since the value is fixed and set to 8. NSM validates your entries and prompts a
correction in case of an error.
8.
Click
OK
to add the multicast group address.
Adding Static DNS Host Addresses
This ScreenOS 5.3 or later feature lets you create a static host name with multiple IP
addresses. You can use this feature to create dynamic addressing in NSM.
To add multiple static host addresses:
1.
In the navigation tree,
2.
Double-click the device you want to configure. The device must be running ScreenOS
5.3 or later.
3.
In the navigation tree of the new dialog box, select
Network
>
DNS
.
4.
Click
Settings
to open the Device Settings dialog box.
5.
Click the Add icon, enter the host name and host IP address, then click
OK
.
6.
Click
OK
to save the changes and close the dialog box.
Example: Using Static Addresses to Share a FW Policy
Static addresses allow two sites with different IP addresses to share a single firewall
policy. For example, each site might have a Web server, each with a different IP address.
If you define an address object using the hostname “webserver” and then using that
object in the firewall policy, the device will resolve the address object's hostname to the
correct IP for that device as defined by its static host entry.
1.
In the navigation tree, select
Object Manager > Address Objects
.
2.
Click the Add icon, then select
Host
to open the New Host dialog box.
3.
Enter the same name in the Name field that you entered for the Device host name
in the previous section. These values are case sensitive and must match exactly.
4.
Click
OK
to save the name and close the dialog box.
5.
Return to the navigation tree and select
Security Policy
.
6.
Click the
Add
icon and enter the security policy name, then click
OK
.
7.
Double-click the name of the security policy you just created.
8.
Right-click the value in the Source column or the Destination column.
9.
Select the address object you just created, click
Add
, then click
OK
. When the address
object is pushed to a device, the host name resolves dynamically. One policy can be
assigned to multiple devices.
NOTE:
If an address object is used in multiple zones, NSM pushes the address object
into the zones without changing its name. When you import a device, NSM combines
address objects with the same name and same content from different zones into a
single address object.
327
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Objects
Содержание NETWORK AND SECURITY MANAGER 2010.3
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Страница 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Страница 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Страница 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Страница 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Страница 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Страница 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Страница 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Страница 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Страница 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Страница 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Страница 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Страница 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Страница 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Страница 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Страница 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Страница 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Страница 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Страница 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...