background image

*HWWLQJ 6WDUWHG *XLGH

%$6,&6(&85,7<$1'32/,&<$'0,1,675$7,21

<RXPXVWUHJLVWHU\RXUSURGXFWDWZZZQHWVFUHHQFRPFVRWRDFWLYDWHFHUWDLQ6FUHHQ26
VHUYLFHVVXFKDVWKH'HHS,QVSHFWLRQ6LJQDWXUH6HUYLFH$IWHUUHJLVWHULQJXVHWKH
:HE8,RU&/,WRREWDLQWKHVXEVFULSWLRQIRUWKHVHUYLFH

6WHS

Using Policy Wizards

. By default, the NetScreen-5GT permits 

workstations in your network to start sessions with outside 
workstations, while outside workstations cannot start sessions with 
your workstations. You can set up policies that tell the device what 
kinds of sessions to restrict or permit.
To set up a policy to either restrict the kinds of traffic that can be 
initiated from inside your network to go out to the Internet, or to 
permit certain kinds of traffic that can be initiated from outside 
workstations to your network, use the WebUI Policy Wizard. In the 
WebUI menu column, click 

Wizards

 > 

Policy

. Follow the directions 

in the Wizard to configure a policy.
You can use the Wizards only when the device is in the default Trust-
Untrust port mode. For details on setting up policies, see the 

NetScreen Concepts & Examples ScreenOS Reference Guide

.

6WHS

Using Protection Options.

 The firewall attack protection (SCREEN) 

menu enables you to tailor detection and threshold levels for a range 
of potential attacks.
a.

In the WebUI menu column, click 

Screening > Screen

.

b.

Select the zone for which you want to configure firewall
attack protection.

c.

Select the appropriate protection options, then click 

Apply

Remember these features must be configured on each zone 
where they are required.

6WHS

Verifying Access.

 To verify that workstations in your network can 

access resources on the Internet, start a Web browser from any 
workstation in the network and enter the URL: www.netscreen.com.

6WHS

You can choose to have the NetScreen-5GT assign IP addresses to 
hosts in your network.

Select 

Yes 

if the NetScreen-5GT is to act as a DHCP server and 

assign dynamic IP addresses to hosts in the Trust zone interface. 
Enter a range for the assigned IP addresses or enter the 
address(es) of the DNS server(s). If you specify an IP address 
range that is in a different subnetwork than the Trust 
subnetwork, then your workstation and the Trust zone interface 
of the NetScreen-5GT might be in different subnetworks. To 
manage the NetScreen-5GT using the WebUI,

 

ensure that your 

workstation and the NetScreen-5GT are in the same 
subnetwork.

Select 

No

 if you do not want the NetScreen-5GT to assign IP 

addresses to hosts in the Trust zone interface.

Click 

Next

.

6WHS

A confirmation screen like the above appears:

Click 

Previous

 to modify configuration information. 

Click 

Next

 to enter the configuration.

Your system reboots after clicking Next.

6WHS

At the final review configuration window, click 

Finish

. Launch a 

Web browser. In the URL address field, enter the Trust zone interface 
or Work zone interface IP address. (Your workstation and the 
NetScreen-5GT must be in the same subnetwork.)
Your NetScreen configuration is complete.

Copyright © 2004 NetScreen Technologies Inc. 

All rights reserved. NetScreen, NetScreen Technologies, GigaScreen, NetScreen-Security Manager, NetScreen-Remote, NetScreen ScreenOS and the NetScreen logo are trademarks 
and registered trademarks of NetScreen Technologies, Inc. in the United States and other countries. All other trademarks and registered trademarks are the property of their respective 
companies.

315HY%

Summary of Contents for 5GT

Page 1: ...at the Status LED blinks green This indicates the device is operating normally c Ensure that the Link Activity LEDs glow green for the connected interfaces This indicates the device has network connectivity 6WHS Configure the workstation to access the NetScreen 5GT via a Web browser a Ensure that your workstation is properly connected to your LAN use the diagram above b Change the TCP IP settings ...

Page 2: ...erface is 192 168 1 1 24 You can change this address to match IP addresses that exist on your network Assigning IP Addresses to Hosts in Trust Zone Enabling DHCP Server You can choose to have the NetScreen 5GT assign IP addresses via DHCP to hosts in your network If you have the NetScreen 5GT assign IP addresses then you can define the range of addresses to be assigned You need to ensure that the ...

Page 3: ...ess or a dynamic IP address assigned via DHCP or PPPoE Select Dynamic IP via DHCP to enable the NetScreen 5GT to receive an IP address for the Untrust zone interface from an ISP Select Dynamic IP via PPPoE to enable the NetScreen 5XG to act as a PPPoE client receiving an IP address for the Untrust zone interface from an ISP Enter the Username and Password assigned by the ISP Select Static IP to as...

Page 4: ...workstations in your network can access resources on the Internet start a Web browser from any workstation in the network and enter the URL www netscreen com 6WHS You can choose to have the NetScreen 5GT assign IP addresses to hosts in your network Select Yes if the NetScreen 5GT is to act as a DHCP server and assign dynamic IP addresses to hosts in the Trust zone interface Enter a range for the a...

Reviews: