
•
WAN interface–The Ethernet interface labeled
0/0
on the services gateway chassis
(called as ge-0/0/0 in J-Web and the CLI ) is in Layer 3 (routing) mode.
This WAN interface is used to connect your services gateway to your ISP. By default,
the WAN port is a Dynamic Host Control Protocol (DHCP) client and configured to
receive an IP address through DHCP.
•
LAN interfaces–Ethernet interfaces labeled
0/1
through
0/7
(called as ge-0/0/1,
fe-0/0/2 to fe-0/0/7 ) are in Layer 2 mode (Ethernet switching mode) and assigned
to a VLAN (
vlan-trust
).
A VLAN interface (Layer 3 interface) is created to route traffic from the interfaces in
the LAN (ge-0/0/1, fe-0/0/2 to fe-0/0/7) to WAN (ge-0/0/0) interface and vice versa.
All traffic between the ports within the VLAN is locally switched. The trust zone VLAN
interface (vlan.0) has a default static IP of 192.168.1.1/24, and assigns IP addresses in
the 192.168.1.2 to 192.168.1.254 range to any device plugged into the trust interfaces.
Default Settings for Interfaces, Zones, Policy, and NAT
provides the default configuration of the interfaces on an SRX210.
Table 3: Default Interfaces Settings
IP Address
DHCP State
Security Zones
Interface
Dynamically assigned
Client
Untrust
ge-0/0/0
192.168.1.1/24
Server
Trust
vlan.0
NOTE:
Because Ethernet interfaces (ge-0/0/1, fe-0/0/2 to fe-0/0/7) are
assigned to the trust zone (vlan-trust), any traffic originating from these
interfaces is treated as trust.
provides the default security policies to block traffic coming from the
untrust zone to devices in the trust zone.
Table 4: Default Security Policy Settings
Policy Action
Destination Zone
Source Zone
Permit
Untrust
Trust
Deny
Trust
Untrust
NOTE:
In default configuration, all LAN interfaces are in Layer 2 mode and
they communicate with each other without need of any policy.
9
Copyright © 2016, Juniper Networks, Inc.
Chapter 2: Understanding Factory Default Configuration Settings
Summary of Contents for Junos OS
Page 6: ...Copyright 2016 Juniper Networks Inc vi Getting Started Guide for Branch SRX Series...
Page 8: ...Copyright 2016 Juniper Networks Inc viii Getting Started Guide for Branch SRX Series...
Page 10: ...Copyright 2016 Juniper Networks Inc x Getting Started Guide for Branch SRX Series...
Page 18: ...Copyright 2016 Juniper Networks Inc 2 Getting Started Guide for Branch SRX Series...
Page 20: ...Copyright 2016 Juniper Networks Inc 4 Getting Started Guide for Branch SRX Series...
Page 22: ...Copyright 2016 Juniper Networks Inc 6 Getting Started Guide for Branch SRX Series...
Page 32: ...Copyright 2016 Juniper Networks Inc 16 Getting Started Guide for Branch SRX Series...
Page 42: ...Copyright 2016 Juniper Networks Inc 26 Getting Started Guide for Branch SRX Series...
Page 44: ...Copyright 2016 Juniper Networks Inc 28 Getting Started Guide for Branch SRX Series...
Page 46: ...Copyright 2016 Juniper Networks Inc 30 Getting Started Guide for Branch SRX Series...
Page 54: ...Copyright 2016 Juniper Networks Inc 38 Getting Started Guide for Branch SRX Series...
Page 62: ...Copyright 2016 Juniper Networks Inc 46 Getting Started Guide for Branch SRX Series...
Page 78: ...Copyright 2016 Juniper Networks Inc 62 Getting Started Guide for Branch SRX Series...
Page 86: ...Copyright 2016 Juniper Networks Inc 70 Getting Started Guide for Branch SRX Series...
Page 90: ...Copyright 2016 Juniper Networks Inc 74 Getting Started Guide for Branch SRX Series...
Page 155: ...PART 5 Index Index on page 141 139 Copyright 2016 Juniper Networks Inc...
Page 156: ...Copyright 2016 Juniper Networks Inc 140 Getting Started Guide for Branch SRX Series...