Quantcast
Channel: Juniper Networks
Viewing all 439 articles
Browse latest View live

Allow RDP on non-standard port - SSG-140

0
0

Hi everyone. I'll be first to admit I have little-to-no experience with Juniper devices. I'm a Cisco/SonicWALL guy usually.

Long story short - we just took over a new customer from an existing IT provider, they have a Juniper SSG-140 and RDP is wide open to their terminal server from the outside. First thing we did was fire up our RMM and saw over 100k failed logins to the terminal server - about 10k/day lately.

I just want to change the port for now to prevent this and work out a VPN solution with them later.

I want to pick a non-standard RDP port. See attached screenshot of current configuration for RDP.

I tried changing the source port to 3333 to 3333 for example on both TCP/UDP, but opening up an RDP session from the outside to their public IP:3333 doesn't work after making that change, and neither does leaving standard 3389 either.

How...


How to bridge two vlan together using screenos

0
0

Hi there,

I need some assistance with this. We are in the midst of an office move. We currently have a Metrolan with tag 1729 that connects the old office back to our datacenter. This metrolan shares internet from our datacenter to our current office.

When we ordered our new service, I was expected them to extend our Metrolan with the same tag 1729 in order to provide internet at the new location as well as connecting to services still located at the old office (temporarily). They did not do that. they provided a new vlan tagged 282. This works as I'm able to connect to the datacenter using a different temporary subnet however how to do I bridge the 1729 and 282 vlan together so internet (as associated static IP's) are broadcasted at the new location? do I need a vlan aware switch now between the edge router/firewall or am I able to do...

PulseSecureVPN: what are we doing wrong between sites?

0
0

Hello all,

This one's been driving both me and my other administrator absolutely bonkers. We're a small LLC doing mostly open source work and communal projects, so, needless to say, it's not as if we've got boatloads of cash to pour into the latest and greatest VPN appliances. Until we figure out IPSec, we're stuck with the free version of PulseSecure (very clunky, very slow). The issue is that we're got a few sites; in Massachusetts, Wilmington and Brighton, and then in others, Tampa, FL, and then Virginia Beach, VA. What is getting to me is the following: I have domain admin access to our Hyper-V environment, so as long as my computer is on the PulseSecure VPN, I ought to be able to see all of my Hyper-V servers within my manager at once. I can ... for the most part; I can see my own site, which is Wilmington, the Tampa site, and the...

Juniper MX240 L2TP LNS/LAC

0
0

Hi all,

While I have experience of configuring already built LNS, I have not had to build one from scratch... now, I have read the Juniper site carefully regarding configuring an LNS and a LAC.... I do not want to have to try and piece together thousands of pages of documents to get to the real meat. 

Does anyone have experience of building an LNS and a LAC, with junos, on here please?

Thanks

Juniper EX2200-C Switch

0
0

I have two Juniper EX2200-C switches connected to an in-line proxy appliance and am able to ping google.com from the network but unable to get to any websites or send/receive email. When we take the juniper switches out and leave the proxy appliance in-line we have no issues with web traffic or email.

Is anyone familiar with these switches and possibly have an idea if they may be "smart" switches and applying any rules to web traffic or blocking in some way?

Feedback Wanted - Juniper Networks Technical Support

0
0

Hi Spiceheads!  

Reaching out to get your feedback and thoughts around the potential of Juniper Networks offering you technical support inside the community.

Without stating the obvious:

 - how useful would you find this?

- would you appreciate being kept up to date on product lines etc?

I appreciate your time & feedback

Best,

Joel

Juniper EX cannot Ping Certain Hosts

0
0

Hello,

Just got done replacing a bunch of Network Gear with Juniper EX series switches. Im having an issue with one stack that is working for the most part. Most Hosts (windows PCs) work fine.

I have several ancillary devices attached to the switches such as NAS, Backup appliance and SIEM appliance, WAPs. All of these ancillary devices do not ping, nor can i reach them in the normal capacity.

See the config below if there is anything that stands out as to why this would be

}
name-server {
10.24.0.100;
10.24.0.115;
}
services {
ssh {
protocol-version v2;
}
netconf {
ssh;
}
web-management {
http;
}
dhcp {
traceoptions {
file dhcp_logfile;
level all;
flag all;
}
}
}
syslog {
user * {
any emergency;
}
file messages {
any notice;
...

add a new vlan to existing vlan infrastructure

0
0

Hi experts., 

I have a network with 10 vlans.(vlan 1, vlan 100, vlan 172 etc..). I need to create a new VLAN for my media devices. (VLAN 199). 

