MoonPoint Support Logo

 

Shop Amazon Warehouse Deals - Deep Discounts on Open-box and Used ProductsAmazon Warehouse Deals



Advanced Search
February
Sun Mon Tue Wed Thu Fri Sat
      1
       
2017
Months
Feb


Wed, Feb 01, 2017 10:42 pm

Allowing the untrusted interface on a Juniper SRX router/firewall to be pinged

If you wish to allow the untrust interface, which is usually the Internet-facing interface on a Juniper Networks SRX router/firewall running the Junos operating system, to be pinged from external systems, you can use the command set security zone security-zone untrust interface ge-0/0/0.0 host-inbound-traffic system-services ping after placing the device in configuration mode with the configure command, presuming, of course, that the untrust interface is ge-0/0/0.0. If it is some other port on the router, substitute that port identifier, instead.

root@Alder> configure
Entering configuration mode

[edit]
root@Alder# set security zone security-zone untrust interface ge-0/0/0.0 host-inbound-traffic system-services ping

[edit]
root@Alder# commit
commit complete

[edit]
root@Alder#

Afer committing the configuration, you should be able to successfully ping the IP address of the untrusted, i.e., Internet side of the device.

[/security/firewalls/SRX] permanent link

Valid HTML 4.01 Transitional

Privacy Policy   Contact

Blosxom logo