I-JUNIPER NETWORKS SRX345 Services Gateway Network User Guide
Services Gateway Network

Ukuqala Ngokushesha

Isinyathelo 1: Qala 

N LESI ISIGABA
Hlangana ne-SRX345 | 2
Faka i-SRX345 kuRakhi | 2
Vula | 4

Kulo mhlahlandlela, sinikeza indlela elula, enezinyathelo ezintathu, ukuze usheshe usebenze nge-SRX345 yakho entsha. Senze kwaba lula futhi safinyeza izinyathelo zokufaka nokumisa, futhi safaka namavidiyo enziwa kanjani. Uzofunda ukuthi uyifaka kanjani i-SRX345 endaweni yokubeka, uyinike amandla, futhi uyihambise kunethiwekhi yakho usebenzisa i-CLI.

QAPHELA: Sicabanga ukuthi uzofuna ukuhlola Ukusethwa kwethu Okuqondisiwe: I-SRX300 Line Firewalls. Ukusethwa Kwethu Okuqondisiwe kuqala lapho lolu suku Lokuqala+ luphela khona, lunikeza imiyalelo yesinyathelo nesinyathelo sendlela yokuvikela nokuqinisekisa kalula indawo yegatsha lakho.

Ingabe unentshisekelo yokuthola ulwazi oluthe xaxa ngezihloko nokusebenza okukhulunywa ngakho kulo mhlahlandlela? Vakashela iJuniper Networks Virtual Labs futhi ubeke ibhokisi lakho lesihlabathi lamahhala namuhla! Uzothola i-sandbox ye-Junes Day One Experience esigabeni sokuma sodwa.

Hlangana ne-SRX345
I-Juniper Networks® SRX345 Firewall ihlanganisa ngokuvikelekile ukuphepha, umzila, ukushintsha, kanye nokuxhumeka kwe-WAN ku-chassis ehlangene engu-1-U. Isekela kufikela ku-5-Gbps firewall throughput kanye ne-800-Mbps IPsec VPN ukuze kuhlangatshezwane nezidingo ze-midsize, izindawo zamabhizinisi asabalalisiwe. Kanye neJuniper Sky™ Enterprise kanye ne-Contrail Service Orchestration® (CSO), i-SRX345 iletha i-SD-WAN ezenzakalelayo ngokugcwele kukho kokubili amabhizinisi nabahlinzeki besevisi. Isici se-zero-touch provisioning (ZTP) senza lula ukuxhumeka kwenethiwekhi yegatsha ukuze kusetshenziswe ekuqaleni kanye nokuphathwa okuqhubekayo.

I-SRX345 inamachweba ayisishiyagalombili ayi-1 Gbe RJ-45, amachweba ayisishiyagalombili ayi-1 Gbe SFP, ichweba elilodwa lokuphatha, ichweba elilodwa lekhonsoli, kanye nezikhala ezine zeMini-Physical Interface Module (Mini-PIM). Amachweba we-RJ-45 kanye ne-SFP ayakwazi ukwenza. Amamodeli we-SRX345 AC angaba nokunikezwa kwamandla okukodwa kwe-AC noma okuphakelayo kwamandla we-AC okukabili. Amamodeli e-SRX345 DC anomthombo wamandla owodwa. Lo mhlahlandlela uhlanganisa amamodeli e-SRX345 AC.
Hlangana no-SR

Faka i-SRX345 kuRakhi 

KULESI SIGABA
Yini eseBhokisini? | 2
Yini Okunye Engiyidingayo? | 2
Yidla | 3

Yini eseBhokisini? 

  • I-Firewall ye-SRX345
  • Intambo yamandla efanele indawo okuyo
  • Ikhebula le-USB
  • Abakaki ababili abakhwezwayo
  • Izikulufu eziyisishiyagalombili zokukhweza zokunamathisela abakaki abakhwezayo ku-SRX345

Yini Okunye Engiyidingayo?
Uzodinga futhi:

  • Umuntu ozokusiza ukuthi ufake
  • Izikulufu zokubeka i-rack ezifanele irack yakho
  • Inombolo yesibili ye-Phillips (+) screwdriver
  • Ikhebula le-DB-9 kuye ku-RJ-45 noma i-adaptha engu-DB-9 kuye ku-RJ-45 enentambo yethusi ye-CAT5E—Asisafaki ikhebula le-DB-9 kuye ku-RJ-45 noma i-adaptha engu-DB-9 kuye ku-RJ-45 ene-CAT5E ikhebula lethusi njengengxenye yephakheji yedivayisi. Uma udinga ikhebula lekhonsoli, ungayi-oda ngokuhlukene ngengxenye yenombolo ethi JNP-CBL-RJ45-DB9 (i-adaptha ye-DB-9 kuye ku-RJ-45 enentambo yethusi ye-CAT5E).

I-Rack It

Nansi indlela yokufaka i-SRX345 endaweni yokubeka:

  1. Review Izinkombandlela Zokuphepha Ezijwayelekile Nezixwayiso.
  2. Goqa futhi ubophe umkhawulo owodwa webhande lesisekelo le-electrostatic discharge (ESD) esihlakaleni sakho esingenalutho, bese uxhuma enye indawo endaweni ye-ESD.
  3. Namathisela amabakaki akhwezayo ezinhlangothini ze-SRX345 usebenzisa izikulufu eziyisishiyagalombili zokukhweza kanye ne-screwdriver. Kuya ngokuthi ungathanda ukuthi i-SRX345 ihlale kanjani endaweni yokubeka, unganamathisela amabakaki akhwezayo ngaphambili noma izimbobo ezifakwa phakathi nendawo.
    I-Rack It
  4. Phakamisa i-SRX345 futhi uyibeke endaweni yokubeka. Layisha imbobo engezansi kubakaki ngamunye ofakwayo ngembobo kusitimela ngasinye sokubeka, uqinisekise ukuthi i-SRX345 isezingeni.
  5. Ngenkathi ubambe i-SRX345 endaweni, faka umuntu wesibili bese uqinisa izikulufu zokubeka irack ukuze uvikele amabakaki akhwezayo endaweni yokubeka. Qiniseka ukuthi uqinisa izikulufu ezimbotsheni ezimbili ezingezansi kuqala bese uqinisa izikulufu ezimbotsheni ezimbili eziphezulu.
    I-Rack It
  6. Hlola ukuthi amabakaki afakayo ohlangothini ngalunye lwerack asezingeni

Vula
Manje njengoba usuyifakile i-SRX345 yakho endaweni yokubeka, usulungele ukuyixhuma emandleni

  1. Namathisela ibhande eliphansi le-electrostatic discharge (ESD) engalweni yakho engenalutho, bese uxhuma enye ingxenye yebhande le-ESD endaweni ye-ESD endaweni yokubeka.
  2. Namathisela intambo yaphansi emhlabathini, bese unamathisela enye indawo endaweni yaphansi kuphaneli eseceleni ye-SRX345.
    Vula
  3. Xhuma intambo yamandla kuphaneli engemuva ye-SRX345.
    Vula
  4. Uma umthombo wamandla we-AC uneswishi yamandla, yivale.
  5. Xhuma enye ingxenye yentambo yamandla kumthombo wamandla we-AC.
  6. Uma umthombo wamandla we-AC uneswishi yamandla, yivule.
  7. Uma usebenzisa i-SRX345 Firewall enamandla kagesi e-AC ekabili, bese uphinda Isinyathelo sesi-3 ukuya ku-Isinyathelo sesi-5 ukuze uthole ugesi wesibili. I-SRX345 iba namandla ngokushesha nje uma uyixhuma emandleni. Lapho ama-PWR nama-STAT LEDs kuphaneli yangaphambili ekhanyiswa ngokuluhlaza okuqinile, i-SRX345 isilungele ukusetshenziswa.
    Vula

Isinyathelo sesi-2: Phezulu bese uyagijima

KULESI SIGABA
Izinketho Zokuhlinzeka Nge-SRX345 | 6
Ukucushwa Kokuqala Ngokusebenzisa i-CLI | 6

Manje njengoba i-SRX345 isivuliwe, asenze ukulungisa okuthile ukuze siyivuse futhi isebenze kunethiwekhi.

