Page 3 - Contents
NetScreen-200 Series iii Contents Preface...............................................................................................................................................v Guide Organization ..................................................................................................
Page 4 - Appendix A
C o n t e n t s iv User’s Guide Establishing a Terminal Emulator Connection................................................ 22Changing Your Admin Name and Password ................................................. 23Setting Port and Interface IP Addresses ...............................................
Page 5 - Preface; UIDE
NetScreen-200 Series v Preface The Juniper Networks NetScreen-200 Series consists of versatile, purpose-built, high-performance security systems that provide IPSec VPN and firewall services for medium and large enterprise offices, e-business sites, data centers, and carrier infrastructures. The NetS...
Page 7 - Overview
NetScreen-200 Series 1 1 Chapter 1 Overview This chapter provides detailed descriptions of the NetScreen-200 Series system devices and their components. Topics in this chapter include: • “NetScreen-200 Systems” on page 2 – “NetScreen-204 Device” on page 2 – “NetScreen-208 Device” on page 2 • “The Fr...
Page 8 - CREEN
C h a p t e r 1 O v e r v i e w 2 User’s Guide N ET S CREEN -200 S YSTEMS This NetScreen-200 Series currently includes the NetScreen-204 device and the NetScreen-208 device. NetScreen-204 Device The NetScreen-204 is a chassis-based, rack-mountable network security device with four ethernet 10/100 Ba...
Page 9 - RONT; System Status LED Display
T h e F r o n t P a n e l NetScreen-200 Series 3 T HE F RONT P ANEL The features shared in common by NetScreen-204 and NetScreen-208 devices include: • A System Status LED display • An Asset Recovery Pinhole • A Console port • A Modem port • A Compact Flash Card Slot • Ethernet interfaces System Sta...
Page 10 - Asset Recovery Pinhole
C h a p t e r 1 O v e r v i e w 4 User’s Guide Asset Recovery Pinhole The Asset Recovery Pinhole is a button that resets the device to its original default settings. To use this button, insert a stiff wire (such as a straightened paper clip) into the pinhole. Alarm System Alarm red Critical alarm: •...
Page 11 - Console and Modem Ports
T h e F r o n t P a n e l NetScreen-200 Series 5 Console and Modem Ports The Console port is an RJ-45 serial console port connector, for vt100 terminal emulator programs to perform local configuration and administration. The Modem port is an RJ-45 serial console port connector, for establishing remo...
Page 12 - Ethernet Interfaces; EAR; Power Supplies
C h a p t e r 1 O v e r v i e w 6 User’s Guide Ethernet Interfaces Each Ethernet port is a 10/100 auto-sensing interface with two link LEDs. The left LED indicates network traffic, and the right LED indicates an active network link. T HE R EAR P ANEL The figure below shows the rear panel of a NetScr...
Page 13 - Power Fuse
T h e R e a r P a n e l NetScreen-200 Series 7 Power Fuse Each NetScreen-200 Series device uses a 2.5 Amp, slow-blow power fuse rated for 250 Volts. To replace a fuse on a NetScreen-200 Series device: 1. Take the device off-line by turning the power switch OFF and disconnecting the power cable. 2. U...
Page 15 - Installing the Device
NetScreen-200 Series 9 2 Chapter 2 Installing the Device This chapter describes how to install a device in an equipment rack or on a desktop, and how to connect the device to other devices. Topics in this chapter include: • “General Installation Guidelines” on page 10 • “Performing Equipment-Rack In...
Page 16 - Equipment Rack Installation Guidelines
C h a p t e r 2 I n s t a l l i n g t h e D e v i c e 10 User’s Guide G ENERAL I NSTALLATION G UIDELINES Observing the following precautions can prevent injuries, equipment failures and shutdowns. • Never assume that the power supply is disconnected from a power source. Always check first. • Room te...
Page 17 - Front Mount; ONNECTING
C o n n e c t i n g t h e P o w e r NetScreen-200 Series 11 There are two ways to rack-mount the NetScreen-200 Series: • Front mount • Mid-mount Front Mount To front mount the NetScreen-200 Series device on your equipment rack: 1. Screw the front mount bracket to the side of the chassis. 2. Screw th...
Page 18 - IRING; DC P; OWER
C h a p t e r 2 I n s t a l l i n g t h e D e v i c e 12 User’s Guide W IRING A DC P OWER S UPPLY The DC power supply, ON/OFF switch, grounding screw, and terminal blocks, are located in the back of the chassis of the power supply unit. To connect the DC power supply to a grounding point at your sit...
Page 21 - Configuring the Device
NetScreen-200 Series 15 3 Chapter 3 Configuring the Device This chapter describes how to perform initial configuration on a NetScreen-200 Series device once you have mounted it in a rack or desktop, plugged in the necessary cables, then turn the power ON. Topics in this chapter include: • “Operation...
Page 22 - PERATIONAL; Transparent Mode
C h a p t e r 3 C o n f i g u r i n g t h e D e v i c e 16 User’s Guide O PERATIONAL M ODES The NetScreen-200 Series device supports two device modes: Transparent mode and Route mode. The default mode is Route. Transparent Mode In Transparent mode, the NetScreen-200 device operates as a Layer-2 brid...
Page 24 - Connectivity Examples
C h a p t e r 3 C o n f i g u r i n g t h e D e v i c e 18 User’s Guide C ONNECTING THE D EVICE AS A S INGLE S ECURITY G ATEWAY There are many ways to connect a NetScreen-200 Series device to your network system. In most cases, the device serves as a single security gateway that protects at least on...
Page 25 - Performing Device Connection
C o n n e c t i n g t h e D e v i c e a s a S i n g l e S e c u r i t y G a t e w a y NetScreen-200 Series 19 In the following example, a NetScreen-208 device connects to a protected LAN through ethernet1 (bound to the Trust security zone) and to a protected DMZ through ethernet2 (bound to the DMZ s...
Page 26 - STABLISHING; HA C; ONNECTION; Device 1
C h a p t e r 3 C o n f i g u r i n g t h e D e v i c e 20 User’s Guide E STABLISHING AN HA C ONNECTION B ETWEEN D EVICES To assure continuous traffic flow in the event of system failure, you can cable and configure two NetScreen devices in a redundant cluster. The devices propagate all network, con...
Page 28 - Switches; ERFORMING; Establishing a Terminal Emulator Connection
C h a p t e r 3 C o n f i g u r i n g t h e D e v i c e 22 User’s Guide Switches 11. Cable together the switches labeled “Switch 3” and “Switch 4.”12. Cable together the switches labeled “Layer 3 switch 1” and “Layer 3 switch 2.”13. Cable the switches labeled “Layer 3 switch 1” and “Layer 3 switch 2...
Page 29 - Changing Your Admin Name and Password; Setting Port and Interface IP Addresses; Viewing Current Interface Settings
P e r f o r m i n g I n i t i a l C o n n e c t i o n a n d C o n f i g u r a t i o n NetScreen-200 Series 23 6. At the password prompt, type netscreen . 7. (Optional) By default, the console times out and terminates automatically after 10 minutes of idle time. To change this timeout interval, execu...
Page 30 - Setting the IP Address of the Management Interface; Setting the IP Address for the Untrust Zone Interface
C h a p t e r 3 C o n f i g u r i n g t h e D e v i c e 24 User’s Guide Setting the IP Address of the Management Interface To make an interface work as the management interface, you must set the IP address and subnet mask to the same address range as your computer (or LAN). Use the CLI save command ...
Page 31 - UI S; Starting a Console Session Using Telnet
C o n f i g u r i n g t h e D e v i c e f o r T e l n e t a n d W e b U I S e s s i o n s NetScreen-200 Series 25 Allowing Outbound Traffic By default, the NetScreen-200 Series device does not allow inbound or outbound traffic, nor does it allow traffic to or from the DMZ. To permit (or deny) traffi...
Page 32 - Starting a Console Session Using Dialup
C h a p t e r 3 C o n f i g u r i n g t h e D e v i c e 26 User’s Guide 5. (Optional) By default, the console times out and terminates automatically after 10 minutes of idle time. To change this timeout interval, execute the following command: set console timeout number where number is the length of...
Page 34 - SSET; Using CLI Commands to Reset the Device
C h a p t e r 3 C o n f i g u r i n g t h e D e v i c e 28 User’s Guide A SSET R ECOVERY If you lose the admin password, you can use one of the following procedures to reset the NetScreen device to its default settings. This destroys any existing configurations, but restores access to the device. Us...
Page 35 - Using the Asset Recovery Pinhole to Reset the Device
A s s e t R e c o v e r y NetScreen-200 Series 29 Using the Asset Recovery Pinhole to Reset the Device You can also reset the device and restore the factory default settings by pressing the asset recovery pinhole. To perform this operation, you need to make a console connection, as described in “Est...
Page 37 - Specifications
NetScreen-200 Series A-I A Appendix A Specifications This appendix provides general system specifications for the NetScreen-200 Series devices. • “NetScreen-200 Attributes” on page A-II • “Electrical Specification” on page A-II • “Environmental” on page A-II • “Safety Certifications” on page A-II • ...
Page 38 - NEBS C
A p p e n d i x A S p e c i f i c a t i o n s A-II User’s Guide N ET S CREEN -200 A TTRIBUTES Height:1.73 inches (4.4 cm) Depth:10.8 inches (27.4 cm) Width:17.5 inches (44.5 cm) Weight: 8 pounds (36 hg) E LECTRICAL S PECIFICATION AC voltage:100-240 VAC +/- 10% DC voltage:-36 to -60 VDC AC Watts:45 W...
Page 39 - Index
I n d e x NetScreen-200 Series IX-I Index A asset recovery 28 B back panel 6 C cables connections 19 power 19 RJ-45 connectors 17 RJ45 connectors 5 , 13 twisted pair 13 , 17 cabling network interfaces 25 power supply 21 changing login and password 23 changing timeout 23 , 26 compact flash card slot ...