Juniper Networks, Junos, Steel-Belted Radius, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United
States and other countries. The Juniper Networks Logo, the Junos logo, and JunosE are trademarks of Juniper Networks, Inc. All other
trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners.
Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify,
transfer, or otherwise revise this publication without notice.
SRX100 Services Gateway Hardware Guide for B and H Model Numbers
The information in this document is current as of the date on the title page.
YEAR 2000 NOTICE
Juniper Networks hardware and software products are Year 2000 compliant. Junos OS has no known time-related limitations through the
year 2038. However, the NTP application is known to have some difficulty in the year 2036.
END USER LICENSE AGREEMENT
The Juniper Networks product that is the subject of this technical documentation consists of (or is intended for use with) Juniper Networks
software. Use of such software is subject to the terms and conditions of the End User License Agreement (“EULA”) posted at
http://www.juniper.net/support/eula.html. By downloading, installing or using such software, you agree to the terms and conditions of
To obtain the most current version of all Juniper Networks®technical documentation,
see the product documentation page on the Juniper Networks website at
http://www.juniper.net/techpubs/.
If the information in the latest release notes differs from the information in the
documentation, follow the product Release Notes.
Juniper Networks Books publishes books by Juniper Networks engineers and subject
matter experts. These books go beyond the technical documentation to explore the
nuances of network architecture, deployment, and administration. The current list can
be viewed at http://www.juniper.net/books.
Supported Platforms
For the features described in this document, the following platforms are supported:
•
SRX100
Documentation Conventions
Table 1 on page xiv defines notice icons used in this guide.
Represents names of configuration
statements, commands, files, and
directories;configuration hierarchy levels;
or labels on routing platform
components.
About the Documentation
ExamplesDescriptionConvention
•
To configure a stub area, include the
stub statement at the [edit protocols
ospf area area-id] hierarchy level.
•
The console port islabeledCONSOLE.
stub <default-metric metric>;Encloses optional keywords or variables.< > (angle brackets)
| (pipe symbol)
# (pound sign)
[ ] (square brackets)
Indention and braces ( { } )
; (semicolon)
GUI Conventions
Bold text like this
Indicates a choice between the mutually
exclusivekeywordsor variables on either
side of the symbol. The set of choices is
often enclosed in parenthesesfor clarity.
same lineasthe configuration statement
to which it applies.
Encloses a variable for which you can
substitute one or more values.
Identifies a level in the configuration
hierarchy.
Identifies a leaf statement at a
configuration hierarchy level.
Representsgraphicaluser interface(GUI)
items you click or select.
broadcast | multicast
(string1 | string2 | string3)
rsvp { # Required for dynamic MPLS onlyIndicates a comment specified on the
community name members [
community-ids ]
[edit]
routing-options {
static {
route default {
nexthop address;
retain;
}
}
}
•
In the Logical Interfaces box, select
All Interfaces.
•
To cancel the configuration, click
Cancel.
> (bold right angle bracket)
Documentation Feedback
We encourage you to provide feedback, comments, and suggestions so that we can
improve the documentation. You can provide feedback by using either of the following
methods:
•
Online feedback rating system—On any page at the Juniper Networks Technical
Documentation site at http://www.juniper.net/techpubs/index.html, simply click the
stars to rate the content,and usethe pop-upform to provide uswith information about
your experience. Alternately, you can use the online feedback form at
https://www.juniper.net/cgi-bin/docbugreport/.
Separates levels in a hierarchy of menu
selections.
In the configuration editor hierarchy,
select Protocols>Ospf.
SRX100 Services Gateway Hardware Guide for B and H Model Numbers
•
E-mail—Sendyourcomments to techpubs-comments@juniper.net. Includethe document
or topic name, URL or page number, and software version (if applicable).
Requesting Technical Support
Technical product support is availablethrough the Juniper Networks Technical Assistance
Center (JTAC). If you are a customer with an active J-Care or Partner Support Service
support contract, or are covered under warranty, and need post-sales technical support,
you can access our tools and resources online or open a case with JTAC.
•
JTAC policies—For a complete understanding of our JTAC procedures and policies,
review the JTAC User Guide located at
JTAC hours of operation—The JTAC centers have resources available 24 hours a day,
7 days a week, 365 days a year.
Self-Help Online Tools and Resources
For quick and easy problem resolution, Juniper Networks has designed an online
self-service portal called the Customer Support Center (CSC) that provides you with the
following features:
Find solutions and answer questions using our Knowledge Base: http://kb.juniper.net/
•
Download the latest versions of software and review release notes:
http://www.juniper.net/customers/csc/software/
•
Search technical bulletins for relevant hardware and software notifications:
http://kb.juniper.net/InfoCenter/
•
Join and participate in the Juniper Networks Community Forum:
http://www.juniper.net/company/communities/
•
Open a case online in the CSC Case Management tool: http://www.juniper.net/cm/
To verify service entitlement by product serialnumber, useour Serial NumberEntitlement
(SNE) Tool: https://tools.juniper.net/SerialNumberEntitlementSearch/
Opening a Case with JTAC
You can open a case with JTAC on the Web or by telephone.
•
Use the Case Management tool in the CSC at http://www.juniper.net/cm/.
•
Call 1-888-314-JTAC (1-888-314-5822 toll-free in the USA, Canada, and Mexico).
SRX100 Services Gateway Features and Functions on page 4
SRX100 Services Gateway Description
This topic includes the following sections:
•
About the SRX100 Services Gateway on page 3
•
SRX100 Services Gateway Models on page 3
•
Accessing the SRX100 Services Gateway on page 4
About the SRX100 Services Gateway
The Juniper Networks SRX100 Services Gateway offers features that provide complete
functionality and flexibility for delivering secure Internet and intranetaccess.The services
gateway offers stable, reliable, and efficient IP routing in addition to switching support
and LAN connectivity. The device provides IP Security (IPsec), virtual private network
(VPN), and firewall services for small and medium-sized companies and enterprise
branch and remote offices. The SRX100 Services Gateway can be connected directly to
traditional private networks such as leased lines, Frame Relay, or Multi Protocol Label
Switching (MPLS) or to the public Internet.
The SRX100 Services Gateway runs the Junos operating system (Junos OS).
SRX100 Services Gateway Models
The following are the two models of the SRX100 Services Gateway available with 1 GB
memory.For information onthe models with2 GBmemory, see SRX100ServicesGateway
SRX100 Services Gateway Hardware Guide for B and H Model Numbers
NOTE: You can upgrade from an SRX100 Services Gateway Low Memory
version to a High Memory version through a license key. You need not order
a separate High Memory device.
NOTE: SRX100H model providesadditional security featuressuchas Unified
Threat Management (UTM), which consists of IPS antispam, antivirus, and
Web filtering.
NOTE: The SRX100 Services Gateway High Memory model ships with a
license key.
All SRX100 Services Gateways run the Junos OS.
Accessing the SRX100 Services Gateway
Two user interfaces are available for monitoring, configuring, troubleshooting, and
managing the SRX100 Services Gateway:
•
J-Web interface: Web-based graphical interface that allows you to operate a services
gateway without commands. The J-Web interface provides access to all Junos OS
functionality and features.
•
Junos OS command-line interface (CLI): Juniper Networks command shell that runs
on top ofa UNIX-based operating system kernel. The CLIis astraightforward command
interface. On a single line, you type commands that are executed when you press the
Enter key. The CLI provides command Help and command completion.
Related
Documentation
SRX100 Services Gateway Specifications on page 24•
• SRX100 Services Gateway Features and Functions on page 4
• Upgrading the SRX100 Services Gateway Low Memory Version to a High Memory
Version on page 90
SRX100 Services Gateway Features and Functions
The SRX100 Services Gateway is a security optimized, fixed processing system that
provides the following features for the Low Memory and High Memory models listed in
Table 4 on page5. Forinformation on the models with2 GBmemory,see SRX100Services
Table 4: SRX100 Services Gateway Hardware Features
Chapter 1: System Overview
SRX100 Services Gateway
Low MemoryFeatures
DDR Memory
High Memory through a license
key)
SRX100 Services Gateway
High Memory
1 GB512 MB (software upgradable to
30 watts30 wattsPower supply adapter
100 to 240 VAC100 to 240 VACAC input voltage
88Fast Ethernet ports
11Console port
11USB port
44LEDs
1 GB1 GBNAND flash
For more details on Junos OS features and licenses for the SRX100 Services Gateway,
see the Junos OS Administration Guide for Security Devices.
For more information on upgrading an SRX100 Services Gateway Low Memory to High
Memory, see “Upgrading the SRX100 Services Gateway Low Memory Version to a High
Memory Version” on page 90.
Related
Documentation
• SRX100 Services Gateway Description on page 3
• SRX100 Services Gateway Specifications on page 24
• Upgrading the SRX100 Services Gateway Low Memory Version to a High Memory
Table 5: SRX100 Services Gateway Front Panel LEDs (continued)
UsageDescriptionComponentNumber
HA LED3
The HA LED has the
following indicator
colors:
The HA LED can be
used to determine if
chassis clustering is
enabled on thedevice.
•
Solid green
indicates that all
chassis clustering
links are available.
•
Solid red indicates
that the chassis
clustering links are
not working as
expected.
•
Solid amber
indicatesthatsome
chassis clustering
links are not
working as
expected.
•
Off indicates that
chassis clustering is
not enabled.
Status LED4
The Status LED has
the following indicator
colors:
The Status LED can
be used to determine
whether the device is
starting up, is
•
Solid green
indicates that the
functioning normally,
or has failed.
device is
functioning
normally.
•
Solid amber
indicates that the
device is starting
up.
•
Solid red indicates
that an error is
detected in the
device.
SRX100 Services Gateway Ethernet Port LEDs
On the SRX100 Services Gateway, each Fast Ethernet port has one functional LED on
the left side that indicates Link and Activity. In Figure 2 on page 10, this LED is marked as
SRX100 Services Gateway Hardware Guide for B and H Model Numbers
Figure 2: SRX100 Services Gateway Ethernet Port LEDs
The Table 6 on page 10 applies only to the TX/RX/LINK LEDmarked 1. Table 6on page 10
describes the states of this LED.
Table 6: SRX100 Services Gateway Built-In Ethernet Port LEDs
DescriptionStateColorFunction
Related
Documentation
BlinkingGreenTX/RX/LINK
Steady
Link is active. Data
communication is taking
place.
Link is active. No data
communication is taking
place.
Link is inactive.OffUnlit
NOTE: The LED marked as 2 in Figure 2 on page 10 is not functional in this
release.
SRX100 Services Gateway Specifications on page 24•
• SRX100 Services Gateway Front Panel and Back Panel Views on page 13
• SRX100 Services Gateway Built-In Interfaces on page 15
• SRX100 Services GatewayBoot Devices and Dual-Root Partitioning Scheme onpage11
• SRX100 Services Gateway Power Supply on page 10
SRX100 Services Gateway Power Supply
The power supply for the SRX100 Services Gateway is external. You must use the power
supply adapter provided by Juniper Networks to provide power to the services gateway.
Related
Documentation
SRX100 Services Gateway Specifications on page 24•
• SRX100 Services Gateway Front Panel and Back Panel Views on page 13
• SRX100 Services Gateway LEDs on page 7
• SRX100 Services Gateway Built-In Interfaces on page 15
• SRX100 Services GatewayBoot Devices and Dual-Root Partitioning Scheme onpage11
• Monitoring the SRX100 Services Gateway Power System on page 101
• SRX100 Services Gateway Electrical and Power Requirements on page 30
SRX100 Services Gateway Boot Devices and Dual-Root Partitioning Scheme
This topic includes the following sections:
•
Boot Devices on page 11
•
Dual-Root Partitioning Scheme on page 11
Boot Devices
The SRX100 Services Gateway can boot from the following storage media (in the order
of priority):
•
Internal NAND Flash (default; always present)
•
USB storage key (alternate)
Dual-Root Partitioning Scheme
Dual-root partitions allow the SRX100 Services Gateways to remain functional if there
is file system corruption and facilitate easy recovery of the corrupted file system.
The dual-root partitioning scheme keeps the primary and backup Junos OS images in
two independently bootable root partitions. If the primary root partition becomes
corrupted, the system will be able to boot from the backup Junos OS image located in
the other root partition and remain fully functional.
When the SRX100 Services Gateway powers up, it tries to boot the Junos OS from the
default storage media. If the device fails to boot from the default storage media, it tries
to boot from the alternate storage media. With the dual-root partitioning scheme, the
SRX100 Services Gateway first tries to boot the Junos OS from the primary root partition
and then from the backup root partition on the default storage media. If both primary
and backup root partitions of a media fail to boot, then the device tries to boot from the
next available type of storage media. The SRX100 Services Gateway remains fully
functional even if it boots the Junos OS from the backup root partition of storage media.
The SRX100 Services Gateways that are running Junos OS Release 9.6 or earlier use the
single-root partitioning scheme.Whileupgrading these devicesto Junos OSRelease 10.0,
you can choose to format the storage media with dual-root partitions (strongly
recommended) or retain the existing single-root partitioning.
NOTE: SRX Series devices that ship from the factory with Junos OS Release
10.0 are formatted with the dual-root partitioning scheme.
For instructions on upgrading to Junos OS Release 10.0, see the following topics: