
This chapter shows you how to configure your NetScreen-10/100 in Transparent mode and allow internal users to access the Internet while denying internal access from the Internet. You do this by setting the System IP address and creating an Access Policy that permits outgoing traffic.
There are two methods for configuring the NetScreen-10/100 for the first time. Table 61 "Administration Requirements" lists the workstation requirements for each method.
The installation procedure using a Web browser is explained first, followed by the CLI procedures using the console port and Telnet.
To perform the initial configuration through a WebUI, you need to change the IP address of the management workstation to the same subnet as the NetScreen-10/100 default system IP address. You can log on through a Web browser and set the system IP address. The following sections details the procedures for administration of the NetScreen-10/100 device from the administrator's workstation.
For remote administration of the NetScreen device over a network connection, you must change the system IP address. The NetScreen-10/100 ships from the factory with a default IP address of 192.168.1.1. To change this to an address on the same subnet as the other network devices to which the NetScreen-10/100 is connected, enter the following command:
1. Record the IP address and subnet mask of your workstation; you must re-enter them later in this process.
2. Change the IP address of the workstation to 192.168.1.2 and the subnet mask to 255.255.255.0. You might have to restart the workstation to enable the changes to take effect. The workstation is now part of the same subnet as the default IP address of the NetScreen-10/100, which is 192.168.1.1.
4. In the URL field of the browser, enter the IP address of the NetScreen-10/100: http://192.168.1.1.
6. In the dialog box, type netscreen for both the user name and password, and then click OK.
Note: The user name and password are case-sensitive. After configuring the NetScreen device for the first time, you should change the default user name and password as described in "Changing the Administrator Login Name and Password" on page 654.
7. For the first-time configuration, you are directed to a special setup page as shown in Figure 6-2.
8. Enter the IP address and subnet mask for administration of the
NetScreen-10/100, and then click OK.
The IP address must be a valid and available IP address on your local network and the subnet mask must be an appropriate value for your local network.
9. Reconfigure your administration workstation IP address and subnet mask back to values you recorded in step 1. Depending on the operating system, you might have to restart your workstation.
2. In the dialog box, type netscreen for both the user name and password, and then click OK. Remember that the user name and password are case-sensitive.
The Access Policies pages appear, with the Outgoing Access Policies page displayed, as shown in Figure 6-5. You are now logged on to the
NetScreen-10/100.
1. Click the New Policy option in the lower left corner of the Access Policies page. The Policy Configuration dialog box appears.
2. Set an Access Policy that allows all inside hosts to access the Internet. Set the options as follows:
- Source Address: Inside Any (Inside Any is a predefined address for any host on the Trusted network)
- Destination Address: Outside Any (Outside Any is a predefined address for any location on the Untrusted network, Internet)
The Outgoing Access Policies page now has one Access Policy that permits any inside traffic to pass through the firewall and access the Internet, as shown in Figure 6-7.
Because there is no need to configure other interface IP settings, your NetScreen-10/100 configuration for Transparent mode is now complete.
Because all NetScreen units come with the same default name and password, it is highly recommended that you change the default Admin Login name and Password.
Use your Web browser to access an external Web site (for example, www.netscreen.com). You should be able to locate the site and access the available Web pages.
The following section provides information on how to configure the device using the command line interface (CLI).
You can access the CLI either by connecting directly via a console (or serial) cable or you can use the network via Telnet. Connection instructions are offered for both methods.
You need direct access to the NetScreen device you want to configure and the following items before you start:
· Microsoft Hyperterminal software on the management workstation (or, if you are using a different operating system, a VT100 terminal emulator)
1. Connect the serial cable from the management workstation to the serial port on the NetScreen-10/100.
4. Select the serial port to which the serial cable is connected to the workstation, and click OK. The COM1 Properties dialog box appears.
Telnet operates over TCP/IP networks. It allows you to configure the device using the command line interface (CLI).
Before you begin, be sure you connected the NetScreen device hardware to the network as outlined in Chapter 2.
To administer the NetScreen device over a network connection, you must change the system IP address. The NetScreen-10/100 ships from the factory with a default IP address of 192.168.1.1. To change this to an address on the same subnet as the other network devices to which the NetScreen-10/100 is connected, enter the following command, substituting your system IP address for the letters:
Because all NetScreen units come with the same default name and password, it is highly recommended that you change the default Admin Login name and Password.
![]() NetScreen Technologies Inc. http://www.netscreen.com Voice: (408) 730-6000 Fax: (408) 730-6100 sales@netscreen.com |