background image

Copyright Notice

Copyright © 2005 Juniper Networks, Inc. All rights reserved.
Juniper Networks, the Juniper Networks logo, NetScreen, NetScreen Technologies, GigaScreen, and the NetScreen logo 

are registered trademarks of Juniper Networks, Inc. NetScreen-5GT, NetScreen-5XP, NetScreen-5XT, NetScreen-25, 

NetScreen-50, NetScreen-100, NetScreen-204, NetScreen-208, NetScreen-500, NetScreen-5200, NetScreen-5400, 

NetScreen-Global PRO, NetScreen-Global PRO Express, NetScreen-Remote Security Client, NetScreen-Remote VPN 

Client, NetScreen-IDP 10, NetScreen-IDP 100, NetScreen-IDP 500, GigaScreen ASIC, GigaScreen-II ASIC, and 

NetScreen ScreenOS are trademarks of Juniper Networks, Inc. All other trademarks and registered trademarks are the 

property of their respective companies.
Information in this document is subject to change without notice.
No part of this document may be reproduced or transmitted in any form or by any means, electronic or mechanical, for any 

purpose, without receiving written permission from: 
Juniper Networks, Inc.

ATTN:  General Counsel

1194 N. Mathilda Ave.

Sunnyvale, CA 94089-1206

FCC Statement

The following information is for FCC compliance of Class A devices: This equipment has been tested and found to comply 

with the limits for a Class A digital device, pursuant to part 15 of the FCC rules. These limits are designed to provide 

reasonable protection against harmful interference when the equipment is operated in a commercial environment. The 

equipment generates, uses, and can radiate radio-frequency energy and, if not installed and used in accordance with the 

instruction manual, may cause harmful interference to radio communications. Operation of this equipment in a 

residential area is likely to cause harmful interference, in which case users will be required to correct the interference at 

their own expense.
The following information is for FCC compliance of Class B devices: The equipment described in this manual generates 

and may radiate radio-frequency energy. If it is not installed in accordance with NetScreen’s installation instructions, it 

may cause interference with radio and television reception. This equipment has been tested and found to comply with the 

limits for a Class B digital device in accordance with the specifications in part 15 of the FCC rules. These specifications are 

designed to provide reasonable protection against such interference in a residential installation. However, there is no 

guarantee that interference will not occur in a particular installation.
If this equipment does cause harmful interference to radio or television reception, which can be determined by turning the 

equipment off and on, the user is encouraged to try to correct the interference by one or more of the following measures:

•   Reorient or relocate the receiving antenna.
•   Increase the separation between the equipment and receiver.
•   Consult the dealer or an experienced radio/TV technician for help.
•   Connect the equipment to an outlet on a circuit different from that to which the receiver is connected.

Caution: Changes or modifications to this product could void the user's warranty and authority to operate this device.

Disclaimer

THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH 

IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY 

THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, 

CONTACT YOUR JUNIPER NETWORKS REPRESENTATIVE FOR A COPY.

Summary of Contents for NETSCREEN-5XT

Page 1: ...NETSCREEN 5XT User s Guide Version 5 0 093 1323 000 Rev B...

Page 2: ...cations Operation of this equipment in a residential area is likely to cause harmful interference in which case users will be required to correct the interference at their own expense The following in...

Page 3: ...ice to Your Internal Network Workstations or Other Devices 7 Chapter 3 Configuring the Device 9 Operational Modes 10 Transparent Mode 10 Route Mode 10 The NetScreen 5XT Interfaces 11 Establishing a Co...

Page 4: ...Contents iv User s Guide Connectors A II Index IX I...

Page 5: ...talling the Device details how to install the NetScreen 5XT on a desktop connect the power and connect the device to your network Chapter 3 Configuring the Device details how to establish a Console se...

Page 6: ...port case using the Case Manager link at http www juniper net support or call 1 888 314 JTAC within the United States or 1 408 745 9500 outside the United States If you find any errors or omissions in...

Page 7: ...nectors on page 2 Status LEDs on page 3 Note For safety warnings and instructions please refer to the NetScreen Safety Guide The instructions in this guide warn you about situations that could cause b...

Page 8: ...LED on the faceplate glows solid green When power fails the power LED turns off Port Description ConnectorType Speed Protocol Console Enables a serial connection to establish terminal sessions with th...

Page 9: ...ntrusted ports LED Name Purpose Status Meaning Power Power Status green Power is functioning correctly off The device is not receiving power Status System Status amber The module is starting up blinki...

Page 10: ...Chapter 1 Overview 4 User s Guide...

Page 11: ...w to install a NetScreen 5XT on a desktop connect the power and connect the NetScreen 5XT to your network Topics explained in this chapter include Desktop Installation Guidelines on page 6 Connecting...

Page 12: ...not work alone if potentially hazardous conditions exist Look carefully for possible hazards in your work area such as moist floors ungrounded power extension cables frayed power cords and missing saf...

Page 13: ...erface on the NetScreen 5XT to the external router or modem Connecting the Device to Your Internal Network Workstations or Other Devices The Trusted interface on the NetScreen 5XT consists of four RJ...

Page 14: ...Chapter 2 Installing the Device 8 User s Guide...

Page 15: ...duct at www juniper net support so that certain NetScreen ScreenOS services such as the Deep Inspection Signature Service can be activated on the device After registering your product use the WebUI or...

Page 16: ...o configured security policies Route Mode In Route mode the NetScreen 5XT operates at Layer 3 Because you can configure each interface using an IP address and subnet mask you can configure individual...

Page 17: ...ault Trusted1 Trusted4 Bound to the Trust security zone by default Connect this interface using a twisted pair cable with RJ 45 connectors Untrusted Bound to the Untrust security zone by default Conne...

Page 18: ...a console session with your NetScreen 5XT are as follows Baud Rate to 9600 Parity to No Data Bits to 8 Stop Bit to 1 Flow Control to none 4 At the login prompt type netscreen 5 At the password prompt...

Page 19: ...o set the IP address and subnet mask of the NetScreen 5XT to 10 100 2 183 and 16 respectively set interface trust ip 10 100 2 183 16 3 To confirm the new settings execute the following command get int...

Page 20: ...olicy wizard allows you to configure rules that tell your NetScreen 5XT the services and computers that users on outside computers the Untrust zone are allowed to access on your network the Trust zone...

Page 21: ...your last chance to cancel this command If you proceed the device will return to factory default configuration which is System IP 192 168 1 1 username netscreen password netscreen Would you like to co...

Page 22: ...mber for one half second then returns to the blinking green state Continue to press the button until the message Configuration Erase sequence accepted unit reset The system generates SNMP and SYSLOG a...

Page 23: ...ix provides general system specifications for the NetScreen 5XT NetScreen 5XT Attributes on page A II Electrical Specification on page A II Environmental on page A II Safety Certifications on page A I...

Page 24: ...is 12 000 ft 0 3 660 m SAFETY CERTIFICATIONS UL CUL CSA CE CB Austel EMI CERTIFICATIONS FCC Part 15 class B VCCI C Tick BSMI CE CONNECTORS The RJ 45 twisted pair ports are compatible with the IEEE 80...

Page 25: ...G guide organization v I IP address system 13 L LED 3 link status LED 3 login changing 12 N NetScreen publications vi NetScreen 5XT connecting to a LAN or workstation 7 connecting to a router or mode...

Page 26: ...Index IX II User s Guide...

Reviews: