Related
Documentation
Understanding Device Configurations Running ScreenOS 5.4 FIPS and Later Overview
About Configuring Devices Running Future Releases of ScreenOS
Copyright © 2010, Juniper Networks, Inc.
Table 12: ALGs Default Status
ALGs
H.323, SIP, MGCP, SCCP, MSRPC, SunRPC,
SQL, PPTP, and DNS Inhibit AAAA(IPv6).
FTP, DNS, Real, Rlogin, RSH, TALK, TFTP,
XING, and SCTP
Configuring Advanced Properties for ScreenOS Device Details on page 26
Configuring a Blacklisted Entry (NSM Procedure) on page 27
Device Configuration Settings Overview on page 25
The following features are disabled on security devices running the Federal Information
Processing Standards (FIPS) certified release of ScreenOS (ScreenOS 5.4 FIPS):
SNMP management
MD5 algorithm
Group 5 Phase 2 IKE proposals
For more information about FIPS-enabled security devices, refer to the ScreenOS 5.0
FIPS Reference Note.
NOTE: To configure and manage security devices running ScreenOS 5.0 FIPS
using NSM, you must first configure a VPN tunnel between the device and
the NSM GUI server. After establishing this tunnel, you cannot reconfigure
tunnel parameters in NSM.
You can use NSM to configure security devices running future releases of ScreenOS in
one of three levels of support:
Forward Support (Basic)—When a new version of ScreenOS is available, you can
download a schema patch that includes changes to the DCF and schema files, as well
as the firmware tables, enabling you to manage devices using a previously known
version of ScreenOS.
Forward Support (Blended)—When a new version of ScreenOS is available, you can
download a schema patch, enabling you to manage devices using the new ScreenOS
version. You cannot, however, manage the new features in ScreenOS with this level
of support.
Chapter 2: Device Configuration
Status
Disabled by default on ISG1000, ISG2000,
NetScreen–2000 line, and NetScreen–5000
line running ScreenOS 6.0 or later.
Enabled by default on a device running ScreenOS
6.0 or later.
29
Need help?
Do you have a question about the NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01 and is the answer not in the manual?