background image

Chapter 3 Configuring the Device

12

User’s Guide

2

3(5$7,21$/

0

2'(6

The NetScreen-25 device supports two operational modes: Transparent and Route. The 
default mode is Route.

7UDQVSDUHQW0RGH

In Transparent mode, the NetScreen-25 device operates as a Layer-2 bridge. Because the 
device cannot translate the IP addresses of packets, it cannot perform Network Address 
Translation (NAT). Consequently, for the device to access the Internet, any IP address in 
your trusted (local) networks must be routable and accessible from untrusted (external) 
networks.

In Transparent mode, the IP addresses for the Trust and Untrust zones are 0.0.0.0, thus 
making the NetScreen device invisible to the network. However, the device can still 
perform firewall, VPN, and traffic management according to configured security policies.

5RXWH0RGH

In Route mode, the NetScreen-25 device operates at Layer 3. Because you can configure 
each interface using an IP address and subnet mask, you can configure individual 
interfaces to perform NAT.

When the interface performs NAT services, the device translates the source IP 
address of each outgoing packet into the IP address of the untrusted port. It also 
replaces the source port number with a randomly-generated value.

When the interface does not perform NAT services, the source IP address and 
port number in each packet header remain unchanged. Therefore, to reach the 
Internet your local hosts must have routable IP addresses.

For more information on NAT, see the NetScreen Concepts & Examples ScreenOS 
Reference Guide
.

Important:  

Performing the setup instructions below configures your device in Route 

mode. To configure your device in Transparent mode, see the NetScreen Concepts & 
Examples ScreenOS Reference Guide.

Содержание NetScreen-25

Страница 1: ...1 76 5 1 8VHU V XLGH Version 5 0 P N 093 1245 000 Rev A...

Страница 2: ...ications Operation of this equipment in a residential area is likely to cause harmful interference in which case users will be required to correct the interference at their own expense The following i...

Страница 3: ...LSPHQW 5DFN FFHVVRULHV DQG 5HTXLUHG 7RROV 1HW6FUHHQ 5DFN 0RXQW KDSWHU RQILJXULQJ WKH HYLFH 2SHUDWLRQDO 0RGHV 7UDQVSDUHQW 0RGH 5RXWH 0RGH 7KH 1HW6FUHHQ QWHUIDFHV RQQHFWLQJ WKH HYLFH WR D 1HWZRUN 3HUIRU...

Страница 4: ...RQWHQWV LY 8VHU V XLGH OHFWULFDO 6SHFLILFDWLRQ QYLURQPHQWDO 6DIHW HUWLILFDWLRQV 0 HUWLILFDWLRQV RQQHFWRUV QGH...

Страница 5: ...Overview provides an overview of the system its ports and power requirements Chapter 2 Installing the Device details how to install the NetScreen 25 device on a desktop or in a rack Chapter 3 Configu...

Страница 6: ...number of a NetScreen device 81 3 5 1 7 25 6 1 76 5 1 38 7 216 To obtain technical documentation for any Juniper Networks NetScreen product visit www netscreen com resources manuals To obtain the lat...

Страница 7: ...and Modem Ports on page 4 Compact Flash Card Slot on page 4 Ethernet Interfaces on page 5 The Rear Panel on page 5 Note For safety warnings and instructions please refer to the NetScreen Safety Guide...

Страница 8: ...as HyperTerminal A Modem port A Compact Flash card slot for storage of system images configuration files keys and logs Four Ethernet ports for connecting the NetScreen 25 device to your LAN or local w...

Страница 9: ...ry 10 remaining High CPU utilization 90 Log memory full Sessions full Maximum number of VPN tunnels reached Firewall attacks detected off No alarms Status 1 System Status blinking green Normal operati...

Страница 10: ...ART port both the console and the modem ports must use this configuration RPSDFW ODVK DUG 6ORW The Compact Flash slot is for downloading or uploading system software or configurations This slot can ac...

Страница 11: ...he left LED indicates network traffic activity and the right LED indicates if the link is up the port is connected to an active device 7 5 5 3 1 The rear panel of the NetScreen 25 device contains the...

Страница 12: ...Chapter 1 Overview 6 User s Guide...

