Juniper Networks, Junos, Steel-Belted Radius, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United
States and other countries. The Juniper Networks Logo, the Junos logo, and JunosE are trademarks of Juniper Networks, Inc. All other
trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners.
Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify,
transfer, or otherwise revise this publication without notice.
Products made or sold by Juniper Networks or components thereof might be covered by one or more of the following patents that are
owned by or licensed to Juniper Networks: U.S. Patent Nos. 5,473,599, 5,905,725, 5,909,440, 6,192,051, 6,333,650, 6,359,479, 6,406,312,
6,429,706, 6,459,579, 6,493,347, 6,538,518, 6,538,899, 6,552,918, 6,567,902, 6,578,186, and 6,590,785.
The information in this document is current as of the date on the title page.
SOFTWARE LICENSE
The terms and conditions for using this software are described in the software license contained in the acknowledgment to your purchase
order or, to the extent applicable, to any reseller agreement or end-user purchase agreement executed between you and Juniper Networks.
By using this software, you indicate that you understand and agree to be bound by those terms and conditions.
Generally speaking, the software license restricts the manner in which you are permitted to use the software and may contain prohibitions
against certain uses. The software license may state conditions under which the license is automatically terminated. You should consult
the license for further details.
For complete product documentation, please see the Juniper Networks Web site at www.juniper.net/techpubs.
END USER LICENSE AGREEMENT
The Juniper Networks product that is the subject of this technical documentation consists of (or is intended for use with) Juniper Networks
software. Use of such software is subject to the terms and conditions of the End User License Agreement (“EULA”) posted at
SRX Series Documentation and Release Notes on page xiii
•
Obtaining Documentation on page xiii
•
Documentation Feedback on page xiv
•
Requesting Technical Support on page xiv
Objectives
This guide describes hardware components and installation, basic configuration, and
basic troubleshooting procedures for the Juniper Networks SRX210 Services Gateway.
It explains how to prepare your site for services gateway installation, unpack and install
the hardware, power on the services gateway, perform initial software configuration, and
perform routine maintenance. After completing the installation and basic configuration
procedures covered in this guide, see the Junos OS configuration guides for information
about further Junos OS configuration.
Audience
This guide is designed for network administrators who are installing and maintaining a
Juniper Networks SRX210 Services Gateway or preparing a site for device installation.
To use this guide, youneed a broad understandingof networks in general andthe Internet
in particular, networking principles, and network configuration. Any detailed discussion
of these concepts is beyond the scope of this guide.
Documentation Conventions
Table 1 on page xii defines the notice icons used in this guide.
Table 2 on page xii defines the text and syntax conventions used in this guide.
DescriptionMeaningIcon
Indicates important features or instructions.Informational note
Indicates a situation that might result in loss of data or hardware damage.Caution
Alerts you to the risk of personal injury or death.Warning
Alerts you to the risk of personal injury from a laser.Laser warning
Table 2: Text and Syntax Conventions
Represents text that you type.Bold text like this
Fixed-width text like this
Italic text like this
Italic text like this
Text like this
Represents output that appears on the
terminal screen.
•
Introduces or emphasizes important
new terms.
•
Identifies book names.
•
Identifies RFC and Internet draft titles.
Represents variables (options for which
you substitute a value) in commands or
configuration statements.
Represents names of configuration
statements, commands, files, and
directories;configurationhierarchy levels;
or labels on routing platform
components.
ExamplesDescriptionConvention
To enter configuration mode, type
theconfigure command:
user@host> configure
user@host> show chassis alarms
No alarms currently active
•
A policy term is a named structure
that defines match conditions and
actions.
•
Junos OS SystemBasics Configuration
Guide
•
RFC 1997, BGP Communities Attribute
Configure the machine’s domain name:
[edit]
root@# set system domain-name
domain-name
•
To configure a stub area, include the
stub statement at the[edit protocols
ospf area area-id] hierarchy level.
•
The console portis labeled CONSOLE.
stub <default-metric metric>;Enclose optional keywords or variables.< > (angle brackets)
Indicates a choice betweenthe mutually
exclusivekeywords or variables on either
side of the symbol. The set of choices is
often enclosed in parentheses for clarity.
same lineas theconfiguration statement
to which it applies.
Enclose a variable for which you can
substitute one or more values.
Identify a level in the configuration
hierarchy.
Identifies a leaf statement at a
configuration hierarchy level.
Representsgraphical user interface (GUI)
items you click or select.
broadcast | multicast
(string1 | string2 | string3)
rsvp { # Required for dynamic MPLS onlyIndicates a comment specified on the
community name members [
community-ids ]
[edit]
routing-options {
static {
route default {
nexthop address;
retain;
}
}
}
•
In the Logical Interfaces box, select
All Interfaces.
•
To cancel the configuration, click
Cancel.
> (bold right angle bracket)
Separates levels in a hierarchy of menu
selections.
SRX Series Documentation and Release Notes
For a list of related SRX Series documentation, see
If the information in the latest SRX Series Release Notes differs from the information in
the documentation, follow the SRX Series Release Notes.
Obtaining Documentation
To obtain the most current version of all Juniper Networks technical documentation, see
the products documentation page on the Juniper Networks web site at
http://www.juniper.net/techpubs.
To order printed copies of this guide and other Juniper Networks technical documents,
or to order a documentation CD, which contains this guide, contact your sales
representative.
In the configuration editor hierarchy,
select Protocols>Ospf.
Copies of the Management Information Bases (MIBs) available in a software release are
included on the documentation CDs and at http://www.juniper.net/.
Documentation Feedback
We encourage you to provide feedback, comments, and suggestions so that we can
improve the documentation. You can send your comments to
techpubs-comments@juniper.net, or fill out the documentation feedback form at
http://www.juniper.net/techpubs/docbug/docbugreport.html. If you are using e-mail, be
sure to include the following information with your comments:
•
Document name
•
Document part number
•
Page number
•
Software release version (not required for Network Operations Guides [NOGs])
Requesting Technical Support
Technical product support is available through the Juniper NetworksTechnical Assistance
Center (JTAC). If you are a customer with an active J-Care or JNASC support contract,
or are covered under warranty, and need postsales technical support, you can access
our tools and resources online or open a case with JTAC.
•
JTAC policies- For a complete understanding of our JTAC procedures and policies,
review the JTAC User Guide located at
Product warranties- For product warranty information, visit
http://www.juniper.net/support/warranty/.
•
JTAC Hours of Operation- The JTAC centers have resources available 24 hours a day,
7 days a week, 365 days a year.
Self-Help Online Tools and Resources
For quick and easy problem resolution, Juniper Networks has designed an online
self-service portal called the Customer Support Center (CSC) that provides you with the
following features:
Join and participate in the Juniper Networks Community Forum:
http://www.juniper.net/company/communities/
•
Open a case online in the CSC Case Manager: http://www.juniper.net/cm/
To verify service entitlement byproduct serial number, useour SerialNumber Entitlement
(SNE) tool located at https://tools.juniper.net/SerialNumberEntitlementSearch/.
Opening a Case with JTAC
You can open a case with JTAC on the Web or by telephone.
•
Use the Case Manager tool in the CSC at http://www.juniper.net/cm/.
•
Call 1-888-314-JTAC (1-888-314-5822 toll-free in the USA, Canada, and Mexico).
For international or direct-dial options in countries without toll-free numbers, visit us at
SRX210 Services Gateway Hardware Features on page 4
SRX210 Services Gateway Description
This topic includes the following sections:
•
About the SRX210 Services Gateway on page 3
•
SRX210 Services Gateway Models on page 3
•
Accessing the SRX210 Services Gateway on page 4
About the SRX210 Services Gateway
The Juniper Networks SRX210 Services Gateway offers complete functionality and
flexibility for delivering secure and reliable data, along with multiple interfaces that
support WAN and LAN connectivity and Power over Ethernet (PoE).
The SRX210 Services Gateway provides Internet Protocol Security (IPsec), virtual private
network (VPN), and firewall services for small and medium-sized companies and
enterprise branch and remote offices. Additional security features also include Unified
ThreatManagement (UTM), which consists ofIPS antispam, antivirus, and Web filtering.
The SRX210 Services Gateway runs the Junos operating system (Junos OS).
SRX210 Services Gateway Models
The SRX210 Services Gateway is available in six models, which are listed in
All SRX210 Services Gateways run the Junos operating system (Junos OS).
Accessing the SRX210 Services Gateway
Two user interfaces are available for monitoring, configuring, troubleshooting, and
managing the SRX210 Services Gateway:
•
J-Web interface: Web-based graphical interface that allows you to operate a services
gateway without commands. The J-Web interface provides access to all Junos
functionality and features.
SRX210HEHigh Memory (Enhanced)SRX210 Services Gateway High
SRX210HE-TAAHigh Memory (Enhanced + TAA
Compliant)
SRX210HE-POEHigh Memory with Power over
Ethernet (Enhanced + PoE)
SRX210HE-POE-TAAHigh Memory with PoE
(Enhanced + TAA Compliant)
•
Junos OS command-line interface (CLI): Juniper Networks command shell that runs
on top of a UNIX-basedoperating system kernel. The CLI is a straightforward command
interface. On a single line, you type commands that are executed when you press the
Enter key. The CLI provides command Help and command completion.
Related
Documentation
SRX210 Services Gateway Specifications on page 7•
• SRX210 Services Gateway Hardware Features on page 4
SRX210 Services Gateway Hardware Features
Table 4 on page 5 lists the hardware features supported on the SRX210 Services
No performance degradation up to 10,000 ft (3048
m) for SRX210 Services Gateway Low Memory, High
Memory, and PoE models
5% to 90%, noncondensingRelative humidity
Normal operation ensured in temperature range of
32°F (0°C) to 104°F (+40°C)
Nonoperating storage temperature in shipping
container: –40°F (–40°C) to 158°F (70°C)
Maximum thermal output
CAUTION: Before removingor installingcomponents ofa functioning services
gateway, attach an electrostatic discharge (ESD) strap to an ESD point and
place the other end of the strap around your bare wrist. Failure to use an ESD
strap could result in damage to the services gateway.
NOTE: These specificationsare estimatesand subject
Chapter 2: SRX210 Services Gateway Hardware Components and Specifications
Related
Documentation
SRX210 Services Gateway Description on page 3•
• SRX210 Services Gateway Front Panel and Back Panel Views (Low Memory, High
Memory, and PoE Versions) on page 9
• Monitoring the SRX210 Services Gateway Components Using LEDs on page 103
• SRX210 Services Gateway Electrical Safety Guidelines and Warnings on page 132
SRX210 Services Gateway Front Panel and Back Panel Views (Low Memory, High
Memory, and PoE Versions)
This topic contains views of the front panel and back panel of the SRX210 Services
Gateway high memory, low memory, and Power over Ethernet (PoE) versions. This topic
includes the following sections:
•
SRX210 Services Gateway Front Panel on page 9
•
SRX210 Services Gateway Back Panel on page 10
SRX210 Services Gateway Front Panel
Figure 2 on page 9 shows the front panel of the SRX210 Services Gateway.
Figure 2: SRX210 Services Gateway Front Panel
Table 6 on page 9 lists the front panel components of the services gateway.
NOTE: The numbers in Figure 2 on page 9 correspond to the numbers in
Table 6 on page 9.
Table 6: SRX210 Services Gateway Front Panel Components
Are labeled as port 0/2 to
port 0/7 on the front panel
•
Provide link speeds of
10/100 Mbps
•
Operate in full-duplex and
half-duplex modes
The first two Fast Ethernet
ports support Power over
Ethernet on the SRX210
Services Gateway (PoE
version).
•
Consist of two ports
•
Function in full speed and
high speed
•
Are compliant with USB
revision 2.0
The Fast Ethernet ports can
be used as follows:
•
To provide LAN connectivity
to hubs, switches, local
servers, and workstations
•
To forward incoming data
packets to the device
•
To receive outgoing data
packets from the device
•
To connect power devices
to receive network
connectivity and electric
power (PoE functionality)
(For the PoE model of the
SRX210 Services Gateway)
The USB ports can be used as
follows:
•
To support a USB storage
device that functions as a
secondary boot device in
case of the internal flash
failureon startup,if theUSB
storage device is installed
and configured
NOTE: You must install and
configure the USB storage
device on the USB port to use
it as secondary boot device.
Also, the USB device must
have Junos installed.
•
To provide the USB
interfaces that are used to
communicate with many
types of Juniper supported
USB storage devices.
Contactyour JuniperNetworks
customer service
representative for more
information.
NOTE: We strongly recommend that only transceivers provided by Juniper
Networks be used on an SRX210 Services Gateway. We cannot guarantee
that the interface module will operate correctly if third-party transceivers
are used. Contact Juniper Networks for the correct transceiver part number
for your device.
•
Consists of one port
•
Uses an RJ-45 serial cable
connector
•
Supports the RS-232
(EIA-232) standard
Consists of one slot for a
Mini-PIM
The console port can be used
as follows:
•
To provide the console
interface
•
To function as a
management port to log
into a device directly
•
To configure the device
using the CLI
The Mini-PIM slot can beused
to provide LAN and WAN
functionality along with
connectivity to various media
types.
For more information about
the supported Mini-PIMs, see
the SRX Series Services
Gateways for the Branch
Physical Interface Modules
Hardware Guide.
Related
Documentation
SRX210 Services Gateway Front Panel and Back Panel Views (Low Memory, High
•
Memory, and PoE Versions) on page 9
• SRX210 Services Gateway LEDs on page 13
• SRX210 ServicesGateway BootDevices and Dual-RootPartitioningScheme onpage 17
• SRX210 Services Gateway Cooling System on page 18