Juniper Networks 5000 SERIES manual Transparent Mode, Route Mode, Operational Modes

Page 30

Chapter 3 Configuring the Device

OPERATIONAL MODES

A NetScreen-5000 Series device supports two operational modes: Transparent and Route. The default mode is Route.

Transparent Mode

In Transparent mode, a NetScreen-5000 Series device operates as a Layer-2 bridge. Because the device cannot translate packet IP addresses, it cannot perform Network Address Translation (NAT). Consequently, for the device to access the Internet, any IP address in your trusted (local) networks must be routable and accessible from untrusted (external) networks.

In Transparent mode, the IP addresses for the Layer-2 Trust and Untrust zones are 0.0.0.0, thus making the NetScreen-5000 Series device invisible to the network. However, the device can still perform firewall, VPN, and traffic management according to configured security policies.

Route Mode

In Route mode, a NetScreen-5000 Series device operates at Layer 3. Because you can configure each interface using an IP address and subnet mask, you can configure individual interfaces to perform NAT.

When the interface performs NAT services, the NetScreen-5000 Series device translates the source IP address of each outgoing packet into the IP address of the untrusted interface. It also replaces the source port number with a randomly-generated value.

When the interface does not perform NAT services, the source IP address and port number in each packet header remain unchanged. Therefore, to reach the Internet your local hosts must have routable IP addresses.

For more information on NAT, see the NetScreen Concepts & Examples ScreenOS Reference Guide.