Страница 13: ...age 8 Equipment Rack Installation Guidelines on page 8 Equipment Rack Accessories and Required Tools on page 9 NetScreen 25 Rack Mount on page 9 Note For safety warnings and instructions please refer...

Страница 14: ...standard 19 inch equipment rack TXLSPHQW 5DFN QVWDOODWLRQ XLGHOLQHV The location of the chassis the layout of the equipment rack and the security of your wiring room are crucial for proper system oper...

Страница 15: ...t required 4 screws to match the rack if the thread size of the screws provided in the NetScreen 25 product package do not fit the thread size of the rack The included rack mount bracket kit 1HW6FUHHQ...

Страница 16: ...Chapter 2 Installing the Device 10 User s Guide...

Страница 17: ...to Reset the Device on page 19 Using the Asset Recovery Pinhole to Reset the Device on page 20 Note You must register your product at www netscreen com cso so that certain ScreenOS services such as t...

Страница 18: ...ding to configured security policies 5RXWH 0RGH In Route mode the NetScreen 25 device operates at Layer 3 Because you can configure each interface using an IP address and subnet mask you can configure...

Страница 19: ...y default you can bind it to another zone as required ethernet1 Bound to the Trust security zone by default Connect this interface using a twisted pair cable with RJ45 connectors ethernet2 Bound to th...

Страница 20: ...wer outlet at the rear of the device and to a power source 4 Connect an RJ 45 cross over cable from the Trust zone interface Ethernet port 1 to the internal switch router or hub 5 Connect an RJ 45 str...

Страница 21: ...terminal emulator such as Hilgraeve Hyperterminal through an RJ 45 serial cable connected to the console port Using Telnet through a TCP IP network connection to the NetScreen 25 device RQQHFWLQJ 8VLQ...

Страница 22: ...IP address within the current address range of your Local Area Network 2 Set the IP address of the Trust zone interface to this unused IP address by executing the following command set interface ethe...

Страница 23: ...point on the Trust network to any point on the Untrust network set policy outgoing inside any outside any any permit save You can also use the Outgoing Policy Wizard in the WebUI management applicatio...

Страница 24: ...assigned the Trust zone interface of the device the IP address of 10 100 2 183 16 enter the following 10 100 2 183 The NetScreen WebUI software displays the login prompt 3 Enter netscreen in both the...

Страница 25: ...have initiated a command to reset the device to factory defaults clearing all current configuration and settings Would you like to continue y n Warning Resetting the device will delete all existing c...

Страница 26: ...vt100 Terminal Emulator on page 15 1 Locate the asset recovery pinhole on the front panel Using a thin firm wire such as a paper clip push the button located behind the asset recovery pinhole for fou...

Страница 27: ...restarts If you do not follow the complete sequence the reset process cancels without any configuration change and the serial console message states Configuration Erasure Process aborted The status LE...

Страница 28: ...Chapter 3 Configuring the Device 22 User s Guide...

Страница 29: ...er switch OFF and disconnect the power cable 2 Using a screwdriver separate the lid of the external fuse cover from the surface of the power outlet 3 Manually remove the fuse assembly from the device...

Страница 30: ...Chapter 4 Replacing the Fuse 24 User s Guide...

Страница 31: ...ides general system specifications for the NetScreen 25 device NetScreen 25 Attributes on page A II Electrical Specification on page A II Environmental on page A II Safety Certifications on page A II...

Страница 32: ...100 240 VAC 10 DC voltage 36 to 60 VDC Maximum AC Watts 45 Watts Maximum DC Watts 50 Watts Fuse Rating 2 5 Amps 250 Volts 19 5210 17 The maximum normal altitude is 12 000 ft 0 3 660 m 6 7 57 7 216 UL...

Страница 33: ...compatible with the IEEE 802 3 Type 10 100 Base T standard The following table displays the media type and distance for this connector Standard Media Type Mhz Km Rating Maximum Distance 100Base TX Ca...

Страница 34: ...Appendix A Specifications A IV User s Guide...

Страница 35: ...meout 16 17 initiating a session 15 console port 4 guide organization v installation guidelines 8 LEDs Alarm 3 Flash 3 Power 3 Session 3 Status 1 3 Status 2 3 0 management software logging on 18 1 Net...

Страница 36: ...Index IX II User s Guide...

Отзывы: