Juniper Networks, Inc.
1194 North Mathilda Avenue
Sunnyvale, California 94089
USA
408-745-2000
www.juniper.net
Juniper Networks, Junos, Steel-Belted Radius, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United
States and other countries. The Juniper Networks Logo, the Junos logo, and JunosE are trademarks of Juniper Networks, Inc. All other
trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners.
Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify,
transfer, or otherwise revise this publication without notice.
The information in this document is current as of the date on the title page.
SOFTWARE LICENSE
The terms and conditions for using this software are described in the software license contained in the acknowledgment to your purchase
order or, to the extent applicable, to any reseller agreement or end-user purchase agreement executed between you and Juniper Networks.
By using this software, you indicate that you understand and agree to be bound by those terms and conditions.
Generally speaking, the software license restricts the manner in which you are permitted to use the software and may contain prohibitions
against certain uses. The software license may state conditions under which the license is automatically terminated. You should consult
the license for further details.
For complete product documentation, please see the Juniper Networks Web site at www.juniper.net/techpubs.
END USER LICENSE AGREEMENT
The Juniper Networks product that is the subject of this technical documentation consists of (or is intended for use with) Juniper Networks
software. Use of such software is subject to the terms and conditions of the End User License Agreement (“EULA”) posted at
http://www.juniper.net/support/eula.html. By downloading, installing or using such software, you agree to the terms and conditions of
SRX Series Documentation and Release Notes on page xi
•
Obtaining Documentation on page xi
•
Documentation Feedback on page xii
•
Requesting Technical Support on page xii
Objectives
This guide describes hardware components and installation, basic configuration, and
basic troubleshooting procedures for the Juniper Networks SRX240 Services Gateway.
It explains how to prepare your site for services gateway installation, unpack and install
the hardware, power on the services gateway, perform initial software configuration, and
perform routine maintenance. After completing the installation and basic configuration
procedures covered in this guide, see the Junos OS configuration guides for information
about further Junos OS configuration.
Audience
This guide is designed for network administrators who are installing and maintaining a
Juniper Networks SRX240 Services Gateway or preparing a site for device installation.
To use this guide,you needa broad understandingofnetworks ingeneral and the Internet
in particular, networking principles, and network configuration. Any detailed discussion
of these concepts is beyond the scope of this guide.
Documentation Conventions
Table 1 on page x defines the notice icons used in this guide.
Table 2 on page x defines the text and syntax conventions used in this guide.
DescriptionMeaningIcon
Indicates important features or instructions.Informational note
Indicates a situation that might result in loss of data or hardware damage.Caution
Alerts you to the risk of personal injury or death.Warning
Alerts you to the risk of personal injury from a laser.Laser warning
Table 2: Text and Syntax Conventions
Represents text that you type.Bold text like this
Fixed-width text like this
Italic text like this
Italic text like this
Text like this
Represents output that appears on the
terminal screen.
•
Introduces or emphasizes important
new terms.
•
Identifies guide names.
•
Identifies RFC and Internetdraft titles.
Represents variables (options for which
you substitute a value) in commands or
configuration statements.
Represents names of configuration
statements, commands, files, and
directories;configurationhierarchy levels;
or labels on routing platform
components.
ExamplesDescriptionConvention
To enter configuration mode, type the
configure command:
user@host> configure
user@host> show chassis alarms
No alarms currently active
•
A policy term is a named structure
that defines match conditions and
actions.
•
Junos OS CLI User Guide
•
RFC 1997, BGP Communities Attribute
Configure the machine’s domain name:
[edit]
root@# set system domain-name
domain-name
•
To configure a stub area, include the
stub statement at the [edit protocols
ospf area area-id] hierarchy level.
•
The console portis labeled CONSOLE.
stub <default-metric metric>;Enclose optional keywords or variables.< > (angle brackets)
Indicates a choice between the mutually
exclusivekeywords orvariables on either
side of the symbol. The set of choices is
often enclosed in parentheses for clarity.
same lineas theconfigurationstatement
to which it applies.
Enclose a variable for which you can
substitute one or more values.
Identify a level in the configuration
hierarchy.
Identifies a leaf statement at a
configuration hierarchy level.
Representsgraphical user interface (GUI)
items you click or select.
broadcast | multicast
(string1 | string2 | string3)
rsvp { # Required for dynamic MPLS onlyIndicates a comment specified on the
community name members [
community-ids ]
[edit]
routing-options {
static {
route default {
nexthop address;
retain;
}
}
}
•
In the Logical Interfaces box, select
All Interfaces.
•
To cancel the configuration, click
Cancel.
> (bold right angle bracket)
Separates levels in a hierarchy of menu
selections.
SRX Series Documentation and Release Notes
For a list of related SRX Series documentation, see
If the information in the latest SRX Series Release Notes differs from the information in
the documentation, follow the SRX Series Release Notes.
Obtaining Documentation
To obtain the most current version of all Juniper Networks technical documentation, see
the products documentation page on the Juniper Networks website at
http://www.juniper.net/techpubs.
To order printed copies of this guide and other Juniper Networks technical documents,
contact your sales representative.
In the configuration editor hierarchy,
select Protocols>Ospf.
Copies of the Management Information Bases (MIBs) available in a software release are
included on the documentation CDs and at http://www.juniper.net.
Documentation Feedback
We encourage you to provide feedback, comments, and suggestions so that we can
improve the documentation. You can send your comments to
techpubs-comments@junper.net, or fill out the documentation feedback form at
http://www.juniper.net/techpubs/docbug/docbugreport.html. If you are using e-mail, be
sure to include the following information with your comments:
•
Document Name
•
Document part number
•
Page number
•
Software release version (not required for Network Operations Guides [NOGs])
Requesting Technical Support
Technical product support is availablethrough theJuniper Networks Technical Assistance
Center (JTAC). If you are a customer with an active J-Care or JNASC support contract,
or are covered under warranty, and need postsales technical support, you can access
our tools and resources online or open a case with JTAC.
•
JTAC policies—For a complete understanding of our JTAC procedures and policies,
review the JTAC User Guide located at
JTAC Hours of Operation —The JTAC centers have resources available 24 hours a day,
7 days a week, 365 days a year.
Self-Help Online Tools and Resources
For quick and easy problem resolution, Juniper Networks has designed an online
self-service portal called the Customer Support Center (CSC) that provides you with the
following features:
Join and participate in the Juniper Networks Community Forum:
http://www.juniper.net/company/communities/
•
Open a case online in the CSC Case Management tool: http://www.juniper.net/cm/
To verify service entitlement byproduct serial number,use ourSerial Number Entitlement
(SNE) Tool: https://tools.juniper.net/SerialNumberEntitlementSearch/
Opening a Case with JTAC
You can open a case with JTAC on the Web or by telephone.
•
Use the Case Management tool in the CSC at http://www.juniper.net/cm/.
•
Call 1-888-314-JTAC (1-888-314-5822 toll-free in the USA, Canada, and Mexico).
For international or direct-dial options in countries without toll-free numbers, visit us at
SRX240 Services Gateway Hardware Features on page 5
SRX240 Services Gateway Description
The Juniper Networks SRX240 Services Gateway offers complete functionality and
flexibility for delivering secure, reliable data over IP, and provides multiple interfaces that
support WAN and LAN connectivity and Power over Ethernet (PoE).
The SRX240 ServicesGatewayprovides IP Security(IPsec), virtualprivate network (VPN),
and firewall services for small and medium-sized companies and enterprise branch and
remote offices. Additional security features include Unified Threat Management (UTM),
which consists of IPS antispam, antivirus, and Web filtering.
The SRX240 Services Gatewayruns the Juniper Networks Junos operatingsystem (Junos
OS).
The SRX240 Services Gateway has a modular 1U chassis that fits a 19-inch rack with a
depth of approximately 17.5 in. (44.5 cm).
Figure 1 on page 3 shows the SRX240 Services Gateway.
Table 4: SRX240 Services Gateway Hardware Features (continued)
Internal flash
Air filters
SRX240 Services
Gateway with AC
Power Supply and
No PoE SupportFeatures
•
For SRX240B:
1 GB
•
For SRX240B2:
2 GB
•
For SRX240H:
1 GB
•
For SRX240H2:
2 GB
•
For SRX240H-TAA:
1 GB
•
For
SRX240H2-TAA:
2 GB
(Separately
orderable)
SRX240 Services
Gateway with AC
Power Supply and
PoE Support
•
For SRX240H-POE:
1 GB
•
For
SRX240H2-POE:
2 GB
•
For
SRX240H-POE-TAA:
1 GB
•
For
SRX240H2-POE-TAA:
2 GB
SRX240 Services
Gateway with DC
Power Supply
•
For SRX240H-DC:
1 GB
•
For SRX240H2-DC:
2 GB
666Fans
OneNoneOne
Related
Documentation
YesNoNoNEBS-compliant
NOTE: An air filter is not shipped with the SRX240 Services Gateway with
AC power supply models. To meet NEBS requirements, you must order the
air filter separately and install it. Contact your Juniper Networks customer
service representative for more information.
For moredetails about the chassisspecification, see “SRX240 Services Gateway Chassis”
Table 5: Physical Specifications for the SRX240 Services
Gateway (continued)
Chassis weight
Average Power
consumption
ValueSpecification
15 in. (38.1 cm)Chassis depth
•
SRX240 Services Gateway with AC power supply and no PoE
support models: 11.24 lb. (5.1 kg)
•
SRX240 Services Gateway with AC power supply and PoE support
models: 12.34 lb. (5.6 kg)
•
SRX240 Services Gateway with DC power supply models: 12.56 lb.
(5.7 kg)
•
SRX240 Services Gateway with AC power supply and no PoE
support models: 74 watts
•
SRX240 Services Gateway with AC power supply and PoE support:
86 watts (excluding PoE load)
•
SRX240 Services Gateway with DC power supply models: 72 watts
Temperature
Seismic
Maximum thermal
output
NOTE: Before removing or installing components of a functioning services
gateway, attach an electrostatic discharge (ESD) strap to an ESD point and
fasten the other end of the strap around your bare wrist. Failure to use an
ESD strap could result in damage to the services gateway.
No performance degradation at upto 10,000 ft (3048 m)Altitude
5% to 90%, noncondensingRelative humidity
Normal operation ensured in temperature range 32°F (0°C) through
104°F (40°C)
Nonoperating storage temperature in shipping container: -40°F
(-40°C) to 158°F (70°C)
Designed to meet Telcordia Technologies Zone 4 earthquake
requirements
•
SRX240 Services Gateway with AC power supply and no PoE
support models: 427 BTU/hour
•
SRX240 Services Gateway with AC power supply and PoE support
models: 560 BTU/hour (Excluding PoE load)
•
SRX240 Services Gateway with DC power supply models: 409
BTU/hour
NOTE: These specifications are estimates and subject to change.
Chapter 2: SRX240 Services Gateway Hardware Components and Specifications
SRX240 Services Gateway Back Panel (AC power supply models)
Figure 4 on page 11 shows the back panel of the SRX240 Services Gateway AC power
supply models.
Figure 4: SRX240 Services Gateway Back Panel ( with AC Power Supply
Models)
Table 7 on page 11 lists the back panel components of the SRX240 Services Gateway
AC power supply models.
Table 7: SRX240 Services Gateway Back Panel AC Power Supply Models
ComponentNumber
Cable tie holder1
Power supply point2
Grounding point3
Air filter slot4
NOTE: The air filter is shipped with SRX240 Services Gateways with DC
power supply models only.
You can order the air filter separately for the SRX240 Services Gateway with
AC power supply models. Contact your Juniper Networks customer service
representative for more information.
SRX240 Services Gateway Back Panel (DC Power Supply Model)
Figure 5on page 11 shows theback panel of an SRX240 Services Gateway with DC power
supply models.
Figure 5: SRX240 Services Gateway DC Power Supply Model
Support a USB storage device that
functions as a secondary boot device in
case of internal flash failure on startup.
NOTE: To use USB to boot your services
gateway, you must install and configure the
USB storage device on the USB port to use
it as a secondary boot device. Additionally,
the USB storage device must have Junos
OS installed.
•
Provide the USB interfaces that are used
to communicate with the various types
of Juniper Networks-supported USB
storage devices.
Contact a customer service
representative for more information.
•
Functions as a management port using
which you can log in to the services
gateway directly.
•
Provides the interface to configure the
services gateway using the CLI.
Provide LAN and WAN functionality along
with connectivity to various media types.
For more information about Mini-PIMs, see
the SRX Series Services Gateways for
the Branch Physical Interface Modules
Hardware Guide.
Related
Documentation
SRX240 Services Gateway Chassis on page 7•
• SRX240 Services Gateway Front Panel and Back Panel Views on page 9
• SRX240 Services Gateway Cooling System on page 21
NOTE: We strongly recommend that only transceivers provided by Juniper
Networks be used on an SRX240 Services Gateway. We cannot guarantee
that the interface module will operate correctly if third-party transceivers
are used. Please contact Juniper Networks for the correct transceiver part
number for your device.