Summary of the content on the page No. 1
NETSCREEN-200 SERIES
User’s Guide
Version 5.0 P/N 093-1253-000 Rev. C
Summary of the content on the page No. 2
Copyright Notice Copyright © 2007 Juniper Networks, Inc. All rights reserved. Juniper Networks, the Juniper Networks logo, NetScreen, NetScreen Technologies, GigaScreen, and the NetScreen logo are registered trademarks of Juniper Networks, Inc. NetScreen-5GT, NetScreen-5XP, NetScreen-5XT, NetScreen-25, NetScreen-50, NetScreen-100, NetScreen-204, NetScreen-208, NetScreen-500, NetScreen-5200, NetScreen-5400, NetScreen-Global PRO, NetScreen-Global PRO Express, NetScreen-Remote Security Client, N
Summary of the content on the page No. 3
Contents Preface...............................................................................................................................................v Guide Organization ..................................................................................................v Command Line Interface (CLI) Conventions ............................................................ vi Juniper Networks NetScreen Publications ................................................................vi Chapter
Summary of the content on the page No. 4
Contents Establishing a Terminal Emulator Connection................................................ 22 Changing Your Admin Name and Password ................................................. 23 Setting Port and Interface IP Addresses ......................................................... 23 Viewing Current Interface Settings ............................................................23 Setting the IP Address of the Management Interface ...............................24 Setting the IP Addre
Summary of the content on the page No. 5
Preface The Juniper Networks NetScreen-200 Series consists of versatile, purpose-built, high- performance security systems that provide IPSec VPN and firewall services for medium and large enterprise offices, e-business sites, data centers, and carrier infrastructures. The NetScreen-200 Series includes the following device models: • The NetScreen-204, which has four 10/100 Base-T interface ports and performs firewall functions at 400 Mbps • The NetScreen-208, which has eight 10/100 Base-T inte
Summary of the content on the page No. 6
Preface COMMAND LINE INTERFACE (CLI) CONVENTIONS The following conventions are used when presenting the syntax of a command line interface (CLI) command: • Anything inside square brackets [ ] is optional. • Anything inside braces { } is required. • If there is more than one choice, each choice is separated by a pipe ( | ). For example, set interface { ethernet1 | ethernet2 | ethernet3 } manage means “set the management options for the ethernet1, ethernet2, or ethernet3 interface”. • Variabl
Summary of the content on the page No. 7
Chapter 1 1 Overview This chapter provides detailed descriptions of the NetScreen-200 Series system devices and their components. Topics in this chapter include: • “NetScreen-200 Systems” on page 2 – “NetScreen-204 Device” on page 2 – “NetScreen-208 Device” on page 2 • “The Front Panel” on page 3 – “System Status LED Display” on page 3 – “Asset Recovery Pinhole” on page 4 – “Console and Modem Ports” on page 5 – “Compact Flash Card Slot” on page 5 – “Ethernet Interfaces” on page 6 • “The Rear Pa
Summary of the content on the page No. 8
Chapter 1 Overview NETSCREEN-200 SYSTEMS This NetScreen-200 Series currently includes the NetScreen-204 device and the NetScreen-208 device. NetScreen-204 Device The NetScreen-204 is a chassis-based, rack-mountable network security device with four ethernet 10/100 Base-T interface ports. The figure below shows a NetScreen-204 device. System Status LEDs Asset Recovery Console Modem Compact Flash Ethernet Interfaces Pinhole Port Port Card Slot NetScreen-208 Device The NetScreen-208 is a chassis-
Summary of the content on the page No. 9
The Front Panel THE FRONT PANEL The features shared in common by NetScreen-204 and NetScreen-208 devices include: • A System Status LED display • An Asset Recovery Pinhole • A Console port • A Modem port • A Compact Flash Card Slot • Ethernet interfaces System Status LED Display The front panel of each NetScreen-200 Series device has a System Status display, which contains six LEDs. Status LED HA LED Power LED Flash LED Alarm LED Session LED The information revealed by each LED is as follows: L
Summary of the content on the page No. 10
Chapter 1 Overview Alarm System Alarm red Critical alarm: • Failure of hardware component or software module (such as a cryptographic algorithm). Firewall attacks detected. HA status changed amber Major alarm: Low memory (less than 10% remaining). High CPU utilization (more than 90% in use). Session full. Maximum number of VPN tunnels reached. HA redundant group member not found. off No alarms. Status Session amber Session utilization is between 70% and 90%. Utilization red Sessio
