<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for I-BLOG</title>
	<atom:link href="http://www.rsivanandan.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rsivanandan.com</link>
	<description>Never go to bed mad. Stay up and fight!</description>
	<lastBuildDate>Fri, 16 Jul 2010 05:28:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>Comment on About by Faizan</title>
		<link>http://www.rsivanandan.com/about/comment-page-1/#comment-1832</link>
		<dc:creator>Faizan</dc:creator>
		<pubDate>Fri, 16 Jul 2010 05:28:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/?page_id=9#comment-1832</guid>
		<description>Dear Rajesh,

I am still unable to do this... can you please help me... do you have any number so i can call you?...

Regards,
Faizan</description>
		<content:encoded><![CDATA[<p>Dear Rajesh,</p>
<p>I am still unable to do this&#8230; can you please help me&#8230; do you have any number so i can call you?&#8230;</p>
<p>Regards,<br />
Faizan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Block Facebook using Juniper SRX by rsivanandan</title>
		<link>http://www.rsivanandan.com/2010/07/13/block-facebook-using-juniper-srx/comment-page-1/#comment-1831</link>
		<dc:creator>rsivanandan</dc:creator>
		<pubDate>Thu, 15 Jul 2010 15:44:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/2010/07/13/block-facebook-using-juniper-srx/#comment-1831</guid>
		<description>Of course you should be able to do that as well!</description>
		<content:encoded><![CDATA[<p>Of course you should be able to do that as well!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Block Facebook using Juniper SRX by michael</title>
		<link>http://www.rsivanandan.com/2010/07/13/block-facebook-using-juniper-srx/comment-page-1/#comment-1829</link>
		<dc:creator>michael</dc:creator>
		<pubDate>Thu, 15 Jul 2010 15:31:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/2010/07/13/block-facebook-using-juniper-srx/#comment-1829</guid>
		<description>you could just as easily not block this and just log this traffic for statistical purposes correct?</description>
		<content:encoded><![CDATA[<p>you could just as easily not block this and just log this traffic for statistical purposes correct?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by Faizan</title>
		<link>http://www.rsivanandan.com/about/comment-page-1/#comment-1825</link>
		<dc:creator>Faizan</dc:creator>
		<pubDate>Mon, 05 Jul 2010 09:09:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/?page_id=9#comment-1825</guid>
		<description>Many thanks... sorry for late replying.. I have not checked it yet.. I will definitely try &amp; then let you know...

Thank you so much for you kind co-operation.

Regards,
Faizan</description>
		<content:encoded><![CDATA[<p>Many thanks&#8230; sorry for late replying.. I have not checked it yet.. I will definitely try &amp; then let you know&#8230;</p>
<p>Thank you so much for you kind co-operation.</p>
<p>Regards,<br />
Faizan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Photography &#8211; Gears by rsivanandan</title>
		<link>http://www.rsivanandan.com/2010/06/18/photography-gears/comment-page-1/#comment-1818</link>
		<dc:creator>rsivanandan</dc:creator>
		<pubDate>Fri, 18 Jun 2010 06:33:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/2010/06/18/photography-gears/#comment-1818</guid>
		<description>Dude, the camera is awesome man :-) A perfect gear to relax and forget about agile;

Cheers,
rsivanandan</description>
		<content:encoded><![CDATA[<p>Dude, the camera is awesome man <img src='http://www.rsivanandan.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  A perfect gear to relax and forget about agile;</p>
<p>Cheers,<br />
rsivanandan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Photography &#8211; Gears by Gopal</title>
		<link>http://www.rsivanandan.com/2010/06/18/photography-gears/comment-page-1/#comment-1817</link>
		<dc:creator>Gopal</dc:creator>
		<pubDate>Fri, 18 Jun 2010 06:13:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/2010/06/18/photography-gears/#comment-1817</guid>
		<description>I am yet to lay my hands on DSLR. Honestly an excellent choice. However on the photos I guess its the camera doing the trick not the camera-man....:-)

Nice Pics!!!</description>
		<content:encoded><![CDATA[<p>I am yet to lay my hands on DSLR. Honestly an excellent choice. However on the photos I guess its the camera doing the trick not the camera-man&#8230;.:-)</p>
<p>Nice Pics!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on My Phones. by rsivanandan</title>
		<link>http://www.rsivanandan.com/2010/06/16/phones-i-own/comment-page-1/#comment-1816</link>
		<dc:creator>rsivanandan</dc:creator>
		<pubDate>Thu, 17 Jun 2010 06:49:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/2010/06/16/phones-i-own/#comment-1816</guid>
		<description>:-) I&#039;m obliged dude...

Cheers,
rsivanandan</description>
		<content:encoded><![CDATA[<p> <img src='http://www.rsivanandan.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  I&#8217;m obliged dude&#8230;</p>
<p>Cheers,<br />
rsivanandan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on My Phones. by Gopal</title>
		<link>http://www.rsivanandan.com/2010/06/16/phones-i-own/comment-page-1/#comment-1815</link>
		<dc:creator>Gopal</dc:creator>
		<pubDate>Thu, 17 Jun 2010 05:46:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/2010/06/16/phones-i-own/#comment-1815</guid>
		<description>There is a saying in Tamil &quot;Donkey...Camphor etc etc.....&quot; probably you will figure it out.</description>
		<content:encoded><![CDATA[<p>There is a saying in Tamil &#8220;Donkey&#8230;Camphor etc etc&#8230;..&#8221; probably you will figure it out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by rsivanandan</title>
		<link>http://www.rsivanandan.com/about/comment-page-1/#comment-1813</link>
		<dc:creator>rsivanandan</dc:creator>
		<pubDate>Wed, 16 Jun 2010 15:18:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/?page_id=9#comment-1813</guid>
		<description>That would do, so what is the external public ip that you want to use? Or do you want to use the outside interface ip itself?

If yes, then look at the port forward tranlsation example I have in the document.

If you have a public ip, the look at the 1-1 translation in the document.

I have the policies as well in the same section. All you need to do is setup using that.

Cheers,
rsivanandan</description>
		<content:encoded><![CDATA[<p>That would do, so what is the external public ip that you want to use? Or do you want to use the outside interface ip itself?</p>
<p>If yes, then look at the port forward tranlsation example I have in the document.</p>
<p>If you have a public ip, the look at the 1-1 translation in the document.</p>
<p>I have the policies as well in the same section. All you need to do is setup using that.</p>
<p>Cheers,<br />
rsivanandan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by Faizan</title>
		<link>http://www.rsivanandan.com/about/comment-page-1/#comment-1812</link>
		<dc:creator>Faizan</dc:creator>
		<pubDate>Wed, 16 Jun 2010 10:59:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/?page_id=9#comment-1812</guid>
		<description>internal IP address of ISA server is 192.168.100.5

i have prepared one &#039;VPN&#039; rule for 3389... is that rule ok??

Regards,
Faizan</description>
		<content:encoded><![CDATA[<p>internal IP address of ISA server is 192.168.100.5</p>
<p>i have prepared one &#8216;VPN&#8217; rule for 3389&#8230; is that rule ok??</p>
<p>Regards,<br />
Faizan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by rsivanandan</title>
		<link>http://www.rsivanandan.com/about/comment-page-1/#comment-1810</link>
		<dc:creator>rsivanandan</dc:creator>
		<pubDate>Tue, 15 Jun 2010 15:55:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/?page_id=9#comment-1810</guid>
		<description>Do you have a free public IP that you can use?

What is the internal IP address of the ISA server?

Cheers,
rsivanandan</description>
		<content:encoded><![CDATA[<p>Do you have a free public IP that you can use?</p>
<p>What is the internal IP address of the ISA server?</p>
<p>Cheers,<br />
rsivanandan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by Faizan</title>
		<link>http://www.rsivanandan.com/about/comment-page-1/#comment-1809</link>
		<dc:creator>Faizan</dc:creator>
		<pubDate>Tue, 15 Jun 2010 15:09:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/?page_id=9#comment-1809</guid>
		<description>Thanks... but can you please guide me also... how can i do that.. i m not that much familiar with Juniper Firewall

thanking you in advance... 

Regards,
Faizan</description>
		<content:encoded><![CDATA[<p>Thanks&#8230; but can you please guide me also&#8230; how can i do that.. i m not that much familiar with Juniper Firewall</p>
<p>thanking you in advance&#8230; </p>
<p>Regards,<br />
Faizan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by rsivanandan</title>
		<link>http://www.rsivanandan.com/about/comment-page-1/#comment-1808</link>
		<dc:creator>rsivanandan</dc:creator>
		<pubDate>Tue, 15 Jun 2010 14:57:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/?page_id=9#comment-1808</guid>
		<description>See, you need to first have a NAT in place (MIP/VIP) so that you can access your machine from outside world (internet). 

Steps are:- as I have mentioned in the pdf file.