QAPHELA: Qiniseka ukuthi ubheka Ukusethwa Okuqondisiwe: I-SRX300 Line Firewalls. Ukusethwa Kwethu Okuqondisiwe kuqala lapho lolu suku Lokuqala+ luphela khona, lunikeza imiyalelo yesinyathelo ngesinyathelo yokuthi ungayivikela kanjani futhi uqinisekise kalula indawo yegatsha lakho.

Izinketho Zokuhlinzeka nge-SRX345
Kulula ukunikeza nokuphatha i-SRX345 namanye amadivaysi kunethiwekhi yakho. Ungakhetha ithuluzi lokumisa elikulungele:

  • Imiyalo kaJuni CLI. Kulo mhlahlandlela sikubonisa ukuthi ungayimisa kanjani i-SRX345 ngemiyalo ye-CLI esebenzisa ipulaki nokudlala okuzenzakalelayo kwasembonini.
  • J-Web, Iwizadi Yokusetha Amanethiwekhi weJuniper efakwe kuqala ku-SRX345. Ukuze uthole ulwazi ngokwenza ukumisa kokuqala usebenzisa i-J-Web isethaphu wizadi bona okuthi Lungiselela Amadivayisi e-SRX Usebenzisa i-J-Web Setha iWizadi ku-J-Web Umhlahlandlela Womsebenzisi wamadivayisi ochungechunge we-SRX.
  • I-Juniper Sky™ Enterprise, i-Juniper Networks-isingethwe i-Software esekwe ngamafu yomphakathi njengesixazululo sesevisi (SaaS). Uzodinga ukuba nesevisi yokubhalisela iJuniper Sky Enterprise ngaphambi kokuthi uyisebenzise ukuze ulungiselele i-SRX345. Ukuze uthole ukwaziswa okwengeziwe, hlola I-Juniper Sky Enterprise Getting Started Guide.
  • IJuniper Networks Contrail Service Orchestration (CSO). Ukuze usebenzise i-CSO, uzodinga ikhodi yokuqinisekisa. Bheka I-Contrail Service Orchestration (CSO ) Umhlahlandlela Wokuthuma

Uma usebenzisa i-Junos OS Release 19.2 noma ngaphambili, ungasebenzisa Isilawuli Sesevisi Yenethiwekhi Yenethiwekhi ukuze ulungiselele i-SRX345 nge-ZTP. Isilawuli Sesevisi Yenethiwekhi siyingxenye ye-CSO. Bheka Lungiselela Idivayisi Usebenzisa i-ZTP ngeJuniper Networks Network Service Controller.

Ukucushwa Kokuqala Ngokusebenzisa i-CL

N LESI ISIGABA
Xhuma Embobeni Yekhonsoli Ye-serial | 7
Yenza Ukucushwa Kokuqala | 8
Siyakuhalalisela! I-SRX Yakho Ivuliwe Futhi Iyasebenza | 9

Ungasebenzisa imbobo yekhonsoli ku-SRX ukwenza ukumisa kokuqala. Lesi sigaba sithatha ukuthi uqala kusukela ekucushweni okuzenzakalelayo kwefekthri. Bona i-SRX345 Firewall Hardware Guide ukuze uthole imininingwane yokucushwa okuzenzakalelayo kwasembonini kwe-SRX345.

Ngemva kokumisa i-SRX345, ungangena embobeni yendawo ye-LAN, noma ukude usebenzisa isixhumi esibonakalayo se-WAN, ukuze uphathe futhi ulungiselele i-SRX usebenzisa i-CLI noma i-J-Web.

Sincoma ukuthi usebenzise isixhumi esibonakalayo se-ge-0/0/0 ekuxhumekeni kwe-WAN ku-SRX345. Ngokuzenzakalelayo, lesi sikhombimsebenzisi sisethelwe ukuthola ukucushwa kokufinyelela ku-inthanethi kumhlinzeki wesevisi.

QAPHELA: Lesi exampLes icabanga ukuthi usebenzisa i-DHCP ukuze ulungiselele isixhumi esibonakalayo se-WAN. Uma umhlinzeki we-WAN engayisekeli i-DHCP, uzodinga ukulungiselela mathupha isixhumi esibonakalayo se-WAN kanye nemizila emile ehlobene. Bheka Ukucushwa Kwasekuqaleni kukaJuni.

Yiba nalolu lwazi ngaphambi kokuthi uqale ukumisa kokuqala:

  • Iphasiwedi yezimpande
  • Igama lomethuleli

Xhuma Kumbobo Yekhonsoli Ye-serial

  1. Xhuma ingxenye eyodwa yekhebula ye-Ethernet ku-adaptha yembobo yochungechunge ye-RJ-45 ukuya ku-DB-9 ye-SRX345 yakho.
    QAPHELA: Asisafaki ikhebuli ye-DB-9 kuye ku-RJ-45 noma i-adaptha ye-DB-9 kuye ku-RJ-45 enekhebula le-CAT5E yethusi njengengxenye yephakheji yedivayisi. Uma udinga ikhebuli yekhonsoli, ungayi-oda ngokuhlukene ngengxenye yenombolo JNP-CBL-RJ45-DB9 (i-adaptha ye-DB-9 kuye ku-RJ-45 enentambo yethusi ye-CAT5E)
  2. Xhuma i-RJ-45 ku-DB-9 i-adaptha yembobo yomkhiqizo embobeni ye-serial kudivayisi yokuphatha.
  3. Xhuma enye ingxenye yekhebula ye-Ethernet embobeni ye-serial console ku-SRX345.
    I-Serial Console Port
  4. Qala uhlelo lwakho lokusebenza lokulingisa ukuphela kwe-asynchronous (njenge-Microsoft Windows HyperTerminal) bese ukhetha imbobo ye-COM efanelekile ozoyisebenzisa (ngokwesibonelo.ample, COM1).
  5. Qinisekisa ukuthi izilungiselelo zembobo ye-serial zisethwe kokumisiwe:
    • Isilinganiso se-Baud - 9600
    • Ukulingana—N
    • Izingcezu zedatha-8
    • Misa izingcezu-1
    • Ukulawula ukugeleza—akekho

QAPHELA: Ungakwazi futhi ukuxhuma ku-SRX345 usebenzisa i-mini-USB console port. Bheka i-SRX345 Hardware Guide.

Yenza Ukucushwa Kokuqala 

  1. Ngena ngemvume njengomsebenzisi wempande bese uqala i-CLI. Awudingi iphasiwedi uma usebenzisa okumisiwe kwasembonini.
    login: impande
    impande@%cli
    impande>
    QAPHELA: Ungakwazi view izilungiselelo zefekthri ezizenzakalelayo ngomyalo wemodi yokusebenza yokucushwa kombukiso.
  2. Faka imodi yokumisa.
    impande> lungiselela
    [hlela] impande#
  3. Njengoba wenza ukumisa kokuqala ngesandla, uzodinga ukususa i-ZTP ekucushweni. Lokhu kumisa imilayezo yelogi ngezikhathi ezithile ebika ngesimo se-ZTP.
    Setha iphasiwedi yokuqinisekisa impande futhi wenze ushintsho ukuze uvale i-ZTP. [hlela] impande# susa i-chassis auto-image-upgrade
    impande# susa isistimu yefoni-ekhaya
    i-root# setha i-root-authentication plain-text-password
    Iphasiwedi entsha: iphasiwedi
    Thayipha kabusha iphasiwedi entsha: iphasiwedi
    Khipha umyalo wokuzibophezela ukuze wenze kusebenze ukucushwa kwekhandidethi okukhubaza i-ZTP:
    [hlela] impande# bophezela
  4. Nika amandla ukungena kwezimpande nge-SSH, futhi uvumele ukufinyelela kwe-SSH ku-WAN interface (ge-0/0/0).
    [hlela] impande# setha izinsiza zesistimu i-sash root-login vumela
    impande# setha izindawo zokuphepha-indawo yokuvikeleka engathembeki ukuxhumana ne-ge-0/0/0.0 i-host-inbound-traffic system-sash yamasevisi
  5. Lungiselela igama lomethuleli.
    [hlela] impande# setha igama lomsingathi wesistimu
  6. Yilokho kuphela! Ukucushwa kokuqala kuqediwe. Zibophezele ukumisa ukuze wenze izinguquko ku-SRX zisebenze.
    [hlela] impande# bophezela

Siyakuhalalisela! I-SRX Yakho Ivuliwe Futhi Iyasebenza

I-SRX345 yakho manje isiku-inthanethi futhi inikeza ukufinyelela kwe-inthanethi okuphephile kumadivayisi anamathiselwe ezimbobeni ze-LAN. Ungaphatha idivayisi endaweni futhi ukude, usebenzisa i-Junos CLI, J-Web, noma isevisi esekelwe emafini. Nansi indlela inethiwekhi yakho ebukeka ngayo:
I-SRX Ivuliwe Futhi Iyasebenza

Izinto ezimbalwa okufanele uzikhumbule mayelana nenethiwekhi yegatsha lakho elisha le-SRX345:

  • Ufinyelela i-SRX CLI noma i-J-Web ukusebenzelana komsebenzisi endaweni kusetshenziswa ikheli elithi 192.168.1.1. Ukuze ufinyelele i-SRX ukude, cacisa ikheli le-IP elinikezwe umhlinzeki we-WAN. Vele ukhiphe kalula izixhumanisi zombukiso ze-ge-0/0/0 terse CLI umyalo ukuze uqinisekise ikheli elisetshenziswa isixhumi esibonakalayo se-WAN.
  • I-interface yokuphatha ilungiselelwe njengeseva ye-DHCP ye-subnet engu-192.168.1.0/24.
  • Amadivayisi anamathiselwe ezimbobeni ze-LAN alungiselelwe ukusebenzisa i-DHCP. Bathola ukucushwa kwenethiwekhi yabo ku-SRX. Lawa madivayisi athola ikheli le-IP kusuka ku-192.168.2.0/24 ikheli pool futhi asebenzise i-SRX njengesango labo elizenzakalelayo.
  • Zonke izimbobo ze-LAN ziku-subnet efanayo enoxhumo lwe-Layer 2. Yonke ithrafikhi ivunyelwe phakathi kwezindawo zokusebenzelana zendawo ethembekile.
  • Yonke ithrafikhi evela endaweni ethembekile ivunyelwe endaweni engathembekile. Ithrafikhi yokuphendula efanayo ivunyelwe ukubuya kusukela kokungathenjwa kuya endaweni yokwethenjwa. Ithrafikhi esuka endaweni engathembekile ivinjiwe endaweni yokwethenjwa.
  • I-SRX yenza umthombo we-NAT (S-NAT) isebenzisa i-IP yesixhumi esibonakalayo se-WAN ngethrafikhi ethunyelwe ku-WAN esuka endaweni yokuthembana.
  • Ithrafikhi ehlotshaniswa namasevisi athile esistimu (i-HTTPS, i-DHCP, i-TFTP, ne-SSH) ivunyelwe ukusuka endaweni engathembekile ukuya kumsingathi wendawo. Zonke izinsiza zokusingatha zendawo kanye nezinqubo ezilandelwayo zivunyelwe kuthrafikhi evela endaweni yokwethenjwa.

Isinyathelo sesi-3: Qhubeka

KULESI SIGABA
Yini Okulandelayo? | 11
Ulwazi Olujwayelekile | 12
Funda Ngamavidiyo | 12

Siyakuhalalisela! I-SRX345 yakho imisiwe futhi ilungele ukuhamba. Nazi ezinye izinto ongazenza ngokulandelayo.

Yini Okulandelayo?

QAPHELA: Ngokushesha lungiselela futhi uqinisekise ihhovisi legatsha elivikelekile ngezinyathelo ezimbalwa ezilula Ngokusethwa kwethu Okuqondisiwe: I-SRX300 Line Firewalls. Ukusethwa kwethu Okuqondisiwe kuqala lapho lo mhlahlandlela we-Day One+ uphela khona futhi uklanyelwe ukuthola indawo yegatsha lakho ngokushesha ku-inthanethi futhi uvikeleke.

Uma ufuna Khona-ke
Shintsha izilungiselelo zokumisa, vula futhi isebenze enye idivayisi, noma kokubili Ngena ngemvume ku-J-Web bese usebenzisa iwizadi. Kungenjalo, ungasebenzisa izici zokumisa ezithuthuke kakhulu ezinikezwa yiJuniper Contrail Service Orchestration (CSO) kanye neJuniper Sky Enterprise. Ukuze usebenzise lezi zinsizakalo, uzodinga i-akhawunti nekhodi yokwenza kusebenze. Hlola I-Contrail Service Orchestration (CSO) Umhlahlandlela Wokuthumela kanye ne Juniper Sky Enterprise Umhlahlandlela Wokuqalisa.
Setha i-SRX345 yakho ngezinyathelo zokuphepha ezithuthukisiwe ukuze uvikele futhi uvikele inethiwekhi yakho Vakashela Usuku Lokuqala: I-SRX Series Up and Running With Advanced Security Amasevisi
Phatha ukuthuthukiswa kwesofthiwe ku-SRX345 yakho Bheka Ifaka Isoftware kumadivayisi e-SRX Series

Ulwazi oluvamile 

Uma ufuna Khona-ke
Landa, wenze kusebenze, futhi uphathe amalayisensi esofthiwe yakho ukuze uvule izici ezengeziwe ze-SRX Firewall yakho Bheka Yenza kusebenze amalayisense e-Junos OS kwe Ijunipha Umhlahlandlela Wokuthola Amalayisense
Bona wonke amadokhumenti atholakalayo e-SRX345 Vakashela i- Imibhalo ye-SRX345 ikhasi kuJuniper TechLibrary
Lungiselela i-SRX345 nge-Junes OS CLI Qala nge Usuku Lokuqala+ lwe-Junos OS umhlahlandlela
Lungiselela i-SRX345 usebenzisa i-J-Web Bheka J-Web ye-SRX Series Documentation
Hlala unolwazi lwakamuva ngezici ezintsha nezishintshile nezinkinga ezaziwayo nezixazululiwe. Bheka Amanothi okukhishwa kwe-Junos OS

Funda Ngamavidiyo

Umtapo wethu wamavidiyo uyaqhubeka nokukhula! Sidale amavidiyo amaningi, amaningi abonisa ukuthi ungayenza kanjani yonke into kusukela ekufakeni ihadiwe yakho ukuze ulungiselele izici ezithuthukisiwe zenethiwekhi ye-Junos OS. Nazi ezinye izinsiza ezinhle zevidiyo nezokuqeqesha ezizokusiza ukuthi wandise ulwazi lwakho lwe-Junos OS.

Uma ufuna Khona-ke
View a Web-Ividiyo yokuqeqeshwa esekwe enikeza ngaphezuluview ye-SRX340 futhi ichaza indlela yokufaka nokuyilungisa I-SRX340 kanye ne-SRX345 Firewalls Overview kanye Nokusatshalaliswa (WBT)
Thola amathiphu amafushane nafushane nemiyalo enikeza izimpendulo ezisheshayo, ukucaca, kanye nokuqonda ezicini ezithile nemisebenzi yobuchwepheshe beJuniper Bheka Ukufunda ngeJuniper ekhasini eliyinhloko le-Juniper Networks le-YouTube
View uhlu lokuqeqeshwa kwamahhala kwezobuchwepheshe esikunikeza eJuniper Vakashela i- Ukuqalisa ikhasi kuJuniper Learning Portal

I-Juniper Networks, ilogo ye-Juniper Networks, iJuniper, kanye noJuni yizimpawu zokuthengisa ezibhalisiwe ze-Juniper Networks, Inc. emazweni aklolodelwayo nakwamanye amazwe. Zonke ezinye izimpawu zokuthengisa, izimpawu zesevisi, amamaki abhalisiwe, noma izimpawu zesevisi ezibhalisiwe ziyimpahla yabanikazi bazo. IJuniper Networks ayinaso isibopho sanoma yikuphi ukungalungi kulo mbhalo. I-Juniper Networks igodla ilungelo lokushintsha, ukulungisa, ukudlulisa, noma ukubuyekeza lokhu kushicilelwa ngaphandle kwesaziso. Copyright © 2023 Juniper Networks, Inc. Wonke amalungelo agodliwe. Rev. 09, Agasti 2023.
Ilogo ye-JUNIPER

Amadokhumenti / Izinsiza

I-JUNIPER NETWORKS SRX345 Services Gateway Network [pdf] Umhlahlandlela Womsebenzisi
I-SRX345 Services Gateway Network, SRX345, Services Gateway Network, Gateway Network, Network

Izithenjwa

Shiya amazwana

Ikheli lakho le-imeyili ngeke lishicilelwe. Izinkambu ezidingekayo zimakiwe *