Performing the Initial Software Configuration for the SRX5800
SRX5800 Firewall Software Configuration Overview
The firewall is shipped with the Junos operating system (Junos OS) preinstalled and ready to be configured when the device is powered on. There are three copies of the software: one on a CompactFlash card (if installed) in the Routing Engine, one on the hard disk in the Routing Engine, and one on a USB flash drive that can be inserted into the slot in the Routing Engine faceplate.
When the device boots, it first attempts to start the image on the USB flash drive. If a USB flash drive is not inserted into the Routing Engine or the attempt otherwise fails, the device next tries the CompactFlash card (if installed), and finally the hard disk.
You configure the firewall by issuing Junos OS command-line interface (CLI) commands, either on a console device attached to the CONSOLE port on the Routing Engine, or over a telnet connection to a network connected to the ETHERNET port on the Routing Engine.
Gather the following information before configuring the device:
Name the device will use on the network
Domain name the device will use
IP address and prefix length information for the Ethernet interface
IP address of a default router
IP address of a DNS server
Password for the root user
Initially Configuring the SRX5800 Firewall
This procedure connects the device to the network but does not enable it to forward traffic. For complete information about enabling the device to forward traffic, including examples, see the appropriate Junos OS configuration guides.
To configure the software:
Performing Initial Software Configuration Using J-Web
- Configuring Root Authentication and the Management Interface from the CLI
- Configuring Interfaces, Zones, and Policies with J-Web
Configuring Root Authentication and the Management Interface from the CLI
Before you can use J-Web to configure your device, you must access the CLI to perform the initial configuration.
To configure root authentication and the management interface:
Configuring Interfaces, Zones, and Policies with J-Web
You can configure hostnames, interfaces, zones, and security policies using J-Web.
You cannot use J-Web to configure SRX5400, SRX5600, and SRX5800 Firewalls in Junos OS Release 15.1X49-D10.
Before you begin:
Ensure you have configured the IP address, root authentication, and default route. See Performing Initial Software Configuration Using J-Web
Enable HTTP on the device to access J-Web. See Performing Initial Software Configuration Using J-Web
Configure the device with J-Web using the following procedures.
- Configuring the Hostname
- Configuring Interfaces
- Configuring Zones and Assigning Interfaces
- Configuring Security Policies
Configuring the Hostname
To configure the hostname:
- Launch a Web browser from the management device.
- Enter the IP address of the device in the URL address field.
- Specify the default username as root and enter the password. See Performing Initial Software Configuration Using J-Web.
- Click Log In. The J-Web Dashboard page appears.
- Select Configure>System Properties>System Identity, and then select Edit. The Edit System Identity dialog box appears.
- Enter the hostname and click OK.
- Select Commit Options>Commit to apply the configuration changes.
You have successfully configured the hostname for the system.
Configuring Interfaces
To configure two physical interfaces:
You have successfully configured the physical interface. Repeat these steps to configure the second physical interface for the device.
Configuring Zones and Assigning Interfaces
To assign interfaces within a trust zone and an untrust zone:
You have successfully configured interfaces in a trust zone and in an untrust zone.
Configuring Security Policies
To configure security policies:
You have successfully configured the security policy.