SRX650 Services Gateway Quick Start
Use the instructions in this quick start to help you connect the SRX650 Services
Gateway to your network. For details, see the SRX650 Services Gateway Hardware
Guide at http://
www.juniper.net/techpubs/hardware/junos-srx/srx650/index.html.
SRX650 Services Gateway Front Panel
SRX650 Services Gateway Back Panel
Connecting and Configuring the SRX Series Device
Use the instructions below to connect and set up the SRX650 Services Gateway to
protect your network. Refer to the LEDs on the front and back panels of the device to
help you determine the status of the device.
Task 1: Overview
The SRX650 Services Gateway is a security device that requires these basic
configuration settings to function:
n Interfaces must be assigned IP addresses.
n Interfaces must be bound to zones.
n All interfaces must be configured as Layer 3 interfaces.
n Policies must be configured between zones to permit or deny traffic.
n Source NAT rules must be set.
The device has the following default configuration set when you power it on for the first
time
. To be able to use the device, you do not need to perform any initial configuration.
Factory-Default Settings:
Factory-Default Settings for Security Policies:
Factory-Default Settings for NAT Rule:
Callout Description Callout Description
1 Mounting brackets 7 GPIM/XPIM slots
2 ALARM LED 8 POWER LED
3 FAN LED 9 HA SYS LED
4 SRE/ACE LED 1.0 10 SRE/ACE LED 0 (applies to Services and
Routing Engine models only)
5 ESD outlet 11 SRE/ACE LED 1.1
6 10/100/1000 Ethernet ports 12 Power button
650
Callout Description Callout Description
1 Power supply slots 7 SRE LEDs
2 Multi-use processing slot 8 AUX port
3 SRE slot 0 (shown with Services and
Routing Engine model installed)
9 Console port
4 Fan tray 10 External CompactFlash slot
5 Air filter (behind fan tray) 11 2 USB ports
6 Reset Config button
Interface Security Zone DHCP State IP Address
ge-0/0/0 Untrust Client Dynamically assigned
ge-0/0/1 Trust Server 192.168.1.1/24
ge-0/0/2 Trust Server 192.168.2.1/24
ge-0/0/3 Trust Server 192.168.3.1/24
Source Zone Destination Zone Policy Action
timrePtsurtnUtsurT
Source Zone Destination Zone Policy Action
tsurtnUtsurT
Source NAT to untrust zone interface