22

User’s Guide

Image 30
Contents NETSCREEN-5000 Series Copyright Notice Language Contents Language Contents Table of Contents Servicing the Device Index Table of Contents Viii Preface Guide OrganizationCommand Line Interface CLI Conventions Set admin user name1 password xyzJuniper Networks Netscreen Publications Overview1 NetScreen-5200 NetScreen-5400NETSCREEN-5000 Series Power Supplies NetScreen-5200 Power Recommendations NetScreen-5400 Power RecommendationsDC Power Supply AC Power Supply FAN ModulesManagement Modules NETSCREEN-5000 Modules5000-M Management Module 5000-M2 Management Module NetScreen-5000 ModulesSecure Port Modules 5000-8G SPM5000-2G24FE SPM Overview User’s Guide Installing the Device General Installation Guidelines Equipment Rack Installation GuidelinesNetScreen-5200 Front and Rear Mount Mounting the NETSCREEN-5000 SeriesNetScreen-5200 Mid-Mount NetScreen-5400 Front MountInstalling and Connecting the AC Power Supply Installing and Wiring a DC Power Supply48V COMThumbscrew Power Connecting the NETSCREEN-5000 Series to a Router or Switch Establishing AN HA ConnectionInstalling the Device User’s Guide Configuring the Device Transparent Mode Route ModeOperational Modes NetScreen-5200 Interfaces NETSCREEN-5000 InterfacesConfigurable Interfaces NetScreen-5400 InterfacesPerforming Initial Connection and Configuration Establishing a Terminal Emulator ConnectionUpgrading the Firmware During the Boot Process Viewing Current Interface Settings Changing Your Admin Name and PasswordSetting Port and Interface IP Addresses Setting the IP Address of the Management InterfaceSetting the IP Address for the Trust Zone Interface Setting the IP Address for the Untrust Zone InterfaceStarting a Console Session Using Telnet Configuring the Device for Telnet and Webui SessionsAllowing Outbound Traffic Starting a Console Session Using Dialup Establishing a GUI Management SessionTelnet Configuring the Chassis Alarm Http//10.100.2.183Get chassis Configuring Aggregate Interfaces Set interface string zone zonenameGet interface Get interface aggregate1 Using CLI Commands to Reset the Device Following CLI command unset admin device-resetPress the y key Following message appears Servicing the Device Replacing a DC Power Supply Removing and Reseating ModulesReplacing AN AC Power Supply Replacing the FAN TrayConnecting and Disconnecting Gigabit Ethernet Cables Removing and Installing a MINI-GBIC Transceiver Servicing the Device User’s Guide Specifications NETSCREEN-5200 Attributes Electrical SpecificationEnvironmental Specification NETSCREEN-5400 AttributesNebs Certifications Safety CertificationsConnectors EMI CertificationsAppendix a Specifications User’s Guide Port Descriptions and LED Status B Module Port Descriptions MGTInterpreting Status LEDs for the Management Modules Module LED DescriptionsStatus LED States Interpreting Status LEDs for the Secure Port Module Interpreting Ethernet Port Status LEDs for All ModulesPower Supply Leds Interpreting Power Supply LED Status for the NetScreen-5200Interpreting Power Supply LED Status for the NetScreen-5400 Single SPM InstalledFAN LED Index User’s Guide Table des matières Chapitre Entretien de l’unité Index 103 Table des matières Xii Manuel de l’utilisateur Préface Organisation DU ManuelSet admin user nom1 password xyz Publications Juniper Networks NetscreenPrésentation générale Unité NetScreen-5200 Unité NetScreen-5400Série DE Produits NETSCREEN-5000 Blocs D’ALIMENTATION Bloc d’alimentation CC DELBloc d’alimentation CA Modules DE VentilationModules de gestion Modules NETSCREEN-5000Module de gestion 5000-M Module de gestion 5000-M2 Modules NetScreen-5000Modules de ports sécurisés SPM 5000-8GSPM 5000-2G24FE Chapitre 1 Présentation générale Manuel de l’utilisateur Installation de l’unité Instructions D’INSTALLATION Générales Instructions D’INSTALLATION DE LA Baie DE ÉquipementMontage avant et arrière de l’unité NetScreen-5200 Montage DE L’UNITÉ DE LA Série NETSCREEN-5000Montage à mi-hauteur de l’unité NetScreen-5200 Montage frontal de l’unité NetScreen-5400Installation ET Connexion DU Bloc Dalimentation CA Installation ET Raccordement D’UN Bloc ’ALIMENTATION CDCOM Établissement D’UNE Connexion HA Chapitre 2 Installation de l’unité Manuel de l’utilisateur Configuration de l’unité Mode Transparent Mode RouteModes DE Fonctionnement Interfaces NetScreen-5200 Interfaces NETSCREEN-5000Interfaces configurables Interfaces NetScreen-5400Exécution DE LA Connexion ET DE LA Configuration Initiales Établissement d’une connexion d’émulateur de terminalChapitre 3 Configuration de l’unité Affichage des paramètres d’interface actuels Configuration des adresses IP de port et d’interfaceConfiguration de l’adresse IP de l’interface de gestion Set interface mgt ip adrip/masqueGet interface mgt Set interface ethernet2/2 ip adrip/masqueGet interface ethernet2/2 Démarrage d’une session de console à l’aide de Telnet Autorisation du trafic sortantSet interface ethernet2/3 ip adrip/masque Telnet Configuration DE L’ALARME DE Châssis Configuration D’INTERFACES Agrégées Set interface chaîne zone nomdelazoneSérie de produits NetScreen-5000 Appuyez sur la touche y Le message suivant s’affiche Entretien de l’unité Retrait ET Réinstallation DES Modules Remplacement D’UN Bloc D’ALIMENTATION CCRemplacement D’UN Bloc D’ALIMENTATION CA Remplacement DU Bloc DE VentilationConnexion ET Déconnexion DES Câbles Gigabit Ethernet Retrait ET Installation D’UN Transmetteur MINI-GBIC Chapitre 4 Entretien de l’unité Manuel de l’utilisateur SpécificationsA Spécifications Électriques Attributs DE L’UNITÉ NETSCREEN-5200Attributs DE L’UNITÉ NETSCREEN-5400 Spécifications EnvironnementalesCertifications EMI Certifications NebsCertifications DE Conformité ConnecteursAnnexe a Spécifications Manuel de l’utilisateur Série de produits NetScreen-5000 Description DES Ports DES Modules Interprétation des DEL d’état des modules de gestion Description DES DEL DES ModulesEtats DES DEL D’ÉTAT Interprétation des DEL d’état des modules de ports sécurisés Un seul SPM installé DEL DES Blocs D’ALIMENTATIONDEL DE Ventilation FAN Nombres 104 Manuel de l’utilisateur