Digital Certificate exchange
Good evening,i would like to check my understanding in PKI: 1-if we have 2 HOSTS (Host A and Host B) under same CA, what will happen is :each Host will receive a local certificate and CA-certificate...
View ArticleRe: Digital Certificate exchange
Hello, 1) 'Host A will receive the local certificate from Host B and will use the CA-Certificate to validate it' --- In simple terms you are right. 2) At no point of time Host sends the CA certificate...
View ArticleRe: Digital Certificate exchange
That's soo confusing When i was studying it was said that you may receive a certificate chain from a remote peer containing EE certificate and intermediate CA-certificates and you will use the common...
View ArticleRe: Digital Certificate exchange
https://www.juniper.net/documentation/en_US/junos/topics/concept/security-pki-certificate-chain-understanding.html i have been reading the same thing while studying ( understanding PKI ) please Mr....
View ArticleRe: Digital Certificate exchange
Hello, Your understanding is not entirely wrong. In simple words:- * Recipient must maintain the certificate chain if it needs to secure authenticate peer when their Sub-CAs are different.* Sender can...
View ArticleRe: Fabric Monitoring
Hello, As long as your fabric is healthy, in my opinion it should not have any impact. Regards, Rushi
View ArticleRe: PKI- validation
Hello, So that entity requesting it can confirm that response has come from the valid CA. Regards, Rushi
View ArticleSRX240 Change the Broadband IP
Hello, My Public IP not enough to use, So I apply to ISP renew more IP. On the SRX, All public IP is set to reth 1.0 port, source and dest NAT, Would you have suggest to do change the public IP?!...
View ArticleRe: SRX240 Change the Broadband IP
Hi Zero, So if we understand properly, the public IP pool provided to you by ISP is not enough for your network and hence you have requested for few more Ips.If the ISP is the same and the old public...
View ArticleRe: SRX240 Change the Broadband IP
Unfortunately, ISp gave different IP and Subnet to me. How could I re-configure the new IP and subnet on SRX240? Thanks!!!
View Article/var/db/utm_policy.id: File too large
Hello,I have problem witch my SRX 210, when I try to check new configuration, I see message # commit check error: could not open /var/db/utm_policy.id: File too large error: foreign file propagation...
View ArticleRe: /var/db/utm_policy.id: File too large
Possible file system corruption, try doing junos re-install or an upgrade.
View ArticleRe: SRX240 Change the Broadband IP
Whats the gateway for new subnet IPs provided by ISP? Is that same as old one?
View ArticleRe: /var/db/utm_policy.id: File too large
I my opinion file system is ok, when I try check this file % cat /var/db/utm_policy.idI see three license records
View ArticleRe: /var/db/utm_policy.id: File too large
Did you try reboot? Do you have active UTM license/config?
View ArticleRe: Fabric Monitoring
Before application run show chassis cluster interfaces And be sure there are no errors or warnings in progress. If you enable when in some inconsistent state you may trigger failover events. I would...
View ArticleRe: SRX240 Change the Broadband IP
You will need to change the following types of configuration with this: the interfacethe default routeDestination and source NAT using ip addresses specifically in this range (interface NAT can stay...
View ArticleRe: /var/db/utm_policy.id: File too large
No, I didn't reboot, because I can't at this moment. In this file are three licenses and this licenses are expired. But few days ago I change configuration and everything was ok.
View ArticleRe: Digital Certificate exchange
im really upset with juniper explanation of stuff . this is not the first time to keep studying a topic and find out that my understanding is wrong
View ArticleSRX3600 In Service Upgrade
Hello everyone! Do I need to upload the new firmware on both devices in an in-service upgrade? Or is it enough when I do this on the master
View Article