SSG 500m Series
SSG 500m Series
SSG 500m Series
SSG 500M-series
Hardware Installation and Configuration Guide
Juniper Networks, the Juniper Networks logo, JUNOS, NetScreen, ScreenOS, and Steel-Belted Radius are registered trademarks of Juniper Networks, Inc.
in the United States and other countries. JUNOSe is a trademark of Juniper Networks, Inc. All other trademarks, service marks, registered trademarks, or
registered service marks are the property of their respective owners.
All specifications are subject to change without notice. Juniper Networks assumes no responsibility for any inaccuracies in this document or for any
obligation to update information in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication
without notice.
FCC Statement
The following information is for FCC compliance of Class A devices: This equipment has been tested and found to comply with the limits for a Class A
digital device, pursuant to part 15 of the FCC rules. These limits are designed to provide reasonable protection against harmful interference when the
equipment is operated in a commercial environment. The equipment generates, uses, and can radiate radio-frequency energy and, if not installed and
used in accordance with the instruction manual, may cause harmful interference to radio communications. Operation of this equipment in a residential
area is likely to cause harmful interference, in which case users will be required to correct the interference at their own expense.
The following information is for FCC compliance of Class B devices: The equipment described in this manual generates and may radiate radio-frequency
energy. If it is not installed in accordance with Juniper Networks’ installation instructions, it may cause interference with radio and television reception.
This equipment has been tested and found to comply with the limits for a Class B digital device in accordance with the specifications in part 15 of the FCC
rules. These specifications are designed to provide reasonable protection against such interference in a residential installation. However, there is no
guarantee that interference will not occur in a particular installation.
If this equipment does cause harmful interference to radio or television reception, which can be determined by turning the equipment off and on, the user
is encouraged to try to correct the interference by one or more of the following measures:
Connect the equipment to an outlet on a circuit different from that to which the receiver is connected.
Caution: Changes or modifications to this product could void the user's warranty and authority to operate this device.
Disclaimer
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED
WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED
WARRANTY, CONTACT YOUR JUNIPER NETWORKS REPRESENTATIVE FOR A COPY.
2
Table of Contents
About This Guide 5
Organization .................................................................................................... 5
Web User Interface Conventions .............................................................. 6
Command Line Interface Conventions ......................................................6
Requesting Technical Support .......................................................................... 7
Self-Help Online Tools and Resources........................................................ 7
Opening a Case with JTAC ......................................................................... 7
Feedback ......................................................................................................... 8
.................................................................................................................. 8
Table of Contents 3
SSG 500M-series Installation and Configuration Guide
Appendix A Specifications 57
Physical.......................................................................................................... 57
Electrical ........................................................................................................ 58
Environmental Tolerance ............................................................................... 58
Certifications.................................................................................................. 59
RoHS and WEEE ............................................................................................ 59
Connectors..................................................................................................... 60
Index.......................................................................................................................... 63
4 Table of Contents
About This Guide
The Juniper Networks Secure Services Gateway (SSG) 500M-series devices are
integrated router and firewall platforms. They provide Internet Protocol Security
(IPSec) virtual private network (VPN) and firewall services for enterprise-edge
environments.
SSG 520M
SSG 550M
NOTE: The configuration instructions and examples in this document are based on the
functionality of a device running ScreenOS Release 6.0.0. Your device might
function differently depending on the ScreenOS version you are running. For the
latest device documentation, refer to the Juniper Networks Technical Publications
website at www.juniper.net/techpubs/hardware. To determine which ScreenOS
versions are currently available for your device, refer to the Juniper Networks
Support website at http://www.juniper.net/customers/support/.
Organization
This guide contains the following chapters and appendix:
Organization 5
SSG 500M-series Installation and Configuration Guide
The following example shows the WebUI path and parameters for defining an
address:
Policy > Policy Elements > Addresses > List > New: Enter the following, then
click OK:
Address Name: addr_1
IP Address/Domain Name:
IP/Netmask: (select), 10.2.2.5/32
Zone: Untrust
To open online Help for configuration settings, click the question mark (?) in the
upper left of the screen.
The navigation tree also provides a Help > Config Guide configuration page to help
you configure security policies and Internet Protocol Security (IPSec). Select an
option from the list and follow the instructions on the page. Click the ? character in
the upper left for Online Help on the Config Guide.
In text, commands are in boldface type and variables are in italic type.