1. First create a MIP with a public ip and map it to your ISA&#039;s internal ip address.
2. Then create a policy to allow traffic for the service VPN onto that address.

that&#039;s it. done.

Cheers,
rsivanandan</description>
		<content:encoded><![CDATA[<p>See, you need to first have a NAT in place (MIP/VIP) so that you can access your machine from outside world (internet). </p>
<p>Steps are:- as I have mentioned in the pdf file.</p>
<p>1. First create a MIP with a public ip and map it to your ISA&#8217;s internal ip address.<br />
2. Then create a policy to allow traffic for the service VPN onto that address.</p>
<p>that&#8217;s it. done.</p>
<p>Cheers,<br />
rsivanandan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by Faizan</title>
		<link>http://www.rsivanandan.com/about/comment-page-1/#comment-1807</link>
		<dc:creator>Faizan</dc:creator>
		<pubDate>Tue, 15 Jun 2010 12:22:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/?page_id=9#comment-1807</guid>
		<description>dear,

I&#039;ve prepared one service named &#039;VPN&#039; for remote access to our network by opening 3389 port. kindly check &amp; update me accordingly.


set clock dst-off
set clock timezone 5
set vrouter trust-vr sharable
set vrouter &quot;untrust-vr&quot;
exit
set vrouter &quot;trust-vr&quot;
unset auto-route-export
exit
set service &quot;YahooCAM&quot; protocol tcp src-port 0-65535 dst-port 5100-5100 
set service &quot;EZ1&quot; protocol tcp src-port 0-65535 dst-port 5001-5003 
set service &quot;EZ1&quot; + tcp src-port 0-65535 dst-port 5050-5050 
set service &quot;KASB1&quot; protocol tcp src-port 0-65535 dst-port 6789-6800 
set service &quot;KASB1&quot; + tcp src-port 0-65535 dst-port 8998-8998 
set service &quot;ONSPEED&quot; protocol tcp src-port 0-65535 dst-port 7000-7000 
set service &quot;ONSPEED&quot; + tcp src-port 0-65535 dst-port 5404-5405 
set service &quot;SATURN&quot; protocol tcp src-port 0-65535 dst-port 8000-8000 
set service &quot;SATURN&quot; + tcp src-port 0-65535 dst-port 8001-8001 
set service &quot;SATURN&quot; + tcp src-port 0-65535 dst-port 8002-8002 
set service &quot;SATURN&quot; + tcp src-port 0-65535 dst-port 8003-8003 
set service &quot;SATURN&quot; + tcp src-port 0-65535 dst-port 8004-8004 
set service &quot;BloomBerg&quot; protocol tcp src-port 0-65535 dst-port 5001-5003 
set service &quot;BloomBerg&quot; + tcp src-port 0-65535 dst-port 5050-5050 
set service &quot;BloomBerg&quot; + tcp src-port 0-65535 dst-port 6666-6666 
set service &quot;BloomBerg&quot; + tcp src-port 0-65535 dst-port 8194-8294 
set service &quot;BloomBerg&quot; + udp src-port 0-65535 dst-port 48129-48137 
set service &quot;PTA&quot; protocol tcp src-port 0-65535 dst-port 8080-8080 
set service &quot;SC&quot; protocol tcp src-port 0-65535 dst-port 1521-1521 
set service &quot;SC&quot; + tcp src-port 0-65535 dst-port 8090-8093 
set service &quot;SC&quot; + tcp src-port 0-65535 dst-port 3055-3055 
set service &quot;IMS&quot; protocol tcp src-port 0-65535 dst-port 5000-5005 
set service &quot;IMS&quot; + tcp src-port 0-65535 dst-port 5050-5050 
set service &quot;VPN&quot; protocol tcp src-port 1-65535 dst-port 3389-3389 
set service &quot;PCM&quot; protocol tcp src-port 7070-7074 dst-port 7070-7074 
set auth-server &quot;Local&quot; id 0
set auth-server &quot;Local&quot; server-name &quot;Local&quot;
set auth default auth server &quot;Local&quot;
set auth radius accounting port 1646
set admin name &quot;*****&quot;
set admin password &quot;nOGJJIrYMaMIc65KTsKOmzGtUDNzOn&quot;
set admin http redirect
set admin auth timeout 0
set admin auth server &quot;Local&quot;
set admin format dos
set zone &quot;Trust&quot; vrouter &quot;trust-vr&quot;
set zone &quot;Untrust&quot; vrouter &quot;trust-vr&quot;
set zone &quot;VLAN&quot; vrouter &quot;trust-vr&quot;
set zone &quot;Untrust-Tun&quot; vrouter &quot;trust-vr&quot;
set zone &quot;Trust&quot; tcp-rst 
set zone &quot;Untrust&quot; block 
unset zone &quot;Untrust&quot; tcp-rst 
set zone &quot;MGT&quot; block 
set zone &quot;VLAN&quot; block 
unset zone &quot;VLAN&quot; tcp-rst 
set zone &quot;Untrust&quot; screen tear-drop
set zone &quot;Untrust&quot; screen syn-flood
set zone &quot;Untrust&quot; screen ping-death
set zone &quot;Untrust&quot; screen ip-filter-src
set zone &quot;Untrust&quot; screen land
set zone &quot;V1-Untrust&quot; screen tear-drop
set zone &quot;V1-Untrust&quot; screen syn-flood
set zone &quot;V1-Untrust&quot; screen ping-death
set zone &quot;V1-Untrust&quot; screen ip-filter-src
set zone &quot;V1-Untrust&quot; screen land
set interface &quot;trust&quot; zone &quot;Trust&quot;
set interface &quot;untrust&quot; zone &quot;Untrust&quot;
set interface &quot;adsl1&quot; pvc 8 35 mux llc protocol bridged zone &quot;Null&quot;
unset interface vlan1 ip
set interface trust ip ******/29
set interface trust route
set interface untrust ip ******/32
set interface untrust route
unset interface vlan1 bypass-others-ipsec
unset interface vlan1 bypass-non-ip
set interface trust ip manageable
set interface untrust ip manageable
set interface trust dhcp server service
set interface trust dhcp server auto
set interface trust dhcp server option gateway ****** 
set interface trust dhcp server option netmask 255.255.255.0 
set interface &quot;trust&quot; webauth ssl-only
set interface &quot;trust&quot; webauth-ip ******
set flow tcp-mss
set flow all-tcp-mss 1304
unset flow no-tcp-seq-check
set flow tcp-syn-check
set hostname ns5gt-adsl

