Re: Newbie issue with SSG140 MIP/VIP configuration for multipl public IPs on...
Glad you have it all figured out. Thanks for the update.
View ArticleRe: Internal ip address SSG 550M
Right your configuration looks correct. Can you run debug flow basic for the none working ip address and let's have a look at the results....
View ArticleRe: Internal ip address SSG 550M
I've attached the file.. The strange thing is, after i change the ip address it goes like route is invalid route is invalid and suddenly stops.
View ArticleRe: Internal ip address SSG 550M
I just notice. on the "routing" when i change the ip to be to 1.254 it goes from mask 24 to 32.. is it possible that's what is freezing the public ip and the internet.
View ArticleSSG 520M firmware upgrade issue
When trying to upgrade the firmware of SSG 520M System to the latest version ssg500.6.3.0r24, we received the below issue:LibCHFW:LibCHFW2(B)-> save software from usb ssg500.6.3.0r24 to flashIt will...
View ArticleRe: SSG 520M firmware upgrade issue
ScreenOS changed the signing key a couple years back. Your new image has the new key while you device has the old one. You are suppose to update the key just prior to the upgrade....
View ArticleRe: SSG 520M firmware upgrade issue
Thank you spuluka,Please note that I cannot use gui to install the new sign key, please can you share the procedure step by step using cli commands. Best Regards,
View ArticleRe: SSG 520M firmware upgrade issue
The signing key can only be installed from the gui. Once you delete the key from the cli command above the device should boot again and give you access to the gui for the key install.
View ArticleRe: SSG 520M firmware upgrade issue
But i am unable to open the gui for this firewall, all what i can do is working via cli.The key is .cert?
View ArticleRe: SSG 520M firmware upgrade issue
You can update the signing key via CLI using the following commands. It will require a TFTP server OR a USB thumb drive. save image-key tftp x.x.x.x filenameORsave image-key usb filename
View ArticleRe: How to config High Available on SSG Firewall?
Do we need to create a VSD group as part of HA if we don't care which server should be the master? Also, some of the documentation refers to having the manage IP as part of the VSI configuration. Why...
View ArticleSSG5 firmware
I have obtained an old SSG5 unit, but can't get the latest firmware 6.3.0r24 I fear this has been asked multiple times, but my account does not have the privileges needed. thanks in advance
View ArticleRe: SSG5 firmware
Hi, You need an active support account to gain access to the Software download section.
View ArticleRe: How to config High Available on SSG Firewall?
No, a VSD group is not necessary. VSD-0 gets created automatically when clustering is enabled. You just need to tweak the priority values on individual boxes. There is no 'seperate' manage-ip for NSRP....
View ArticleRe: SSG 520M firmware upgrade issue
As a quick workaround, you may also delte the auth key, effectively disabling image authentication. Process outlined here: https://kb.juniper.net/InfoCenter/index?page=content&id=KB25626# Please...
View ArticleRe: SSG 520M firmware upgrade issue
Hello Gokul, But if I delete the auth key, the device will not load the image on next reboot right?Why we dont install the new auth key to solve my problem?
View ArticleRe: SSG 520M firmware upgrade issue
Thanks rseibert, Yes I am using usb and not a TFTP server.Can you provide me the new signing key? and are you sure its only key issue or the image i am using is invalid?
View ArticleRe: SSG 520M firmware upgrade issue
No, deleting the auth key will simply disable image auth, device will boot up fine. It is a workaround if you cant arrange for USB/TFTP.If you have USB/TFTP, then go ahead with updating the key and...
View ArticleRe: How to config High Available on SSG Firewall?
As Gokul notes, creating vsd groups is optional but it is an important choice whether or not you use them. Without the vsd group your interfaces on the two devices are essentially independent of each...
View Article