Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Configure Junos OS on the SRX4120

This topic guides you through the initial configuration of your SRX4120 by using Juniper® Mist, Juniper® Security Director on Premise, Juniper® Security Director Cloud, the J-Web GUI, and the CLI.

We ship the SRX4120 with preinstalled Junos OS, which is ready to be configured when you power on the device. You can use Juniper® Mist, Juniper® Security Director on Premise, Juniper® Security Director Cloud, the J-Web GUI, or the CLI to perform the initial configuration.

Access the CLI on the SRX4120

To access the CLI on your device:
  1. Verify that the router is powered on.
  2. Connect the management device to the serial console port as described in Connect the to External Devices.
  3. Start your asynchronous terminal emulation application (such as Microsoft Windows HyperTerminal) and select the appropriate COM port to use (for example, COM1).
  4. Configure the serial port settings with the following values:
    • Baud rate—9600

    • Parity—N

    • Data bits—8

    • Stop bits—1

    • Flow control—none

  5. Power on the device. You can start performing initial software configuration on the device after the device is up.
    Note:

    After you complete the initial configuration, you can connect your device to a network for out-of-band management as described in Connect the to External Devices.

Configure Root Authentication and Management Interface from the CLI

You must perform the initial configuration of the device through the console port.

Gather the following information before configuring the device:

  • Root authentication

  • IP address of the management interface

  • IP address of the default gateway

  • IP address of a DNS server

To configure root authentication and the management interface:

  1. Log in as root. There is no password.
  2. Start the CLI and enter configuration mode.
  3. Set the root authentication password. You can enter a cleartext password, an encrypted password, or an SSH public key string (DSA or RSA).
  4. (Optional) Configure the host name of the device.
  5. Commit the configuration to activate it on the device.
  6. Configure the IP address and prefix length for the Ethernet management interface on the device.
  7. Configure the default route.
  8. Enable Web access to launch J-Web.
  9. Enable SSH access on the device.
  10. Configure the IP address of a DNS server.
  11. Commit the configuration changes.

Configure the SRX4120 Using J-Web

The J-Web interface is a Web-based graphical interface that allows you to operate a device without commands.

To access the J-Web interface on a new device that has the factory-default configuration:

  1. Connect the management port (MGMT) on your device to the Ethernet port on the management device (laptop or PC), using an RJ-45 cable.
  2. Manually configure the management device with a compatible IP address in the 192.168.1.0 network (for example, 192.168.1.2). Do not use the 192.168.1.1 IP address for the management device as this IP address is assigned to the fxp0 interface.
  3. Open a browser and enter https://192.168.1.1 in the address bar.

    The J-Web Setup page opens. You can choose one of the following setup modes to configure the device:

    • Standalone mode—In this mode, you can configure the basic settings such as device credentials, time, management interface, zones and interfaces, and DNS servers and default gateways.

    • Cluster (HA) mode—In cluster mode, a pair of devices are connected and configured to operate like a single node, providing device-, interface-, and service-level redundancy.

    • Passive (Tap) mode—Tap mode allows you to passively monitor traffic flows across a network. If intrusion prevention system (IPS) is enabled, then the tap mode inspects the incoming and outgoing traffic to detect the number of threats.

  4. Select the setup mode that you want to use to configure the device, and click Start.

    The Setup Wizard page appears.

  5. Follow the instructions on the Setup Wizard to to configure your device.

Configure the SRX4120 using Juniper Mist

You can configure and manage your device using the Mist cloud portal. If you have a Mist WAN Assurance license, follow the instructions in the Cloud-Ready SRX Series Firewalls with Mist.

If you don't have a license, use the CLI to configure your system.

Configure the SRX4120 using Juniper Security Director On-Premise

Juniper® Security Director is an on-premises management solution that allows you to manage your firewalls through a centralized web interface.

Follow the instructions in the Onboard SRX Series Firewalls to Security Director guide to configure your device.

Configure the SRX4120 using Juniper Security Director Cloud

Juniper® Security Director Cloud is a cloud-based software as a solution (SaaS) portal that helps you securely migrate your network to a Secure Access Service Edge (SASE) architecture.

Follow the instructions in the Onboard SRX Series Firewalls to Security Director Cloud guide to configure your device.