set pki authority default scep mode &quot;auto&quot;
set pki x509 default cert-path partial
set ike respond-bad-spi 1
unset ike ikeid-enumeration
unset ipsec access-session enable
set ipsec access-session maximum 5000
set ipsec access-session upper-threshold 0
set ipsec access-session lower-threshold 0
set ipsec access-session dead-p2-sa-timeout 0
unset ipsec access-session log-error
unset ipsec access-session info-exch-connected
unset ipsec access-session use-error-log
set attack db mode Update
set attack db schedule daily 00:00
set av all fail-mode traffic permit
set av http keep-alive
set av http trickling default
unset av http webmail enable
set av profile &quot;scan-mgr&quot;
unset ftp enable    
set ftp scan-mode  scan-all  
set ftp decompress-layer  2  
unset http enable    
set http scan-mode  scan-all  
unset imap enable    
set imap scan-mode  scan-all  
set imap decompress-layer  2  
set pop3 scan-mode  scan-all  
set pop3 decompress-layer  2  
unset smtp enable    
set smtp scan-mode  scan-all  
set smtp decompress-layer  2  
exit
unset av scan-mgr max-content-size drop
unset av scan-mgr max-msgs drop
set url protocol sc-cpa
exit
set anti-spam profile ns-profile
 set whitelist 202.101.171.50;
 set blacklist @cdwdrives.com;@dbaza.com;@etiquettes-martin.com;@euregio.net;@evesham.com;@executiveauto.com;@invitel.hu;@jeol.de;@marcusevanskl.com;@my-desk.com;@net.br;@regula.by;@rima-tde.net;@rr.com;@stingrayinternet.com;@verizon.net;
 set sbl default-server enable
 set default action tag subject &quot;***SPAM***     &quot;
exit
set policy id 1 name &quot;inbound&quot; from &quot;Trust&quot; to &quot;Untrust&quot;  &quot;Any&quot; &quot;Any&quot; &quot;ANY&quot; permit log 
set policy id 1 disable
set policy id 1 av &quot;scan-mgr&quot;
set policy id 1 anti-spam ns-profile
set policy id 1
set log session-init
exit
set policy id 2 name &quot;mail&quot; from &quot;Untrust&quot; to &quot;Trust&quot;  &quot;Any&quot; &quot;Any&quot; &quot;HTTP&quot; permit log 
set policy id 2
set service &quot;IMAP&quot;
set service &quot;MAIL&quot;
set service &quot;ONSPEED&quot;
set service &quot;PCM&quot;
set service &quot;POP3&quot;
set service &quot;SATURN&quot;
set service &quot;SMTP&quot;
set service &quot;VPN&quot;
set service &quot;MS-EXCHANGE&quot;
set log session-init
exit
set policy id 3 name &quot;AllAccess&quot; from &quot;Trust&quot; to &quot;Untrust&quot;  &quot;Any&quot; &quot;Any&quot; &quot;BloomBerg&quot; permit log 
set policy id 3 anti-spam ns-profile
set policy id 3
set service &quot;DNS&quot;
set service &quot;EZ1&quot;
set service &quot;FTP&quot;
set service &quot;HTTP&quot;
set service &quot;HTTPS&quot;
set service &quot;ICMP-ANY&quot;
set service &quot;IMAP&quot;
set service &quot;IMS&quot;
set service &quot;KASB1&quot;
set service &quot;MAIL&quot;
set service &quot;MS-SQL&quot;
set service &quot;MSN&quot;
set service &quot;ONSPEED&quot;
set service &quot;PCM&quot;
set service &quot;POP3&quot;
set service &quot;PTA&quot;
set service &quot;SATURN&quot;
set service &quot;SC&quot;
set service &quot;SMTP&quot;
set service &quot;TELNET&quot;
set service &quot;VNC&quot;
set service &quot;VPN&quot;
set service &quot;YMSG&quot;
set service &quot;MS-EXCHANGE&quot;
set log session-init
exit
set policy id 4 from &quot;Untrust&quot; to &quot;Trust&quot;  &quot;Any&quot; &quot;Any&quot; &quot;ANY&quot; permit 
set policy id 4 disable
set policy id 4
exit
set pppoe name &quot;*****&quot;
unset pppoe name &quot;*****&quot; auth CHAP
set pppoe name &quot;*****&quot; username &quot;picicasset1&quot; password &quot;bafVX9e9NUNzeysy4UCgBH5uADnJaY6ATQ==&quot;
set pppoe name &quot;*****&quot; interface untrust
unset pppoe name &quot;******&quot; update-dhcpserver
set syslog config &quot;******&quot;
set syslog config &quot;******&quot; facilities local0 local0
set syslog config &quot;*******&quot; log traffic
set syslog src-interface trust
set syslog enable
unset log module system level debugging destination syslog
set global-pro policy-manager primary outgoing-interface untrust
set global-pro policy-manager secondary outgoing-interface untrust
set nsmgmt bulkcli reboot-timeout 60
set ssh version v2
set config lock timeout 5
set ntp server &quot;0.0.0.0&quot;
set ntp server backup1 &quot;0.0.0.0&quot;
set ntp server backup2 &quot;0.0.0.0&quot;
set modem speed 115200
set modem retry 3
set modem interval 10
set modem idle-time 10
set snmp community &quot;private1&quot; Read-Write Trap-on  traffic version v1
set snmp host &quot;private1&quot; ****** 255.255.255.255 src-interface trust trap v1
set snmp location &quot;KHI&quot;
set snmp contact &quot;****&quot;
set snmp name &quot;*****&quot;
set snmp port listen 161
set snmp port trap 162
set vrouter &quot;untrust-vr&quot;
exit
set vrouter &quot;trust-vr&quot;
unset add-default-route
exit
set vrouter &quot;untrust-vr&quot;
exit
set vrouter &quot;trust-vr&quot;
exit


