Educause Security Discussion mailing list archives

Re: Juniper Firewalls


From: "Marsh, Todd" <tmarsh () BENTLEY EDU>
Date: Thu, 6 Dec 2007 16:28:02 -0500

We migrated from cisco pix's to isg1000's over the summer.  We have 2 in an active-active HA config.  A little bit of a 
learning curve with that but they've been rock solid.  The big thing that bit me was that they implicitly deny all 
traffic from the trust zone to the untrust zone, so all those applications that have magically just worked over the 
years (and IT was not aware of) stopped.  I guess on the upside it allowed us to really get a handle on all the 
special/unsupported apps the faculty really use.  
 
Feel free to contact me directly if you have any specific questions.
 
Todd Marsh
Bentley College
tmarsh () bentley edu
781-891-2543

________________________________

From: Clark, Joseph K [mailto:ClarkJK () COFC EDU]
Sent: Thu 12/6/2007 3:09 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Juniper Firewalls



Good Afternoon,

 

We are in the process of migrating to a pair of Juniper firewalls.

Does anyone have any words of wisdom or experiences that would help us during the transition?

 

Thanks,

Joseph Clark

Current thread: