Interface Configurations For Root And Vsys Overview - Juniper NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01 Manual

Configuring screenos devices guide
Hide thumbs Also See for NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01:
Table of Contents

Advertisement

Configuring ScreenOS Devices Guide
Table 62: Zone Configuration for Root and Vsys (continued)
Zones
Global-vsys_name zone
Related
Documentation

Interface Configurations for Root and Vsys Overview

Table 63: Interface Configuration for Root and Vsys
Interface Configuration
Shared Interface
252
Description
This zone is created by default when you create the vsys.
Each vsys also supports user-defined security zones; you can bind these zones to any
shared virtual routers defined at the root level or to the virtual router dedicated to that
vsys.
NOTE: In ScreenOS 6.2, a new shared zone called shared-DMZ allows
inter-vsys communications. NAT is also available for traffic from vsys-to-vsys
based on the shared-DMZ zone to solve overlapping address issues. For
details on configuring the shared DMZ zone, see the "Managing Inter-Vsys
Traffic with Shared DMZ Zones" on page 253.
Interface Configurations for Root and Vsys Overview on page 252
Virtual Router Configurations for Root and Vsys Overview on page 251
Viewing Root and Vsys Configurations on page 253
Interfaces can be dedicated, shared, imported, and exported between root and vsys.
NOTE: When the root system is in L2V, you cannot import or export interfaces.
For more information, see "Layer 2 Vsys Configuration Overview" on page 258.
At the root level, shared interfaces that are bound to a shared zone. However, any physical,
subinterface, redundant interface, or aggregate interface in the root system that is bound
to a nonsharable zone is dedicated to the root system, and cannot be shared. To import
an interface to a vsys, the interface must be in the null zone at the root level; to export
an interface from a vsys, the interface must be in the null zone at the vsys level.
At the vsys level, you can configure interfaces as described in Table 63 on page 252.
Description
A shared interface is an interface that can be shared with the root system. To share a root
interface, the interface must be shared at the root level and bound to a shared zone in a shared
virtual router. By default, the untrust-vr and untrust zone are shared, enabling you to configure
a vsys to share any root-level physical interface, subinterface, redundant interface, or aggregate
interface that is bound to the untrust zone.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

Table of Contents