{"id":58,"date":"2023-04-09T02:57:14","date_gmt":"2023-04-08T23:57:14","guid":{"rendered":"https:\/\/onurunlu.com.tr\/?p=58"},"modified":"2023-04-09T02:57:14","modified_gmt":"2023-04-08T23:57:14","slug":"btk-ara-baglantisi-icin-juniper-ssg20-firewall-tanimlamasi","status":"publish","type":"post","link":"https:\/\/onurunlu.com.tr\/?p=58","title":{"rendered":"BTK ARA BA\u011eLANTISI \u0130\u00c7\u0130N JUNIPER SSG20 FIREWALL TANIMLAMASI"},"content":{"rendered":"<p>Servis Sa\u011flay\u0131c\u0131 Lisans\u0131 almak isteyen bir\u00e7ok firma ve arkada\u015f\u0131n en b\u00fcy\u00fck problemlerinden biri de BTK&#8217; n\u0131n lisans i\u015flemlerinden \u00f6nce baz\u0131 isterleri olmas\u0131d\u0131r.<\/p>\n<p>Bunlardan biri de altyap\u0131 kurulumudur. Bu makalede size Juniper SSG20 serisi firewall i\u00e7in \u00f6rnek bir konfigurasyon payla\u015fmak istedim.<\/p>\n<p>Eminim ki bu \u00f6rnek konfigurasyona internet \u00fczerinde ula\u015famayabilirsiniz. Umar\u0131m yararl\u0131 bir payla\u015f\u0131m olur.<\/p>\n<p>Unutmayal\u0131m, Bilgi payla\u015ft\u0131k\u00e7a \u00e7o\u011fal\u0131r &#8230;<\/p>\n<hr \/>\n<p>unset key protection enable<\/p>\n<p>set clock timezone 0<\/p>\n<p>set vrouter trust-vr sharable<\/p>\n<p>set vrouter &#8220;untrust-vr&#8221;<\/p>\n<p>exit<\/p>\n<p>set vrouter &#8220;trust-vr&#8221;<\/p>\n<p>unset auto-route-export<\/p>\n<p>exit<\/p>\n<p>set alg appleichat enable<\/p>\n<p>unset alg appleichat re-assembly enable<\/p>\n<p>set alg sctp enable<\/p>\n<p>set auth-server &#8220;Local&#8221; id 0<\/p>\n<p>set auth-server &#8220;Local&#8221; server-name &#8220;Local&#8221;<\/p>\n<p>set auth default auth server &#8220;Local&#8221;<\/p>\n<p>set auth radius accounting port 1646<\/p>\n<p>set admin name &#8220;netscreen&#8221; <strong>(netscreen YER\u0130NE YEN\u0130 B\u0130R USER TANIMLAYIN)<\/strong><\/p>\n<p>set admin password &#8220;&#8221; <strong>(YEN\u0130 B\u0130R \u015e\u0130FRE TANIMLAYIN)<\/strong><\/p>\n<p>set admin auth web timeout 10<\/p>\n<p>set admin auth dial-in timeout 3<\/p>\n<p>set admin auth server &#8220;Local&#8221;<\/p>\n<p>set admin format dos<\/p>\n<p>set zone &#8220;Trust&#8221; vrouter &#8220;trust-vr&#8221;<\/p>\n<p>set zone &#8220;Untrust&#8221; vrouter &#8220;trust-vr&#8221;<\/p>\n<p>set zone &#8220;DMZ&#8221; vrouter &#8220;trust-vr&#8221;<\/p>\n<p>set zone &#8220;VLAN&#8221; vrouter &#8220;trust-vr&#8221;<\/p>\n<p>set zone &#8220;Untrust-Tun&#8221; vrouter &#8220;trust-vr&#8221;<\/p>\n<p>set zone &#8220;Trust&#8221; tcp-rst<\/p>\n<p>set zone &#8220;Untrust&#8221; block<\/p>\n<p>unset zone &#8220;Untrust&#8221; tcp-rst<\/p>\n<p>set zone &#8220;MGT&#8221; block<\/p>\n<p>unset zone &#8220;V1-Trust&#8221; tcp-rst<\/p>\n<p>unset zone &#8220;V1-Untrust&#8221; tcp-rst<\/p>\n<p>set zone &#8220;DMZ&#8221; tcp-rst<\/p>\n<p>unset zone &#8220;V1-DMZ&#8221; tcp-rst<\/p>\n<p>unset zone &#8220;VLAN&#8221; tcp-rst<\/p>\n<p>unset zone &#8220;Untrust&#8221; screen tear-drop<\/p>\n<p>unset zone &#8220;Untrust&#8221; screen syn-flood<\/p>\n<p>unset zone &#8220;Untrust&#8221; screen ping-death<\/p>\n<p>unset zone &#8220;Untrust&#8221; screen ip-filter-src<\/p>\n<p>unset zone &#8220;Untrust&#8221; screen land<\/p>\n<p>set zone &#8220;V1-Untrust&#8221; screen tear-drop<\/p>\n<p>set zone &#8220;V1-Untrust&#8221; screen syn-flood<\/p>\n<p>set zone &#8220;V1-Untrust&#8221; screen