networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 9 posts ] 
Author Message
PostPosted: Tue Aug 07, 2012 9:20 am 
Offline
New Member
New Member

Joined: Tue Aug 07, 2012 9:01 am
Posts: 13
I have a medical office with a Juniper 208 Firewall. They want to add an Wireless access point for their patients in the waiting room. This need to be separate and unable to access their secure private network. What is the simplest way of doing this with the Juniper 208? Separate Port? Please explain config.

-Shawn


Top
 Profile  
 
PostPosted: Tue Aug 07, 2012 9:26 am 
Offline
CCIE #38070
CCIE #38070
User avatar

Joined: Wed Jun 18, 2008 7:49 am
Posts: 12471
Location: London, UK
Certs: CCIE ,CC-NP/IP, JNCIP-SP, JNCIS-ENT, BC-/SPNE/NP
separate port, separate zone.

_________________
www.mellowd.co.uk/ccie/


Top
 Profile  
 
PostPosted: Tue Aug 07, 2012 9:45 am 
Offline
New Member
New Member

Joined: Tue Aug 07, 2012 9:01 am
Posts: 13
Thanks for the reply. I thought that might have been the correct setup. I tried that before but was unable to get internet access with that config. Would you be able to provide a sample config?


Top
 Profile  
 
PostPosted: Tue Aug 07, 2012 9:52 am 
Offline
CCIE #38070
CCIE #38070
User avatar

Joined: Wed Jun 18, 2008 7:49 am
Posts: 12471
Location: London, UK
Certs: CCIE ,CC-NP/IP, JNCIP-SP, JNCIS-ENT, BC-/SPNE/NP
Did you create rules between the zones? Enabled NAT? Checked the logs?

_________________
www.mellowd.co.uk/ccie/


Top
 Profile  
 
PostPosted: Tue Aug 07, 2012 10:19 am 
Offline
New Member
New Member

Joined: Tue Aug 07, 2012 9:01 am
Posts: 13
Here is what I have ...

Created New Virtual Route:
name: public-vr

Created New Zone:
name: Public
virtual router: public-vr
interface: ethernet4

Set Interface:
interface: etnernet4
zone: Public
ip: static (172.21.20.1/24)
mode: NAT

Created New Policy:
direction: From Public To Untrust
service: http, https
action: Permit

Not sure where I went wrong?

-Shawn


Top
 Profile  
 
PostPosted: Tue Aug 07, 2012 10:21 am 
Offline
CCIE #38070
CCIE #38070
User avatar

Joined: Wed Jun 18, 2008 7:49 am
Posts: 12471
Location: London, UK
Certs: CCIE ,CC-NP/IP, JNCIP-SP, JNCIS-ENT, BC-/SPNE/NP
Why did you create a new virtual router? All you need is new zones

Also you've allowed http and https, but what about DNS etc?

_________________
www.mellowd.co.uk/ccie/


Top
 Profile  
 
PostPosted: Tue Aug 07, 2012 10:38 am 
Offline
New Member
New Member

Joined: Tue Aug 07, 2012 9:01 am
Posts: 13
Ok, looks good.

One more question. Is there a way to restrict access to the internet on that interface with a simple username and password. This is just to keep the honest people honest. This would allow the front desk receptionist to hand out the username/password to their clients in the lobby and disallow their neighbors to gain free internet access. I know I could configure a key on the wireless radio but I want to keep it simple for the staff and patients.

- Thanks, Shawn


Top
 Profile  
 
PostPosted: Tue Aug 07, 2012 10:39 am 
Offline
CCIE #38070
CCIE #38070
User avatar

Joined: Wed Jun 18, 2008 7:49 am
Posts: 12471
Location: London, UK
Certs: CCIE ,CC-NP/IP, JNCIP-SP, JNCIS-ENT, BC-/SPNE/NP
You can't do that on the firewall

_________________
www.mellowd.co.uk/ccie/


Top
 Profile  
 
PostPosted: Sat Aug 11, 2012 11:39 am 
Offline
New Member
New Member

Joined: Thu Jul 19, 2012 12:18 pm
Posts: 9
Certs: None at present (all expired)
would enabling Webauth on the that interface on the 208 do what you want?

Mark

tspatrick wrote:
Ok, looks good.

One more question. Is there a way to restrict access to the internet on that interface with a simple username and password. This is just to keep the honest people honest. This would allow the front desk receptionist to hand out the username/password to their clients in the lobby and disallow their neighbors to gain free internet access. I know I could configure a key on the wireless radio but I want to keep it simple for the staff and patients.

- Thanks, Shawn


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 9 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group