regards,
Faizan</description>
		<content:encoded><![CDATA[<p>dear,</p>
<p>I&#8217;ve prepared one service named &#8216;VPN&#8217; for remote access to our network by opening 3389 port. kindly check &amp; update me accordingly.</p>
<p>set clock dst-off<br />
set clock timezone 5<br />
set vrouter trust-vr sharable<br />
set vrouter &#8220;untrust-vr&#8221;<br />
exit<br />
set vrouter &#8220;trust-vr&#8221;<br />
unset auto-route-export<br />
exit<br />
set service &#8220;YahooCAM&#8221; protocol tcp src-port 0-65535 dst-port 5100-5100<br />
set service &#8220;EZ1&#8243; protocol tcp src-port 0-65535 dst-port 5001-5003<br />
set service &#8220;EZ1&#8243; + tcp src-port 0-65535 dst-port 5050-5050<br />
set service &#8220;KASB1&#8243; protocol tcp src-port 0-65535 dst-port 6789-6800<br />
set service &#8220;KASB1&#8243; + tcp src-port 0-65535 dst-port 8998-8998<br />
set service &#8220;ONSPEED&#8221; protocol tcp src-port 0-65535 dst-port 7000-7000<br />
set service &#8220;ONSPEED&#8221; + tcp src-port 0-65535 dst-port 5404-5405<br />
set service &#8220;SATURN&#8221; protocol tcp src-port 0-65535 dst-port 8000-8000<br />
set service &#8220;SATURN&#8221; + tcp src-port 0-65535 dst-port 8001-8001<br />
set service &#8220;SATURN&#8221; + tcp src-port 0-65535 dst-port 8002-8002<br />
set service &#8220;SATURN&#8221; + tcp src-port 0-65535 dst-port 8003-8003<br />
set service &#8220;SATURN&#8221; + tcp src-port 0-65535 dst-port 8004-8004<br />
set service &#8220;BloomBerg&#8221; protocol tcp src-port 0-65535 dst-port 5001-5003<br />
set service &#8220;BloomBerg&#8221; + tcp src-port 0-65535 dst-port 5050-5050<br />
set service &#8220;BloomBerg&#8221; + tcp src-port 0-65535 dst-port 6666-6666<br />
set service &#8220;BloomBerg&#8221; + tcp src-port 0-65535 dst-port 8194-8294<br />
set service &#8220;BloomBerg&#8221; + udp src-port 0-65535 dst-port 48129-48137<br />
set service &#8220;PTA&#8221; protocol tcp src-port 0-65535 dst-port 8080-8080<br />
set service &#8220;SC&#8221; protocol tcp src-port 0-65535 dst-port 1521-1521<br />
set service &#8220;SC&#8221; + tcp src-port 0-65535 dst-port 8090-8093<br />
set service &#8220;SC&#8221; + tcp src-port 0-65535 dst-port 3055-3055<br />
set service &#8220;IMS&#8221; protocol tcp src-port 0-65535 dst-port 5000-5005<br />
set service &#8220;IMS&#8221; + tcp src-port 0-65535 dst-port 5050-5050<br />
set service &#8220;VPN&#8221; protocol tcp src-port 1-65535 dst-port 3389-3389<br />
set service &#8220;PCM&#8221; protocol tcp src-port 7070-7074 dst-port 7070-7074<br />
set auth-server &#8220;Local&#8221; id 0<br />
set auth-server &#8220;Local&#8221; server-name &#8220;Local&#8221;<br />
set auth default auth server &#8220;Local&#8221;<br />
set auth radius accounting port 1646<br />
set admin name &#8220;*****&#8221;<br />
set admin password &#8220;nOGJJIrYMaMIc65KTsKOmzGtUDNzOn&#8221;<br />
set admin http redirect<br />
set admin auth timeout 0<br />
set admin auth server &#8220;Local&#8221;<br />
set admin format dos<br />
set zone &#8220;Trust&#8221; vrouter &#8220;trust-vr&#8221;<br />
set zone &#8220;Untrust&#8221; vrouter &#8220;trust-vr&#8221;<br />
set zone &#8220;VLAN&#8221; vrouter &#8220;trust-vr&#8221;<br />
set zone &#8220;Untrust-Tun&#8221; vrouter &#8220;trust-vr&#8221;<br />
set zone &#8220;Trust&#8221; tcp-rst<br />
set zone &#8220;Untrust&#8221; block<br />
unset zone &#8220;Untrust&#8221; tcp-rst<br />
set zone &#8220;MGT&#8221; block<br />
set zone &#8220;VLAN&#8221; block<br />
unset zone &#8220;VLAN&#8221; tcp-rst<br />
set zone &#8220;Untrust&#8221; screen tear-drop<br />
set zone &#8220;Untrust&#8221; screen syn-flood<br />
set zone &#8220;Untrust&#8221; screen ping-death<br />
set zone &#8220;Untrust&#8221; screen ip-filter-src<br />
set zone &#8220;Untrust&#8221; screen land<br />
set zone &#8220;V1-Untrust&#8221; screen tear-drop<br />
set zone &#8220;V1-Untrust&#8221; screen syn-flood<br />
set zone &#8220;V1-Untrust&#8221; screen ping-death<br />
set zone &#8220;V1-Untrust&#8221; screen ip-filter-src<br />
set zone &#8220;V1-Untrust&#8221; screen land<br />
set interface &#8220;trust&#8221; zone &#8220;Trust&#8221;<br />
set interface &#8220;untrust&#8221; zone &#8220;Untrust&#8221;<br />
set interface &#8220;adsl1&#8243; pvc 8 35 mux llc protocol bridged zone &#8220;Null&#8221;<br />
unset interface vlan1 ip<br />
set interface trust ip ******/29<br />
set interface trust route<br />
set interface untrust ip ******/32<br />
set interface untrust route<br />
unset interface vlan1 bypass-others-ipsec<br />
unset interface vlan1 bypass-non-ip<br />
set interface trust ip manageable<br />
set interface untrust ip manageable<br />
set interface trust dhcp server service<br />
set interface trust dhcp server auto<br />
set interface trust dhcp server option gateway ******<br />
set interface trust dhcp server option netmask 255.255.255.0<br />
set interface &#8220;trust&#8221; webauth ssl-only<br />
set interface &#8220;trust&#8221; webauth-ip ******<br />
set flow tcp-mss<br />
set flow all-tcp-mss 1304<br />
unset flow no-tcp-seq-check<br />
set flow tcp-syn-check<br />
set hostname ns5gt-adsl</p>
<p>set pki authority default scep mode &#8220;auto&#8221;<br />
set pki x509 default cert-path partial<br />
set ike respond-bad-spi 1<br />
unset ike ikeid-enumeration<br />
unset ipsec access-session enable<br />
set ipsec access-session maximum 5000<br />
set ipsec access-session upper-threshold 0<br />
set ipsec access-session lower-threshold 0<br />
set ipsec access-session dead-p2-sa-timeout 0<br />
unset ipsec access-session log-error<br />
unset ipsec access-session info-exch-connected<br />
unset ipsec access-session use-error-log<br />
set attack db mode Update<br />
set attack db schedule daily 00:00<br />
set av all fail-mode traffic permit<br />
set av http keep-alive<br />
set av http trickling default<br />
unset av http webmail enable<br />
set av profile &#8220;scan-mgr&#8221;<br />
unset ftp enable<br />
set ftp scan-mode  scan-all<br />
set ftp decompress-layer  2<br />
unset http enable<br />
set http scan-mode  scan-all<br />
unset imap enable<br />
set imap scan-mode  scan-all<br />
set imap decompress-layer  2<br />
set pop3 scan-mode  scan-all<br />
set pop3 decompress-layer  2<br />
unset smtp enable<br />
set smtp scan-mode  scan-all<br />
set smtp decompress-layer  2<br />
exit<br />
unset av scan-mgr max-content-size drop<br />
unset av scan-mgr max-msgs drop<br />
set url protocol sc-cpa<br />
exit<br />
set anti-spam profile ns-profile<br />
 set whitelist 202.101.171.50;<br />
 set blacklist @cdwdrives.com;@dbaza.com;@etiquettes-martin.com;@euregio.net;@evesham.com;@executiveauto.com;@invitel.hu;@jeol.de;@marcusevanskl.com;@my-desk.com;@net.br;@regula.by;@rima-tde.net;@rr.com;@stingrayinternet.com;@verizon.net;<br />
 set sbl default-server enable<br />
 set default action tag subject &#8220;***SPAM***     &#8221;<br />
exit<br />
set policy id 1 name &#8220;inbound&#8221; from &#8220;Trust&#8221; to &#8220;Untrust&#8221;  &#8220;Any&#8221; &#8220;Any&#8221; &#8220;ANY&#8221; permit log<br />
set policy id 1 disable<br />
set policy id 1 av &#8220;scan-mgr&#8221;<br />
set policy id 1 anti-spam ns-profile<br />
set policy id 1<br />
set log session-init<br />
exit<br />
set policy id 2 name &#8220;mail&#8221; from &#8220;Untrust&#8221; to &#8220;Trust&#8221;  &#8220;Any&#8221; &#8220;Any&#8221; &#8220;HTTP&#8221; permit log<br />
set policy id 2<br />
set service &#8220;IMAP&#8221;<br />
set service &#8220;MAIL&#8221;<br />
set service &#8220;ONSPEED&#8221;<br />
set service &#8220;PCM&#8221;<br />
set service &#8220;POP3&#8243;<br />
set service &#8220;SATURN&#8221;<br />
set service &#8220;SMTP&#8221;<br />
set service &#8220;VPN&#8221;<br />
set service &#8220;MS-EXCHANGE&#8221;<br />
set log session-init<br />
exit<br />
set policy id 3 name &#8220;AllAccess&#8221; from &#8220;Trust&#8221; to &#8220;Untrust&#8221;  &#8220;Any&#8221; &#8220;Any&#8221; &#8220;BloomBerg&#8221; permit log<br />
set policy id 3 anti-spam ns-profile<br />
set policy id 3<br />
set service &#8220;DNS&#8221;<br />
set service &#8220;EZ1&#8243;<br />
set service &#8220;FTP&#8221;<br />
set service &#8220;HTTP&#8221;<br />
set service &#8220;HTTPS&#8221;<br />
set service &#8220;ICMP-ANY&#8221;<br />
set service &#8220;IMAP&#8221;<br />
set service &#8220;IMS&#8221;<br />
set service &#8220;KASB1&#8243;<br />
set service &#8220;MAIL&#8221;<br />
set service &#8220;MS-SQL&#8221;<br />
set service &#8220;MSN&#8221;<br />
set service &#8220;ONSPEED&#8221;<br />
set service &#8220;PCM&#8221;<br />
set service &#8220;POP3&#8243;<br />
set service &#8220;PTA&#8221;<br />
set service &#8220;SATURN&#8221;<br />
set service &#8220;SC&#8221;<br />
set service &#8220;SMTP&#8221;<br />
set service &#8220;TELNET&#8221;<br />
set service &#8220;VNC&#8221;<br />
set service &#8220;VPN&#8221;<br />
set service &#8220;YMSG&#8221;<br />
set service &#8220;MS-EXCHANGE&#8221;<br />
set log session-init<br />
exit<br />
set policy id 4 from &#8220;Untrust&#8221; to &#8220;Trust&#8221;  &#8220;Any&#8221; &#8220;Any&#8221; &#8220;ANY&#8221; permit<br />
set policy id 4 disable<br />
set policy id 4<br />
exit<br />
set pppoe name &#8220;*****&#8221;<br />
unset pppoe name &#8220;*****&#8221; auth CHAP<br />
set pppoe name &#8220;*****&#8221; username &#8220;picicasset1&#8243; password &#8220;bafVX9e9NUNzeysy4UCgBH5uADnJaY6ATQ==&#8221;<br />
set pppoe name &#8220;*****&#8221; interface untrust<br />
unset pppoe name &#8220;******&#8221; update-dhcpserver<br />
set syslog config &#8220;******&#8221;<br />
set syslog config &#8220;******&#8221; facilities local0 local0<br />
set syslog config &#8220;*******&#8221; log traffic<br />
set syslog src-interface trust<br />
set syslog enable<br />
unset log module system level debugging destination syslog<br />
set global-pro policy-manager primary outgoing-interface untrust<br />
set global-pro policy-manager secondary outgoing-interface untrust<br />
set nsmgmt bulkcli reboot-timeout 60<br />
set ssh version v2<br />
set config lock timeout 5<br />
set ntp server &#8220;0.0.0.0&#8243;<br />
set ntp server backup1 &#8220;0.0.0.0&#8243;<br />
set ntp server backup2 &#8220;0.0.0.0&#8243;<br />
set modem speed 115200<br />
set modem retry 3<br />
set modem interval 10<br />
set modem idle-time 10<br />
set snmp community &#8220;private1&#8243; Read-Write Trap-on  traffic version v1<br />
set snmp host &#8220;private1&#8243; ****** 255.255.255.255 src-interface trust trap v1<br />
set snmp location &#8220;KHI&#8221;<br />
set snmp contact &#8220;****&#8221;<br />
set snmp name &#8220;*****&#8221;<br />
set snmp port listen 161<br />
set snmp port trap 162<br />
set vrouter &#8220;untrust-vr&#8221;<br />
exit<br />
set vrouter &#8220;trust-vr&#8221;<br />
unset add-default-route<br />
exit<br />
set vrouter &#8220;untrust-vr&#8221;<br />
exit<br />
set vrouter &#8220;trust-vr&#8221;<br />
exit</p>
<p>regards,<br />
Faizan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About by rsivanandan</title>
		<link>http://www.rsivanandan.com/about/comment-page-1/#comment-1806</link>
		<dc:creator>rsivanandan</dc:creator>
		<pubDate>Tue, 15 Jun 2010 09:35:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.rsivanandan.com/?page_id=9#comment-1806</guid>
		<description>&lt;a href=&quot;#comment-1805&quot; rel=&quot;nofollow&quot;&gt;@Faizan &lt;/a&gt; 
I&#039;d need to see the config.

Mention the IP of interest as well.

Cheers,
rsivanandan</description>
		<content:encoded><![CDATA[<p><a href="#comment-1805" rel="nofollow">@Faizan </a><br />
I&#8217;d need to see the config.</p>
<p>Mention the IP of interest as well.</p>
<p>Cheers,<br />
rsivanandan</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->