ping-death<\/p>\n<p>set zone &#8220;V1-Untrust&#8221; screen ip-filter-src<\/p>\n<p>set zone &#8220;V1-Untrust&#8221; screen land<\/p>\n<p>set interface adsl1\/0 phy operating-mode auto<\/p>\n<p>set interface &#8220;ethernet0\/0&#8221; zone &#8220;Untrust&#8221;<\/p>\n<p>set interface &#8220;ethernet0\/1&#8221; zone &#8220;Null&#8221;<\/p>\n<p>set interface &#8220;wireless0\/0&#8221; zone &#8220;Trust&#8221;<\/p>\n<p>set interface &#8220;bgroup0&#8221; zone &#8220;Trust&#8221;<\/p>\n<p>set interface &#8220;adsl1\/0&#8221; pvc 8 35 mux llc protocol bridged qos ubr zone &#8220;Untrust&#8221;<\/p>\n<p>set interface bgroup0 port ethernet0\/1<\/p>\n<p>set interface bgroup0 port ethernet0\/2<\/p>\n<p>set interface bgroup0 port ethernet0\/3<\/p>\n<p>set interface bgroup0 port ethernet0\/4<\/p>\n<p>unset interface vlan1 ip<\/p>\n<p>set interface ethernet0\/0 ip<strong> (BTK NIN VERD\u0130\u011e\u0130 IP ADRESINI G\u0130R\u0130N ! XXX.XXX.XXX.XXX\/27)<\/strong><\/p>\n<p>set interface ethernet0\/0 route<\/p>\n<p>set interface bgroup0 ip <strong>\u00a0(BTK NIN VERD\u0130\u011e\u0130 IP ADRESINI G\u0130R\u0130N ! XXX.XXX.XXX.XXX\/29)<\/strong><\/p>\n<p>set interface bgroup0 nat<\/p>\n<p>set interface ethernet0\/0 gateway <strong>\u00a0(BTK NIN VERD\u0130\u011e\u0130 GATEWAY\u0130 G\u0130R\u0130N ! XXX.XXX.XXX.XXX)<\/strong><\/p>\n<p>unset interface vlan1 bypass-others-ipsec<\/p>\n<p>unset interface vlan1 bypass-non-ip<\/p>\n<p>set interface ethernet0\/0 ip manageable<\/p>\n<p>set interface bgroup0 ip manageable<\/p>\n<p>set interface ethernet0\/0 manage ping<\/p>\n<p>set interface ethernet0\/0 manage ssh<\/p>\n<p>set interface ethernet0\/0 manage telnet<\/p>\n<p>set interface ethernet0\/0 manage snmp<\/p>\n<p>set interface ethernet0\/0 manage web<\/p>\n<p>set interface bgroup0 manage mtrace<\/p>\n<p>set interface ethernet0\/0 vip interface-ip<\/p>\n<p>set interface bgroup0 dhcp server service<\/p>\n<p>set interface bgroup0 dhcp server auto<\/p>\n<p>unset interface bgroup0 dhcp server config next-server-ip<\/p>\n<p>set interface &#8220;serial0\/0&#8221; modem settings &#8220;USR&#8221; init &#8220;AT&amp;F&#8221;<\/p>\n<p>set interface &#8220;serial0\/0&#8221; modem settings &#8220;USR&#8221; active<\/p>\n<p>set interface &#8220;serial0\/0&#8221; modem speed 115200<\/p>\n<p>set interface &#8220;serial0\/0&#8221; modem retry 3<\/p>\n<p>set interface &#8220;serial0\/0&#8221; modem interval 10<\/p>\n<p>set interface &#8220;serial0\/0&#8221; modem idle-time 10<\/p>\n<p>set flow tcp-mss<\/p>\n<p>unset flow tcp-syn-check<\/p>\n<p>unset flow tcp-syn-bit-check<\/p>\n<p>set flow reverse-route clear-text prefer<\/p>\n<p>set flow reverse-route tunnel always<\/p>\n<p>set pki authority default scep mode &#8220;auto&#8221;<\/p>\n<p>set pki x509 default cert-path partial<\/p>\n<p>set crypto-policy<\/p>\n<p>exit<\/p>\n<p>set ike respond-bad-spi 1<\/p>\n<p>set ike ikev2 ike-sa-soft-lifetime 60<\/p>\n<p>unset ike ikeid-enumeration<\/p>\n<p>unset ike dos-protection<\/p>\n<p>unset ipsec access-session enable<\/p>\n<p>set ipsec access-session maximum 5000<\/p>\n<p>set ipsec access-session upper-threshold 0<\/p>\n<p>set ipsec access-session lower-threshold 0<\/p>\n<p>set ipsec access-session dead-p2-sa-timeout 0<\/p>\n<p>unset ipsec access-session log-error<\/p>\n<p>unset ipsec access-session info-exch-connected<\/p>\n<p>unset