Inhaltszusammenfassung zur Seite Nr. 1
NETSCREEN-5000 SERIES
User’s Guide
Version 5.0 P/N 093-1698-000 Rev. D
Inhaltszusammenfassung zur Seite Nr. 2
Copyright Notice Copyright © 2006 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, NetScreen, NetScreen Technologies, GigaScreen, and the NetScreen logo are registered trademarks of Juniper Networks, Inc. NetScreen-5GT, NetScreen-5XP, NetScreen-5XT, NetScreen-25, NetScreen-50, NetScreen-100, NetScreen-204, NetScreen-208, NetScreen-500, NetScreen-5200, NetScreen-5400, NetScreen-Global PRO, NetScreen-Global PRO Express, NetScreen-Remote Security Client, N
Inhaltszusammenfassung zur Seite Nr. 3
Table of Contents Preface...................................................................................................................vii Guide Organization ................................................................................... vii Command Line Interface (CLI) Conventions ............................................. viii Juniper Networks NetScreen Publications ................................................. viii Chapter 1 Overview ..........................................
Inhaltszusammenfassung zur Seite Nr. 4
Table of Contents NetScreen-5400 Interfaces............................................................................ 24 Configurable Interfaces ................................................................................ 24 Performing Initial Connection and Configuration .....................................25 Establishing a Terminal Emulator Connection................................................ 25 Upgrading the Firmware During the Boot Process ......................................
Inhaltszusammenfassung zur Seite Nr. 5
EMI Certifications .....................................................................................A-III Connectors ..............................................................................................A-III Appendix B Port Descriptions and LED Status........................................................ B-I Module Port Descriptions ..........................................................................B-II Module LED Descriptions ..............................................
Inhaltszusammenfassung zur Seite Nr. 6
Table of Contents vi User’s Guide
Inhaltszusammenfassung zur Seite Nr. 7
Preface The Juniper Networks NetScreen-5000 Series consists of purpose-built, high-performance security systems that provide IPSec VPN and firewall services for large-scale carrier, enterprise, and data-center networks. Built around NetScreen’s third-generation ASIC technology and distributed system architecture, the NetScreen-5000 Series offers excellent scalability and flexibility. The NetScreen-5000 Series includes the following device models: • The NetScreen-5200, a chassis-based, two-sl
Inhaltszusammenfassung zur Seite Nr. 8
Preface COMMAND LINE INTERFACE (CLI) CONVENTIONS The following conventions are used when presenting the syntax of a command line interface (CLI) command: • Anything inside square brackets [ ] is optional. • Anything inside braces { } is required. • If there is more than one choice, each choice is separated by a pipe ( | ). For example, set interface { ether1/1 | ether1/2 | ether2/2 } manage means “set the management options for the ether1/1, ether1/2, or ether2/2 interface”. • Variables appe
Inhaltszusammenfassung zur Seite Nr. 9
Chapter 1 Overview 1 This chapter provides detailed descriptions of the NetScreen-5000 Series, modules, power supplies, and fan assemblies. Topics explained in this chapter include: • “NetScreen-5000 Series” on page 2 – “NetScreen-5200” on page 2 – “NetScreen-5400” on page 2 • “Power Supplies” on page 3 – “NetScreen-5200 Power Recommendations” on page 3 – “NetScreen-5400 Power Recommendations” on page 3 – “The DC Power Supply” on page 4 – “The AC Power Supply” on page 4 • “Fan Modules” on page
Inhaltszusammenfassung zur Seite Nr. 10
Chapter 1 Overview NETSCREEN-5000 SERIES This section describes the NetScreen-5000 Series, which currently includes the NetScreen-5200 and the NetScreen-5400. NetScreen-5200 The NetScreen-5200 is a chassis-based, two-slot network security device with a 2U (rack unit) chassis. Slot 1 is for the management module and Slot 2 is for the Secure Port Module (SPM). The device has two hot-swappable power supplies for power redundancy and a removable fan module. The figure below shows a NetScreen-520
Inhaltszusammenfassung zur Seite Nr. 11
