface ethernet3 route
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface ethernet1 ip manageable
set interface ethernet2 ip manageable
set interface ethernet3 ip manageable
set interface ethernet3 manage ping
set interface ethernet3 manage telnet
set interface ethernet3 manage web
set flow tcp-mss
set flow path-mtu
set domain xxxxx.com
set hostname ns208
set ike respond-bad-spi 1
set ike soft-lifetime-buffer 15
set dns host dns1 10.1.1.162
set dns host dns2 10.1.1.161
set pki authority default scep mode "auto"
set pki x509 default cert-path partial
set syslog config "10.1.1.52"
set syslog config "10.1.1.52" facilities local0 local0
set syslog enable
set ssh version v2
set config lock timeout 5
set snmp community "xxxxxxxx" Read-Only Trap-on version v1
set snmp host "xxxxxxx" 10.1.1.16 255.255.255.255 trap v1
set snmp name "ns100"
set snmp port listen 161
set snmp port trap 162
set vrouter "untrust-vr"
exit
set vrouter "trust-vr"
unset add-default-route
set route 0.0.0.0/0 interface ethernet3 gateway 12.1.1.1
exit