ipsec access-session use-error-log<\/p>\n<p>set url protocol websense<\/p>\n<p>exit<\/p>\n<p>set policy id 1 from &#8220;Trust&#8221; to &#8220;Untrust&#8221;\u00a0 &#8220;Any&#8221; &#8220;Any&#8221; &#8220;ANY&#8221; permit<\/p>\n<p>set policy id 1<\/p>\n<p>exit<\/p>\n<p>set nsmgmt bulkcli reboot-timeout 60<\/p>\n<p>set ssh version v2<\/p>\n<p>set ssh enable<\/p>\n<p>set config lock timeout 5<\/p>\n<p>unset license-key auto-update<\/p>\n<p>set telnet client enable<\/p>\n<p>set wlan country-code AT<\/p>\n<p>set wlan 0 channel auto<\/p>\n<p>set wlan 1 channel auto<\/p>\n<p>set wlan change-channel-timer 0<\/p>\n<p>set snmp port listen 161<\/p>\n<p>set snmp port trap 162<\/p>\n<p>set snmpv3 local-engine id &#8220;0164092008000839&#8221;<\/p>\n<p>set vrouter &#8220;untrust-vr&#8221;<\/p>\n<p>exit<\/p>\n<p>set vrouter &#8220;trust-vr&#8221;<\/p>\n<p>unset add-default-route<\/p>\n<p>exit<\/p>\n<p>set vrouter &#8220;untrust-vr&#8221;<\/p>\n<p>exit<\/p>\n<p>set vrouter &#8220;trust-vr&#8221;<\/p>\n<p>exit<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Servis Sa\u011flay\u0131c\u0131 Lisans\u0131 almak isteyen bir\u00e7ok firma ve arkada\u015f\u0131n en<\/p>\n","protected":false},"author":1,"featured_media":47,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[23,64,65],"class_list":["post-58","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-paylasim","tag-btk","tag-juniper","tag-junos"],"featured_image_urls":{"full":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1.jpg",545,533,false],"thumbnail":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1-150x150.jpg",150,150,true],"medium":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1-300x293.jpg",300,293,true],"medium_large":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1.jpg",545,533,false],"large":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1.jpg",545,533,false],"1536x1536":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1.jpg",545,533,false],"2048x2048":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1.jpg",545,533,false],"chromenews-featured":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1.jpg",545,533,false],"chromenews-large":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1.jpg",545,533,false],"chromenews-medium":["https:\/\/onurunlu.com.tr\/wp-content\/uploads\/2023\/04\/onur-sign-big-1-545x410.jpg",545,410,true]},"author_info":{"info":["admin"]},"category_info":"<a href=\"https:\/\/onurunlu.com.tr\/?cat=1\" rel=\"category\">Payla\u015f\u0131m<\/a>","tag_info":"Payla\u015f\u0131m","comment_count":"0","_links":{"self":[{"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=\/wp\/v2\/posts\/58","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=58"}],"version-history":[{"count":1,"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=\/wp\/v2\/posts\/58\/revisions"}],"predecessor-version":[{"id":59,"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=\/wp\/v2\/posts\/58\/revisions\/59"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=\/wp\/v2\/media\/47"}],"wp:attachment":[{"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=58"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=58"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/onurunlu.com.tr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=58"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}