1) Pls help me on configurations in Access switches, and ports,
2) Core switch and ports
3) Firewall configurations.

Note: switches are Juniper switches and the firewall is Sonicwall. 

check the diagram for the network plan to get an idea.  


Juniper SRX240 Contract Renewal

0
0

Hi We have 2xSRX240 and it's contract expired on september end. we tried to renew the contract on october first week but support team says it's EOL can't offer the Hardware Replacement coverage though their website says NBD discontinued date is 5/10/2018 and Juniper team is keen in selling new devices ratherthan renewing the contract. Is there anyone there who face the same issue ?

Juniper EX3300 - OS Update Entitlement

0
0

Im looking at purchasing a couple of Juniper switches for our branch offices. Specifically, I want to buy 2 x EX3300-24T. These offer all of the features I need at a reasonable price.
The one thing im struggling to understand is whether I need support contracts for these switches in order to maintain access to OS/firmware updates.
Ive found conflicting information, so Im hoping for some clarity from the community.
This PDF seems to indicate that the 3300 comes with OS update rights, but it's not 100% clear... 

https://www.juniper.net/support/warranty/990240.pdf

(first paragraph on 2nd page)

Thanks!

How can I route provider's VLANs with EX2200?

0
0

Hello.
Company has an headquarter and several remore branch offices. Provider provides L2 VPN from the HQ to the each branch office. To the HQ packets comes into the VLANs. One branch - 1 VLAN.
At the HQ there are 1 cable from the provider and it's connected to Juniper EX2200 JunOS 11.4R1.6 at port ge-0/0/23. Port ge-0/0/4 is connected to the LAN of the HQ.
IP addressing is the same at the HQ and branches.
The goal is to give an access to the local resources of the HQ to a branch and vice versa.
On the Juniper there are created VLANs with provider's IDs 1800-1807. They are named. Port ge-0/0/23 is setted as trunk and is a member of all VLANs.
Problem is, I can assign to ge-0/0/4 only 1 VLAN. And there will be a connection to only 1 branch. But if I make another access port with another VLAN ID and connect it to the HQ LAN, then only one of...

Juniper, Can see interfaces with show arp for half the build

0
0

First, I am new to networking and just inherited a duel juniper stack. One stack of 5 network switches is located upstairs while the other 5 is located downstairs. These are Juniper EX3400-48p with Junos 15.1x53-d56. I am using putty to remote into both stacks. I am trying to find the interface for a mac address. Mac addresses located upstairs will show me the interface while the units downstairs will not. The picture shows the two locations. The first command is a mac address that is upstairs connected to the upstairs stack while the second command is the downstairs connected to the downstairs stack.


I have tried the same commands on the second stack but the second stack does not recognizethe mac addresses. This is causing a slow down on interface changes because I have to physically track down the cable. What is setting turned off or...

Juniper SSG5 Not Booting

0
0

Hi all,

I recently attempted to update my SSG5 I first had to update the Image Signature Key with a new one and was about to download the update and then ran into an error saying i could download it due to incorrect permissions. So i turn it off and the next day i boot it up and it doesn't boot the status light does not flash after about 2 mins like it use to and doesn't do anything except light up the Power And Status Lights on a solid green. I have tried resetting it numerous times by holding reset for 6 seconds waiting 2 and holding for another 6 seconds but that doesn't work please help !

Server 2012 R2 DHCP Option 82

0
0

I am trying to figure out an issue with DHCP Relay in my network. The L3 switches are Juniper EX4300s and the server is 2012 R2. The main issue is, when a wireless client (already connected to an AP) changes location associates to an AP on a different subnet, the client sends a DHCP Request to the server, and the server replies with a NAK, like it should. That NAK does not reach the client and is dropped by the switch, causing the client to repeatedly send Requests until it times out.

I have been working with Juniper support on this for a while and they have have come back with the following:
"The DHCP sever should return the option 82 attribute in the NAK message, but it doesn't do this. When this option is not available, the dhcp relay agent is not able to find the client in the table entry, and will not forward the message... focus on...

Latency on all backbones of Juniper router

0
0

After installing one installation package i.e JUNOS Services Mobile Subscriber Service Container package on Juniper mx480 router i am getting latency on backbone interfaces

J480-R show version
Model: mx480
Junos: 16.1R6.7
JUNOS OS Kernel 64-bit [20171012.356211_builder_stable_10]
JUNOS OS libs [20171012.356211_builder_stable_10]
JUNOS OS runtime [20171012.356211_builder_stable_10]
JUNOS OS time zone information [20171012.356211_builder_stable_10]
JUNOS OS libs compat32 [20171012.356211_builder_stable_10]
JUNOS OS 32-bit compatibility [20171012.356211_builder_stable_10]
JUNOS py extensions [20171121.225603_builder_junos_161_r6]
JUNOS py base [20171121.225603_builder_junos_161_r6]
JUNOS OS crypto [20171012.356211_builder_stable_10]
JUNOS network stack and utilities [20171121.225603_builder_junos_161_r6]
JUNOS libs...


Help with Juniper SRX configuration

0
0

I am somewhat familiar with Juniper ScreenOS, but not with JunOS. We have recently acquired some SRX320 firewalls running 17.4. I am comfortable entering commands via the CLI, but ideally I need support configuring via (the truly awful) J-Web, specifically a VDSL module in ADSL mode. I have tried following a number of Juniper KB articles and have contacted JTAC, but neither have been fruitful, I simply can't get a connection.

I have tried:-

https://www.juniper.net/documentation/en_US/junos/topics/example/adsl-pim-security-interface-configu...

https://www.juniper.net/documentation/en_US/junos/topics/example/vdsl2-interface-in-adsl-mode-securi...

https://kb.juniper.net/InfoCenter/index?page=content&id=KB25400

I realise this is all a bit vague, but perhaps someone has some recommendations for resources or training materials where I can begin...

v15 vs v17 software, which one?

0
0

For a beginner like me I'm confused as to why there are 2 versions of JunOS listed in the downloads section for my SRX320 devices. Before I go ahead and update all 23 units, can someone summarise in a nutsehell why I'd chose v15 over v17 and vice versa please?

question about point 2 point configuration

0
0

we have a gotten a point 2 point between Location A and Location B. we had to move buildings at our Location B side.
our previous p2p configuration is with a juniper ex4300 on both sides and it worked fine.
this is a piece of the config that relates to the p2p configuration that worked before.

ge-1/0/31 {
description "Point 2 Point";
mtu 1500;
ether-options {
no-auto-negotiation;
link-mode full-duplex;
speed {
100m;
}
}
unit 0 {
family ethernet-switching {
vlan {
members P2P;
}
}
}
}

routing-options {
static {
route 192.168.151.0/24 next-hop 192.168.10.11;
route 192.168.100.0/24 next-hop 192.168.10.11;
}
}

vlan {
unit 166 {
family inet {
address 192.168.10.10/24;
}
}

vlans {
P2P {
vlan-id 166;
l3-interface vlan.166;
}
}

the previous p2p was copper hand off on both Location A and Location B side.
when we moved location B to a new building someone had gone and gooved and...

Juniper Wireless

0
0

So we have Juniper wireless contoller(WLC880R and using WLA532-WW access points. Without a support contract to juniper they dont allow any firmware updates/patches etc.

The question is regarding this Krack vulnerability. What is everyone suggestion if im unable to  patch the hardware?

cheers

juniper ex4300 firmware update broke connection to firewall

0
0

i am messing around with a test switch to see what would break on our production switches after i did a firmware update.
i am trying to update from 14.1x53-D30.3 to 14.1x53-D40.8, applying would break the connection to our firewall on interface 22.

Information for snapshot on internal (/dev/da0s1a) (primary)
Creation date: Feb 10 09:56:19 2018
JUNOS version on snapshot:
jdocs-ex: 14.1X53-D40.8
junos : ex-14.1X53-D40.8
junos-ex-4300: 14.1X53-D40.8
jweb-ex: 14.1X53-D40.8

Information for snapshot on internal (/dev/da0s2a) (backup)
Creation date: Oct 2 10:56:20 2015
JUNOS version on snapshot:
jdocs-ex: 14.1X53-D30.3
junos : ex-14.1X53-D30.3
junos-ex-4300: 14.1X53-D30.3
jweb-ex: 14.1X53-D30.3

a quick detail, shows the interface has a physical link up.

juniper@EX4300 show interfaces ge-0/0/22 detail
Physical interface: ge-0/0/22, Enabled,...

Viewing all 439 articles
Browse latest View live




Latest Images