Power Supplies POWER SUPPLIES The NetScreen-5000 Series can use two kinds of power supplies: • Direct Current (DC) Power Supply • Alternating Current (AC) Power Supply The slots for these power supplies are located in the back of the NetScreen-5200 and on the front of the NetScreen-5400. Note: You can order a NetScreen-5000 Series that runs on DC power. For DC-powered units, the power supply has a DC terminal block with three sockets. When two or more power supplies are in service, they share
Inhaltszusammenfassung zur Seite Nr. 12
Chapter 1 Overview The DC Power Supply The DC power supply weighs about three pounds. The faceplate contains a power LED, a power switch, a cooling fan vent, and three DC power terminal blocks that connect to power cables. The figure below shows the NetScreen-5200 DC power supply. Thumbscrew DC Power Power Terminal LED Blocks Grounding Screw Power Switch The AC Power Supply The AC power supply weighs about three pounds. The faceplate contains a power LED, a power switch, a male power outle
Inhaltszusammenfassung zur Seite Nr. 13
Fan Modules FAN MODULES The NetScreen-5200 has a three-fan module and the NetScreen-5400 has a two-fan module. You can access the fan module from the left front side of each chassis. • To remove the NetScreen-5200 fan module, turn the fan knob in the unlock position, then gently pull the fan module lever toward you to slide the module out. • To remove the NetScreen-5400 fan module, loosen the two thumb screws that secure the fan module, then gently slide the module out. If a fan stops operat
Inhaltszusammenfassung zur Seite Nr. 14
Chapter 1 Overview Management Modules The management module provides general-purpose CPU delivery, and contains dedicated High Availability (HA) and management interfaces. It handles tasks such as management access, session setup and termination, and Internet Key Exchange (IKE) negotiation. There are currently two management modules: The 5000-M and 5000-M2. The 5000-M Management Module The 5000-M management module is based around a powerful, 600-MHz PowerPC CPU, which assists other system el
Inhaltszusammenfassung zur Seite Nr. 15
NetScreen-5000 Modules The 5000-M2 Management Module The 5000-M2 management module is based around powerful, dual 1GHz PowerPC CPUs, which assist other system elements, primarily with non-flow related tasks. The 5000-M2 management module provides overall management and control of the system. Although it performs system management, the primary function of the 5000-M2 is to support the other modules. Features of the 5000-M2 management module include: • A management port, for WebUI management o
Inhaltszusammenfassung zur Seite Nr. 16
Chapter 1 Overview Secure Port Modules Secure Port Modules (SPMs) perform general packet processing and device connection tasks for devices that communicate with the NetScreen-5000 Series. These modules are based around the GigaScreen-II ASIC. SPMs handle packets as they enter and exit the system, providing packet parsing, classification, and flow-level processing. SPMs also provide encryption, decryption, Network Address Translation (NAT), and session lookup features. When packets require
Inhaltszusammenfassung zur Seite Nr. 17
NetScreen-5000 Modules The 5000-2G24FE SPM The 5000-2G24FE SPM provides two 1-Gigabit Ethernet ports and 24 Fast Ethernet (FE) ports with up to 2 Gbps of firewall and up to 1 Gbps of VPN process capacity. This module is capable of supporting a total of six aggregate interfaces. This total consists of one aggregate interface for the two 1-Gigabit ports, and five aggregate interfaces for the 24 10/ 100 Ethernet ports. Only similar ports can be aggregated together. For example, you cannot aggre
Inhaltszusammenfassung zur Seite Nr. 18
Chapter 1 Overview The 5000-8G2 SPM The 5000-8G2 SPM provides eight 1-Gigabit mini-GBIC Ethernet ports using hot-swappable transceivers. The 5000-8G2 SPM delivers up to 8 Gbps of firewall and up to 4 Gbps of VPN capacity. This module is also capable of supporting a total of four aggregate interfaces, with up to four ports for each aggregate interface. This SPM cannot be mixed with the 5000-8G or 5000-2G24FE SPMs. (For details on connecting or removing a mini-GBIC transceiver and connecting a
Inhaltszusammenfassung zur Seite Nr. 19
NetScreen-5000 Modules The 5000-2XGE SPM The 5000-2XGE SPM provides two 10-Gigabit mini-GBIC Ethernet ports using hot-swappable transceivers. The 5000-2XGE SPM delivers up to 10 Gbps of firewall and up to 5 Gbps of VPN capacity. This SPM cannot be mixed with the 5000-8G or 5000- 2G24FE SPMs. (For details on connecting or removing a mini-GBIC transceiver and connecting and disconnecting a Gigabit Ethernet cable, see Chapter 4, Servicing the Device.) The 5000-2XGE SPM provides port Link and Act
Inhaltszusammenfassung zur Seite Nr. 20
Chapter 1 Overview 12 User’s Guide