Juniper SRX300 Quick Start Manual page 10

Hide thumbs Also See for SRX300:
Table of Contents

Advertisement

DHCP Clients
Local Management
Station (Optional)
A few things to keep in mind about your new SRX300 branch network:
You access the SRX CLI or J-Web user interface locally using the 192.168.1.1 address. To access the SRX remotely,
specify the IP address assigned by the WAN provider. Simply issue a show interfaces ge-0/0/0 terse CLI command to
confirm the address in use by the WAN interface.
Devices attached to the LAN ports are configured to use DHCP. They receive their network configuration from the
SRX. These devices obtain an IP address from the 192.168.1.0/24 address pool and use the SRX as their default gateway.
All LAN ports are in the same subnet with Layer 2 connectivity. All traffic is permitted between trust zone interfaces.
All traffic originating in the trust zone is permitted in the untrust zone. Matching response traffic is allowed back from
the untrust to the trust zone. Traffic that originates from the untrust zone is blocked from the trust zone.
The SRX performs source NAT (S-NAT) using the WAN interface's IP for traffic sent to the WAN that originated from
the trust zone.
Traffic associated with specific system services (HTTPS, DHCP, TFTP, and SSH) is permitted from the untrust zone to
the local host. All local host services and protocols are allowed for traffic that originates from the trust zone.
If you'd like to quickly configure and validate a secure branch office, be sure to check out our
Firewalls.
Trust
ge-0/0/1-6
(DHCP Server
SRX300
192.168.1.0/24)
(Factory Default
+ Initial CLI Config)
Untrust
ge-0/0/0
(DHCP Client)
SNAT
Internet
DHCP Server
Remote Management
Station
CSO
Sky Enterprise
Guided Setup: SRX300 Line
10

Advertisement

Table of Contents
loading

Table of Contents