background image

Network and Security Manager

NSMXpress Series II Quick Start

November 17, 2010
Revision 1

NSMXpress Series II is an appliance version of Network and Security Manager (NSM).
NSMXpress Series II simplifies the complexity of network administration by providing a
single, integrated management interface that controls device parameters.

This robust hardware management system installs in minutes with full high availability
(HA) support, making it easy to scale and deploy. Enterprise customers with limited
resources can benefit significantly from NSMXpress Series II because it eliminates the
need to have dedicated resources for maintaining a network and security management
solution.

NSMXpress Series II makes it easy for administrators to control device configuration,
network settings, and security policy settings for multiple families of Juniper devices
including:

IDP Series Intrusion Detection and Prevention Appliances and Firewall and VPN devices
running ScreenOS

Devices running Junos OS, such as J Series Services Routers, SRX Series Services
Gateways, EX Series Ethernet Switches, M Series Multiservice Edge Routers, and MX
Series Ethernet Services routers

SA Series SSL VPN Appliances

IC Series Unified Access Control Appliances

For a complete list of supported device families and platforms, see the

Network and

Security Manager Administration Guide

.

Up to 10 administrators can log into NSMXpress Series II concurrently.

This quick start explains the following steps for installing and configuring NSMXpress
Series II and for configuring NSM.

1.

Install the NSMXpress Series II appliance hardware.

2.

Set up the NSMXpress Series II appliance using the serial port.

1

Copyright © 2010, Juniper Networks, Inc.

Содержание NETWORK AND SECURITY MANAGER NSMXPRESS SERIES II

Страница 1: ...onfiguration network settings and security policy settings for multiple families of Juniper devices including IDP Series Intrusion Detection and Prevention Appliances and Firewall and VPN devices runn...

Страница 2: ...anging the Superuser Password 18 Downloading NSM MIBS Regional Server Only 19 Exporting Audit Logs 19 Exporting Device Logs Regional Server Only 19 Generating Reports Regional Server Only 20 Modifying...

Страница 3: ...rk Data 41 Process Count 41 Disk Data 41 Tile All Graphs 41 Upgrading the Recovery Partition 42 Troubleshooting 43 Auditing User Operations 43 Error Logs 44 Network Utilities 45 Ping 45 Traceroute 46...

Страница 4: ...e 4 provides required port information on the NSMXpress Series II Table 1 Required Ports on NSMXpress Series II Depends on Configuration Internet LAN Description Port Direction No No Yes SSH command l...

Страница 5: ...tion 2049 For more information on ports refer to the Network and Security Manager Installation Guide Installing the Hardware Follow these steps to unpack the NSMXpress Series II appliance and connect...

Страница 6: ...LED Hard disk LED Left LAN LED Right LAN LED NSMXpress II Hard disk Activity LED Hard disk Failure LED Network ports Console port USB maintenance port 7 Plug the console cable with the DB9 to RJ45 ad...

Страница 7: ...1 Data Terminal Ready DTR Output 2 Transmit Data TxD Output 3 Chassis Ground GND 4 Chassis Ground GND 5 Receive Data RxD Input 6 Data Set Ready DSR Input 7 Clear to Send CTS Input 8 Initial Setup Conf...

Страница 8: ...owered on the serial console displays diagnostic information before proceeding to the boot countdown When complete the serial console displays the login prompt terminal emulator NSMXpress juniper net...

Страница 9: ...ess is now active on the network To configure your system via a web browser connect to https 10 150 43 205 administration 2 Open a Web browser and paste the URL into the address text box 3 Press Enter...

Страница 10: ...ress Series II appliance as described in Initial Setup Configuration on page 7 3 Enter the https ip administration URL for your appliance in a Web browser See Web Interface Configuration on page 9 for...

Страница 11: ...Figure 3 Regional Server Configuration Main Menu Figure 4 Central Manager Configuration Main Menu 11 Copyright 2010 Juniper Networks Inc Configuring the NSM Software...

Страница 12: ...ommunicates Regional servers use this password to authenticate peer servers in an HA configuration and to authenticate the central manager The central manager uses this password to authenticate its pe...