Summary of the content on the page No. 11
The Front Panel Console and Modem Ports The Console port is an RJ-45 serial console port connector, for vt100 terminal emulator programs to perform local configuration and administration. The Modem port is an RJ-45 serial console port connector, for establishing remote console sessions using dialup connections through a 9600 bps modem connected via an RS-232 cable. Dialing into the modem establishes the dialup console connection. The table below lists the RJ-45 to DB-9 adapter connection defi
Summary of the content on the page No. 12
Chapter 1 Overview Ethernet Interfaces Each Ethernet port is a 10/100 auto-sensing interface with two link LEDs. The left LED indicates network traffic, and the right LED indicates an active network link. Network Traffic: Network Link: Blinking = link activity On = link is up Off = link is down THE REAR PANEL The figure below shows the rear panel of a NetScreen-200 Series device (with an AC power supply). Power Outlet Fuse Cover Power Switch Note: Certain export restrictions may apply to inter
Summary of the content on the page No. 13
The Rear Panel Power Fuse Each NetScreen-200 Series device uses a 2.5 Amp, slow-blow power fuse rated for 250 Volts. To replace a fuse on a NetScreen-200 Series device: 1. Take the device off-line by turning the power switch OFF and disconnecting the power cable. 2. Using a screwdriver, separate the lid of the external fuse cover from the surface of the power outlet. 3. Gently remove the fuse assembly. 4. Slide the new fuse into the opening until the fuse clicks into place. 5. Replace the pow
Summary of the content on the page No. 14
Chapter 1 Overview 8 User’s Guide
Summary of the content on the page No. 15
Chapter 2 2 Installing the Device This chapter describes how to install a device in an equipment rack or on a desktop, and how to connect the device to other devices. Topics in this chapter include: • “General Installation Guidelines” on page 10 • “Performing Equipment-Rack Installation” on page 10 – “Equipment Rack Installation Guidelines” on page 10 – “Front Mount” on page 11 – “Mid-Mount” on page 11 • “Connecting the Power” on page 11 • “Wiring a DC Power Supply” on page 12 • “Connecting the
Summary of the content on the page No. 16
Chapter 2 Installing the Device GENERAL INSTALLATION GUIDELINES Observing the following precautions can prevent injuries, equipment failures and shutdowns. • Never assume that the power supply is disconnected from a power source. Always check first. • Room temperature might not be sufficient to keep equipment at acceptable temperatures without an additional circulation system. Ensure that the room in which you operate the device has adequate air circulation. • Do not work alone if potentiall
Summary of the content on the page No. 17
Connecting the Power There are two ways to rack-mount the NetScreen-200 Series: • Front mount • Mid-mount Front Mount To front mount the NetScreen-200 Series device on your equipment rack: 1. Screw the front mount bracket to the side of the chassis. 2. Screw the front mount bracket to the rack, as shown below. Mid-Mount To mid-mount the NetScreen-200 Series device on your equipment rack: 1. Screw the mid-mount bracket to the side of the chassis. 2. Screw the mid-mount bracket to the rack, as sho
Summary of the content on the page No. 18
Chapter 2 Installing the Device WIRING A DC POWER SUPPLY The DC power supply, ON/OFF switch, grounding screw, and terminal blocks, are located in the back of the chassis of the power supply unit. Power Switch Grounding Screw DC Power Terminal Blocks Warning: You must shut off the current to the DC feed wires before connecting the wires to the power supplies. Also, make sure that the ON/OFF switch is in the OFF position. To connect the DC power supply to a grounding point at your site: 1. Remo
Summary of the content on the page No. 19
Connecting the NetScreen-200 Device to Other Devices CONNECTING THE NETSCREEN-200 DEVICE TO OTHER DEVICES To connect the device, use the ethernet interfaces (ethernet1 through ethernet4 on the NetScreen-204, or ethernet1 through ethernet8 on the NetScreen-208). The purpose of each interface depends upon the security zone to which it is bound. By default, the zone and interface bindings are as follows: • ethernet1 is bound to the Trust security zone by default. Connect this interface using a t
Summary of the content on the page No. 20
Chapter 2 Installing the Device 14 User’s Guide