SRX简明操作手册 by Panda.docx
《SRX简明操作手册 by Panda.docx》由会员分享,可在线阅读,更多相关《SRX简明操作手册 by Panda.docx(41页珍藏版)》请在淘文阁 - 分享文档赚钱的网站上搜索。
1、目录1. SRX Introduction22. JUNOS Basic OP I83. JUNOS Basic OP II164. Security Policy I185. Security Policy II216. Routing I257. NAT288. IPSecVPN I309. IPSecVPN II341. SRX Introduction=熊猫说:SRX笔记是基于“明教教主”的笔记进行再次整理和“网上的教材”自学时所做笔记进行修改而成。原先的笔记中有些错误和配置缺陷,再经过测试和修改已经将笔记中的95%的命令和状态都已经验证过。SRX笔记可以满足基本的路由配置,接口配置,
2、策略配置,VPN配置,NAT配置等。如果使用者喜欢用GUI配置的话,可以根据本手册进行界面反推。=推荐书籍-Junos Security传统ScreenOS迁移到Junos:1.ScreenOS不能从内核分离运行的任务,所有进程相同优先级SCreenOS任何一个部分崩溃,整个OS也面临崩溃2.Junos模块化的架构更容易添加新功能*Junos源自于FreeBSD系统SRX配置方式:1.CLI2.J-WebBrach SRX Series:SRX Shared Features + SRX Branch FeaturesSRX Branch Features包括-Antivirus-Antosp
3、am-URL Filtering-有限的IPS-Dynamic VPN Client-3G&Wifi-MPLS-支持多种WAN interface/Data Center只支持以太网License for Branch SRX Series-Antivirus Juniper-Kaspersky 1/3/5yrs update-Antispam Juniper-Sphos 1/3/5yrs update-Intrusion protection Juniepr 1/3/5yrs update-Web fiiltering Websense 1/3/5yrs update-Combined se
4、t 以上四合一 1/3/5yrs update-Dyanamic VPN client 5/10/25/50 users-BGP router reflector 作为路由器反射器的能力-AX411 access point 支持外挂一个专用瘦AP-CX111 3G modem 支持外挂一个专用3G适配器SRX100(基本版本512MB/高级版1G内存)内置其实是1G内存,但是要买License激活基本版是无法执行Combined包含的功能的基本版要做防病毒需要先买高级版License,然后再买Antivirus LicenseSRX200(基本版本512MB/高级版1G内存)就像SSG5与S
5、SG20的区别,性能都一样,但是可以支持广域网模块SRX600(性能比SRX100/200高出很多个档次)Data Center SRX Series:SRX Shared Features + SRX Data Center FeaturesSRX Data Center Features包括(高端产品稳定,性能好,但是功能少)-Transparent mode-强大功能的IPS-AppDoSSRX3000 20G吞吐量SRX5600 已经完胜ASA吞吐量SRX5800 IPS吞吐量已经超过ASA最高级别型号的普通吞吐量SRX的主要配置内容:System:系统级内容和配置,例如主机名,管理账
6、号,权限,时钟时区,syslog,SNMP,系统开放的远程管理服务等。Interface:接口配置内容Security:是SRX防火墙的主要配置内容,安全相关内容,如NAT,ZONE,POLICY,Address-Book等。Application:自定义服务单独配置Routing-Options:配置路由或者动态路由等以下是出厂值的配置,可以看到模块分类:root# run show configuration # Last commit: 2014-04-28 06:33:38 UTC by rootversion 10.2R3.10;system root-authentication
7、encrypted-password $1$sJwj3W9D$Gkiyjtau5Bn7oUXKtfPhK1; # SECRET-DATA name-server 208.67.222.222; 208.67.220.220; services ssh; telnet; xnm-clear-text; web-management http interface vlan.0; https system-generated-certificate; interface vlan.0; dhcp router 192.168.1.1; pool 192.168.1.0/24 address-rang
8、e low 192.168.1.2 high 192.168.1.254; propagate-settings fe-0/0/0.0; syslog archive size 100k files 3; user * any emergency; file messages any critical; authorization info; file interactive-commands interactive-commands error; max-configurations-on-flash 5; max-configuration-rollbacks 5; license aut
9、oupdate url interfaces fe-0/0/0 unit 0; fe-0/0/1 unit 0 family ethernet-switching vlan members vlan-trust; fe-0/0/2 unit 0 family ethernet-switching vlan members vlan-trust; fe-0/0/3 unit 0 family ethernet-switching vlan members vlan-trust; fe-0/0/4 unit 0 family ethernet-switching vlan members vlan
10、-trust; fe-0/0/5 unit 0 family ethernet-switching vlan members vlan-trust; fe-0/0/6 unit 0 family ethernet-switching vlan members vlan-trust; fe-0/0/7 unit 0 family ethernet-switching vlan members vlan-trust; vlan unit 0 family inet address 192.168.1.1/24; protocols stp;security nat source rule-set
11、trust-to-untrust from zone trust; to zone untrust; rule source-nat-rule match source-address 0.0.0.0/0; then source-nat interface; screen ids-option untrust-screen icmp ping-death; ip source-route-option; tear-drop; tcp syn-flood alarm-threshold 1024; attack-threshold 200; source-threshold 1024; des
12、tination-threshold 2048; timeout 20; land; zones security-zone trust host-inbound-traffic system-services all; protocols all; interfaces vlan.0; security-zone untrust screen untrust-screen; interfaces fe-0/0/0.0 host-inbound-traffic system-services dhcp; tftp; policies from-zone trust to-zone untrus
13、t policy trust-to-untrust match source-address any; destination-address any; application any; then permit; vlans vlan-trust vlan-id 3; l3-interface vlan.0; edit2. JUNOS Basic OP I模式类型默认账户root,默认密码为空,root账户只能用于Console配置,TELNET和WEB时无法使用此账户。刚进入时显示为:root%cli 刚进入时候提示符是%,还处于linux底层,cli即调用命令行程序提示符为操作模式,即ex
14、ec模式 configure Entering configuration modeeditshow configure 查看配置,在操作模式下,可以直接show注意:如果是用于配制导入的show,必须要用: show configuration | display set 这样才能看到set命令,保存为TXT后才能导入配制。/类似于CISCO的#/#类似于CISCO的(config)#/下show interface类似于CISCO的show interface/#下show interfacce类似于CISCO的show run interface如果要在root#下进行show,要输入“
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- SRX简明操作手册 by Panda SRX 简明 操作手册
限制150内