Страница 13: ...4 Use the HA Remote IP option to enter the IP address for the HA peer in the HA cluster 5 Use the HA Link Failure Detection IP option to enter the IP address of a computer outside the HA cluster that...

Страница 14: ...al Figure 8 HA Links Options Use the options in this menu to set up a redundant link for the HA cluster If you are going to use a second link you need to set the IP address for eth1 before configuring...

Страница 15: ...fer to the Network and Security Manager Installation Guide Figure 10 HA Advanced Settings 11 Click Submit to save the HA options and return to the NSM Configuration Main Menu Advanced Options To displ...

Страница 16: ...page 16 Enabling and Configuring SRS Regional Server Only on page 17 Enabling and Configuring Remote Replication of the Database To configure remote replication of database settings 1 On the Advanced...

Страница 17: ...e default is off If you turn on this feature the server is used with the GUI server 3 Use the SRS DB IP option to enter the IP address for the server on which you have installed the SRS database serve...

Страница 18: ...in the left navigation tree to access the options described in this section These options are available only after installing NSM The following sections explain how to use each of the NSM Administrati...

Страница 19: ...port Audit Logs To export an audit log to a csv file select csv in the drop down list box and then enter the csv file name in the text box To export an audit log to a system log server select syslog i...

Страница 20: ...user is an NSM administrator and not an NSMXpress Series II user Enter a user name as domain user such as global super Modifying NSM Configuration Files To manually edit the GuiSrv cfg DevSvr dfg and...

Страница 21: ...the nsm setup utility all manual changes to the configuration files are lost Backing Up the NSM Database To configure backups of the NSM database select NSM Administration NSM Database Backup link und...

Страница 22: ...NSM Administration NSM Management IP link under NSM Administration See Figure 21 on page 22 Figure 21 Change Management IP Scheduling Security Updates To schedule security updates select NSM Administr...

Страница 23: ...on page 26 Monitoring with SNMP on page 29 Forwarding Syslog Messages on page 32 Changing the System Time on page 35 Installing Updates on page 35 Managing Users on page 36 Configuring the Web Interfa...

Страница 24: ...ion Network Configuration The Network Configuration window appears as shown in Figure 25 on page 24 Figure 25 Network Interfaces Options The following sections describe each of the options available i...

Страница 25: ...ure and manage routes and gateways See Figure 27 on page 25 Figure 27 Routes and Gateways Hostname and DNS Clients Use this option to configure and manage hostnames and DNS clients See Figure 28 on pa...

Страница 26: ...rvers authenticates the user the user is logged in with the privileges that are associated with the user profile If none of the servers authenticates the user the user login fails NOTE The NSMXpress S...

Страница 27: ...RADIUS Servers that have been added See Figure 30 on page 27 Figure 30 RADIUS Servers Dialog Box 2 Click Add to add a RADIUS Server to the WebUI The Add Radius Server dialog box appears See Figure 31...

Страница 28: ...the priority of a RADIUS server select the check box next to the name of the server whose priority you want to increase and click Move Up To decrease the priority of a RADIUS server select the check b...

Страница 29: ...instructions for configuring NSMXpress Series II for SNMP monitoring You must provide access credentials for the SNMP server a list of IP addresses from which logon requests will be accepted and the...

Страница 30: ...sword used on the NSMXpress Series II appliance 5 To limit SNMP Get requests to specific servers select Only and then enter the IP addresses of the permitted servers 6 Click Save SNMP System Informati...

Страница 31: ...IP address of the SNMP management server 4 Select from the following trap conditions Disk space low Enter the percentage of free disk space below which SNMP issues a trap Memory low Enter the percenta...

Страница 32: ...select SSL NSMXpress Series II creates a secure tunnel to the syslog receiver UDP messaging is available for basic syslog implementations The following sections provide procedures for managing syslog...

Страница 33: ...be sent to this receiver Device Server The GUI Server logs configured to be sent to this receiver GUI Server The HA Server logs configured to be sent to this receiver HA Server Adding and Configuring...

Страница 34: ...syslog receiver will be known by within NSM 6 In the IP field Enter the IP address of the syslog receiver 7 In the Transport field select the type of syslog receiver Select UDP for basic syslog implem...

Страница 35: ...d receiver 3 Make the desired changes to the configuration 4 Click Save to save and apply your edits to the configuration of this syslog receiver Deleting Syslog Receivers To delete a syslog receiver...

Страница 36: ...the WebUI NOTE You need System Administration permission to create users This topic contains the following sections Creating New NSMXpress Series II Users on page 36 Deleting a User on page 38 Editin...

Страница 37: ...ress Users dialog box appears with the new NSMXpress user listed To create a WebUI user 1 Select System Administration User Management The NSMXpress Users dialog box appears listing all NSMXpress user...

Страница 38: ...e and click Submit You can change the password and the user profile Understanding User Profiles NSMXpress Series II I provides four predefined user profiles that allow you to implement role based acce...

Страница 39: ...No Yes System Update No No No Yes User Management No No No Yes WebUI Configuration NSM Administration No No Yes Yes Change NSM Super User Password No No Yes Yes Download NSM MIBs No Yes Yes Yes Export...

Страница 40: ...ation WebUI Configuration The Allowed IP Addresses window appears as shown in Figure 40 on page 40 Figure 40 Web Interface Access Maintaining NSMXpress Series II The Maintaining section of the NSMXpre...

Страница 41: ...y to view graphs that monitor the memory activity hourly daily weekly and monthly Network Data Select either eth0 or eth1 to view graphs that monitor network activity hourly daily weekly and monthly P...

Страница 42: ...old recovery image files and installs the current version of the image files from the temporary workspace into the recovery partition By splitting the process into two phases NSMXpress Series II minim...

Страница 43: ...ities Auditing User Operations on page 43 Error Logs on page 44 Network Utilities on page 45 Tech Support on page 48 Auditing User Operations You can audit all user operations performed in NSMXpress S...

Страница 44: ...by a specific authentication mechanism Select Byanyauthentication except and choose a profile from the drop down list to exclude actions by an authentication mechanism Actionsinmodule Select the Inan...

Страница 45: ...c network utilities ping traceroute and nslookup for TCP IP Networking select Troubleshooting Network Utilities These tools also provide an IP subnet calculator SeeFigure 46 on page 45 Figure 46 Netwo...

Страница 46: ...ill fill it with random data This option is useful if you do not have problems with connectivity itself but with data loss Verbosity Output NSMXpress lists the ICMP packets other than ECHO_Response th...

Страница 47: ...he DNS database Enter a nameserver or select the default If you choose the default nslookup will use the server on which NSMXpress is installed Figure 49 Lookup Utility IP Subnet Calculator Use the IP...

Страница 48: ...and then click Run Tech Support Script NSMXpress creates a file you can download and send to Juniper Networks technical support See Figure 51 on page 48 Figure 51 Juniper Tech Support Viewing System...

Страница 49: ...eries II appliances in one rack you should install the lowest one first and proceed upward in the rack Install heavier NSMXpress Series II appliances in the lower part of the rack Front Mounting Flush...

Страница 50: ...o small screws towards the front of the chassis 2 Loosen the side rail screws of the chassis and slide the front rails of the system forward as far as they will move See Figure 54 on page 50 3 Tighten...

Страница 51: ...locking screws on the sides of the rear mount brackets to secure the front and rear mounting brackets in place See Figure 55 on page 51 4 Verify that the mounting screws on one side of the rack are al...

Страница 52: ...of the recessed front rails on either side of the unit This enables easy cable routing on the racks with limited cable management Mid Mount in Two Post Equipment Rack This option is suitable for a two...

Страница 53: ...n with the NSM Online Help which provides step by step instructions for performing management tasks in the NSM user interface UI This guide is intended for application administrators or those individu...

Страница 54: ...Provides details about configuring the device features for all supported Infranet Controllers Network and Security Manager Configuring Infranet Controllers Guide Provides details about configuring the...

Страница 55: ...ng our Knowledge Base http kb juniper net Download the latest versions of software and review release notes http www juniper net customers csc software Search technical bulletins for relevant hardware...

Страница 56: ...property of their respective owners Juniper Networks assumes no responsibility for any inaccuracies in this document Juniper Networks reserves the right to change modify transfer or otherwise revise t...

Отзывы: