ScreenOS Cookbook

Front Cover
"O'Reilly Media, Inc.", Feb 26, 2008 - Computers - 814 pages

Written by key members of Juniper Network's ScreenOS development team, this one-of-a-kind Cookbook helps you troubleshoot secure networks that run ScreenOS firewall appliances. Scores of recipes address a wide range of security issues, provide step-by-step solutions, and include discussions of why the recipes work, so you can easily set up and keep ScreenOS systems on track.

ScreenOS Cookbook gives you real-world fixes, techniques, and configurations that save time -- not hypothetical situations out of a textbook. The book comes directly from the experience of engineers who have seen and fixed every conceivable ScreenOS network topology, from small branch office firewalls to appliances for large core enterprise and government, to the heavy duty protocol driven service provider network. Its easy-to-follow format enables you to find the topic and specific recipe you need right away and match it to your network and security issue.

Topics include:

  • Configuring and managing ScreenOS firewalls
  • NTP (Network Time Protocol)
  • Interfaces, Zones, and Virtual Routers
  • Mitigating Denial of Service Attacks
  • DDNS, DNS, and DHCP
  • IP Routing
  • Policy-Based Routing
  • Elements of Policies
  • Authentication
  • Application Layer Gateway (SIP, H323, RPC, RTSP, etc.,)
  • Content Security
  • Managing Firewall Policies
  • RIP, OSPF, BGP, and NSRP
  • Multicast -- IGPM, PIM, Static Mroutes
  • Wireless
Along with the usage and troubleshooting recipes, you will also find plenty of tricks, special considerations, ramifications, and general discussions of interesting tangents and network extrapolation. For the accurate, hard-nosed information you require to get your ScreenOS firewall network secure and operating smoothly , no book matches ScreenOS Cookbook.


What people are saying - Write a review

We haven't found any reviews in the usual places.


ScreenOS CLI Architecture and Troubleshooting
Firewall Configuration and Management
Route Mode and Static Routing
Transparent Mode
Leveraging IP Services in ScreenOS
Network Address Translation
User Authentication
Traffic Shaping
High Availability with NSRP
PolicyBased Routing

Mitigating Attacks with Screens and Flow Settings
Application Layer Gateways
Content Security
Virtual Systems

Other editions - View all

Common terms and phrases

About the author (2008)

Stefan Brunner has been a technology consultant for more than 15years, helping enterprises to leverage technology for their businessmodel and deploy technology solutions. Stefan is the lead architectin Juniper Networks'' Service Layer Technology Professional Servicesgroup. Prior to Juniper, Stefan worked with NetScreen Technologies asa network security consultant. Stefan holds an MBA in innovationsresearch and technology management from Ludwig-Maximilians-Universityof Munich, and a certificate degree in telecommunications engineeringfrom the University of California at Berkeley. He lives with his wifeand daughter in the Hill Country of Austin, Texas.

Vik Davar has been working in the IT field for more than 15 years,holding positions in financial services firms and technologycompanies including Juniper Networks and Goldman Sachs. Vik is thepresident of 9 Networks, an IT services company. He has a master''sdegree in electrical engineering from Columbia University and abachelor''s degree in electrical engineering from The Cooper Union inNew York City. He is also a CISSP and CCIE# 8377. He lives in NewJersey with his wife and two children.

David Delcourt has worked in the data communications industry for thepast 13 years for enterprise equipment vendors including CabletronSystems and NetScreen Technologies. He has held a variety ofpositions, including advanced TAC engineer, technical trainer, andproduct manager at Cabletron Systems, and senior security consultantat NetScreen Technologies. He is currently the security practicemanager in Professional Services for Juniper Networks, supporting theAmericas. He lives in New Hampshire with his wife and daughter, andtheir two dogs and two cats.

Ken Draper has spent the past 20 years in the networking industry,and has focused on security solutions for the past 11 years. He isCISSP certification #22627 and holds numerous other certifications.Ken has worked at such networking equipment manufacturers asInfotron, Gandalf, Synoptics, Bay Networks, Nortel, NetScreen, andnow Juniper Networks. He has more than six years of experience withScreenOS and large-scale security solutions, he has held a variety oftechnical engineering positions including systems engineer andsolutions architect, and he is currently a Juniper Networksconsulting engineer specializing in the large-scale virtual privatenetwork (VPN), firewall, intrusion prevention, and centralizedmanagement markets. Ken lives outside Dallas with his wife and twodogs.

Joe Kelly has been involved in data networking for more than 12years, focusing on the realms of network security and routing. Hestarted his career in the service provider space at IDT Corporation,where he held roles in network operations and engineering. After IDT,he spent time with various network service providers in engineeringand architectural capacities. In 2001, Joe joined NetScreenTechnologies as a senior systems engineer in the Financial andService Provider verticals, where he specialized in high-availability, high-performance networks. Joe joined Juniper Networksin 2004 with the acquisition of NetScreen, and he is currently thetechnical lead on the Global Banking and Finance team. He lives inNew Jersey with his beautiful wife, Jacqueline, and his threechildren, Hannah, Ben, and Tristan.

Sunil Wadhwa has been in the data networking industry for more than13 years, focusing on systems, network routing, and security inenterprise and service provider organizations. He started his careerin India at GTL Limited and SAP India, and then held a variety ofroles in technical support, network operations, and engineering. Hemoved to the United States and worked with E4E as a networkconsultant for routing and security, and then joined Juniper Networksas an advanced technical support engineer for firewall/VPN products.He currently leads the Advance Technical Support team for JuniperNetworks, supporting enhanced services products. He lives inCalifornia with his beautiful wife, Lavanya, and little angeldaughter, Sneha.