Showing posts with label Juniper. Show all posts
Showing posts with label Juniper. Show all posts

Wednesday, September 28, 2016

Setting up Windows Server 2008 R2 RADIUS authentication with Juniper SRX

Under Windows Network Policy Server (NPS)

Create a shared secret template, name it SRXpassword or something and make a password.

Create a new network policy and name it, leave the network access server unspecified

 

Click next and select the Windows Group and select the group(s) you want to access the device.

Click next and select access granted

For the type of encryption, click add, select MS-CHAPv2

Do not change anything under the constraint page and click next.

Remove everything from the Standard RADIUS attributes and select the vendor specific type. Click add and select vendor specific

Enter the Juniper vendor code 2636 and click yes it conforms

Put in the vendor-assigned attribute number 1 and select string as the attribute format and type in su

 

Click OK to close it and back to the menu select the encryption type. Uncheck everything except strongest encryption and click next and finished.

 

Create the new RADIUS client and populate the information of your firewall. Select the share secret template you create earlier.

 

On the Juniper SRX Firewall

 

Type in the following and fill in your server IP and password.

set system authentication-order [ password radius ]

set system radius-server 192.168.1.2 secret WhatEverPasswordYouMade

set system radius-options password-protocol mschap-v2

set system login user su class super-user

commit

 

Thursday, August 18, 2016

Setup DHCP client for SRX interface and port forwarding

Almost 3 years since I posted anything. Decided to make a quick post today since my firewall died and I replaced it with a Juniper SRX 210. For home use, this firewall kind of sucks. DHCP client on the WAN (untrusted) connection does not work out of the box, I had to do a little tweaking to get it running. In addition to that, the remote access VPN is clunky and I was unable to get it running using 3rd party client software. There is no UPnP of course, which is expected from this type of firewall. But like I said, I am using this as a temporary replacement cause my home firewall died so I had to manually open all my port which was kind of a pain.

 

First of all, to get my DHCP working so the ONT can assign my firewall an IP I had to do a couple of things. The first was enable the interface for DHCP client, that was easily done from the GUI with a check box. Next I execute the following from the shell

 

vi /etc/rc.custom

·         save this file

·         execute the following

sysctl -w net.inet.ip.mcast_ttl=64

·         Modify the permission

chmod 777 /cf/etc/rc.custom

 

 

Then from the CLI we need to modify the security policy to accept DHCP for the interface that needs to obtain an IP address. In my case it was the ge-0/0/0.0

 

 

set security zones security-zone untrust interfaces ge-0/0/0.0 host-inbound-traffic system-services dhcp

 

 

·         Then execute the following command

request system services dhcp renew ge-0/0/0.0

 

My firewall did not receive and IP address till I power cycled the ONT.

 

Enabling each port through the firewall was a serious beating. When using multiple ports to forward to the same server. You will need to make a new address entry for that same IP for each new rule. You can use and modify the following to make it a quick copy and paste

 

·         define your addresses

set security zones security-zone trust address-book address sodapc 192.168.150.99/32

·         define your applications

set applications application qbtor protocol tcp

set applications application qbtor destination-port 9497

·         define your nat rules

set security nat destination pool dnat-192_168_150_99m32 address 192.168.150.99/32

set security nat destination pool dnat-192_168_150_99m32 address port 9497

·         adjust the nat rule for your public IP

set security nat destination rule-set dst-nat rule rule3 match destination-address 0.0.0.0/0

set security nat destination rule-set dst-nat rule rule3 match destination-port 9497

set security nat destination rule-set dst-nat rule rule3 then destination-nat pool dnat-192_168_150_99m32

·         create the policies to permit the traffic

set security policies from-zone untrust to-zone trust policy untrust-to-trust3 match source-address any

set security policies from-zone untrust to-zone trust policy untrust-to-trust3 match destination-address sodapc

set security policies from-zone untrust to-zone trust policy untrust-to-trust3 match application qbtor

set security policies from-zone untrust to-zone trust policy untrust-to-trust3 then permit

 

I have a ton of service at home so I went on with this for quite a while. UPnP would have saved a lot of time.