meetsek:
Thanks a lot for your detailed explanations, Rod.
We usually put an ecommerce websites on one of our shared servers
We use Juniper Networks SSG5
I guess these are your own servers? (I can't see any other reason why you'd be using the SSG5)
meetsek:
I'll take a look at the settings and see what I can do.
Does your network use subnets, or are all hosts on the same network? If all on the same network (and I assume you have your own public IP's) the simplest safe configuration would be to enable all outgoing traffic on all interfaces to any host/port, block all incoming traffic except on the internet connected interface and destined to the hosts and ports you specifically allow, and enable the connection tracking to take care of reply packets.
If you don't have a set of public IP addresses you'll need to rules for NAT translation.
If you are using subnets you'll need to restrict/allow each interface according to the needs of the subnet(s).
Whilst all of this can be done via the GUI, most network admins would favour the CLI to configure these things. It is a lot easier (and quicker) to dump the settings to a text file, make any needed changes using a text editor and then uploading the new file, rather than navigating around all of the different GUI screens. Having said that, if you are 'addicted' to the GUI it is still a good idea to dump the settings to a text file anyway (it'll give a far better idea of what the GUI is actually doing), and these files can be a useful backup/recovery tool for those times that you'll invariably lock yourself out of the device and need to perform a hardware reset :)
Apologies if this goes over (or under) your head, but I have no idea of knowing your skill level with this kind of device. The fact that you have one suggests to me than you probably know more about networks than the average joe, on the other hand, the problem you are having suggests that what you have is an overkill for what you are actually needing, which is where my simple/safe configuration suggestion should prove useful. :)
Cheers
Rod