Table 8: Address Books Configuration
(continued)
Server IP Address-
Address Book
Zones
192.168.1.2/24
PC-Trust
Trust
•
Create security policies as shown in
Table 9: Security Policy Configuration
Action
To Zone
From Zone
Policy Name
Permit SMTP traffic
DMZ
Trust
permit-mail-trust-DMZ
Permit HTTP traffic
DMZ
DMZ
permit-http-in-DMZ
Configuration
CLI Quick
Configuration
To quickly configure this example, copy the following commands, paste them into a text
file, remove any line breaks, change any details necessary to match your network
configuration, copy and paste the commands into the CLI at the
[edit]
hierarchy level,
and then enter
commit
from configuration mode.
delete interfaces ge-0/0/1 unit 0 family ethernet-switching
set interfaces ge-0/0/1 unit 0 family inet address 192.168.2.1/24
set security zones security-zone DMZ interfaces ge-0/0/1 host-inbound-traffic
system-services all
set security zones security-zone DMZ address-book address Server-HTTP-1 192.168.2.2/24
set security zones security-zone DMZ address-book address Server-HTTP-2 192.168.2.3/24
set security zones security-zone DMZ address-book address Server-SMTP 192.168.2.4/24
set security zones security-zone DMZ address-book address-set DMZ-address-set-http
address Server-HTTP-1
set security zones security-zone DMZ address-book address-set DMZ-address-set-http
address Server-HTTP-2
set security zones security-zone trust address-book address PC-Trust 192.168.1.2/32
set security policies from-zone trust to-zone DMZ policy permit-mail-trust-DMZ match
source-address PC-Trust
set security policies from-zone trust to-zone DMZ policy permit-mail-trust-DMZ match
destination-address Server-SMTP
set security policies from-zone trust to-zone DMZ policy permit-mail-trust-DMZ match
application junos-smtp
set security policies from-zone trust to-zone DMZ policy permit-mail-trust-DMZ then
permit
set security policies from-zone DMZ to-zone DMZ policy permit-http-in-DMZ match
source-address DMZ-address-set-http
set security policies from-zone DMZ to-zone DMZ policy permit-http-in-DMZ match
destination-address DMZ-address-set-http
set security policies from-zone DMZ to-zone DMZ policy permit-http-in-DMZ match
application junos-http
set security policies from-zone DMZ to-zone DMZ policy permit-http-in-DMZ then permit
Copyright © 2016, Juniper Networks, Inc.
34
Getting Started Guide for Branch SRX Series
Summary of Contents for Junos OS
Page 6: ...Copyright 2016 Juniper Networks Inc vi Getting Started Guide for Branch SRX Series...
Page 8: ...Copyright 2016 Juniper Networks Inc viii Getting Started Guide for Branch SRX Series...
Page 10: ...Copyright 2016 Juniper Networks Inc x Getting Started Guide for Branch SRX Series...
Page 18: ...Copyright 2016 Juniper Networks Inc 2 Getting Started Guide for Branch SRX Series...
Page 20: ...Copyright 2016 Juniper Networks Inc 4 Getting Started Guide for Branch SRX Series...
Page 22: ...Copyright 2016 Juniper Networks Inc 6 Getting Started Guide for Branch SRX Series...
Page 32: ...Copyright 2016 Juniper Networks Inc 16 Getting Started Guide for Branch SRX Series...
Page 42: ...Copyright 2016 Juniper Networks Inc 26 Getting Started Guide for Branch SRX Series...
Page 44: ...Copyright 2016 Juniper Networks Inc 28 Getting Started Guide for Branch SRX Series...
Page 46: ...Copyright 2016 Juniper Networks Inc 30 Getting Started Guide for Branch SRX Series...
Page 54: ...Copyright 2016 Juniper Networks Inc 38 Getting Started Guide for Branch SRX Series...
Page 62: ...Copyright 2016 Juniper Networks Inc 46 Getting Started Guide for Branch SRX Series...
Page 78: ...Copyright 2016 Juniper Networks Inc 62 Getting Started Guide for Branch SRX Series...
Page 86: ...Copyright 2016 Juniper Networks Inc 70 Getting Started Guide for Branch SRX Series...
Page 90: ...Copyright 2016 Juniper Networks Inc 74 Getting Started Guide for Branch SRX Series...
Page 155: ...PART 5 Index Index on page 141 139 Copyright 2016 Juniper Networks Inc...
Page 156: ...Copyright 2016 Juniper Networks Inc 140 Getting Started Guide for Branch SRX Series...