In examples:
If there is more than one choice, each choice is separated by a pipe ( | ). For
example, the following command means “set the management options for the
ethernet1, the ethernet2, or the ethernet3 interface”:
NOTE: When entering a keyword, you only have to type enough letters to identify the
word uniquely. For example, typing set adm u ang j12fmt54 is enough to enter
the command set admin user angel j12fmt54. Although you can use this shortcut
when entering commands, all the commands documented here are presented in
their entirety.
6 Organization
About This Guide
Download the latest versions of software and review your release notes—
http://www.juniper.net/customers/csc/software/
To verify service entitlement by product serial number, use our Serial Number
Entitlement (SNE) Tool—
https://tools.juniper.net/SerialNumberEntitlementSearch/
Feedback
If you find any errors or omissions in this document, contact Juniper Networks at
[email protected].
8 Feedback
Chapter 1
Hardware Overview
Front Panel
Figure 1 shows the front panel of an SSG 500M-series device.
Figure 1: SSG 500M-series Front Panel (SSG 550M Shown, SSG 520M Similar)
PIM Slot 1 PIM Slot 4
PIM Slot 2 PIM Slot 5
SSG 550M
Device status
LEDs USB ports
Power
button AUX port
Reset config Ethernet Console port
button ports
Front Panel 9
SSG 500M-series Installation and Configuration Guide
Port Descriptions
Table 1 describes the function, connector type, and speed/protocol (if applicable) of
the ports on the front panel of the SSG 500M-series device.
10 Front Panel
Hardware Overview
Power Button
The power button is located on the left side of the front panel. You use the power
button to power the device on and off. When you power on the device, ScreenOS
starts as the power supply completes its startup sequence. See “Powering the
Device On and Off” on page 26 for more information.
When the device powers up, the POWER LED changes from off to blinking green,
and the STATUS LED changes in the following sequence: red, green, blinking green.
Startup takes approximately two minutes to complete. If you want to turn the
device off and on again, we recommend you wait a few seconds between shutting it
down and powering it back up. Table 2 lists the name, color, status, and description
of each device status LED.
Front Panel 11
SSG 500M-series Installation and Configuration Guide
TX/RX LINK
12 Front Panel
Hardware Overview
CAUTION: PIMs are not hot-swappable. Always switch off the device before
inserting or removing PIMs.
Table 4 shows the PIM types you can install in the slots of an SSG 520M device. The
E located on some of the slots identifies where you can install enhanced PIMs
(ePIMs).
Table 5 shows the PIM types you can install in the slots of an SSG 550M device. The
E located on some of the slots identifies where you can install enhanced PIMs
(ePIMs).
NOTE: When you install PIMs with Small Form-factor Pluggable (SFP) interfaces, Juniper
strongly recommends the use of Juniper SFP transceivers. Juniper cannot
guarantee correct operation if non-Juniper transceivers are used. The transceiver
type can be different in each port, as long as a supported part number is used.
USB Ports
The USB ports on the front panel of an SSG 500M-series device accept a universal
serial bus (USB) storage device.
The USB ports let you transfer data such as device configurations, image keys, and
ScreenOS software between a USB storage device and the internal flash storage of
the security device. The USB ports support USB 1.1 and USB 2.0 specifications.
You can also log messages to a USB storage device. For more information about
logging, refer to the Administration volume of the Concepts and Examples ScreenOS
Reference Guide.
Front Panel 13
SSG 500M-series Installation and Configuration Guide
To transfer data between a USB storage device and an SSG 500M-series device:
1. Connect the USB storage device to either the upper or lower USB port on the
security device.
2. Save the files from the USB storage device to the internal flash storage on the
device with the save {software | config | image-key} from usb filename to
flash command.
3. Stop the USB port with the exec usb-device stop command before removing
the USB storage device.
If you want to delete a file from the USB storage device, use the delete file
usb:/filename command.
If you want to view the saved file information on the USB storage device and
internal flash storage, use the get file command.
Back Panel
The back panel of an SSG 500M-series device contains the fan tray and power
supply unit(s) and a two-hole grounding lug.
Grounding
lugs
The SSG 550M device has slots for two field-installable PSUs and is supplied
with a single AC or DC PSU. You can add a second AC or DC PSU for increased
reliability.
14 Back Panel
Hardware Overview
For PSU servicing instructions, see “Replacing Power Components (SSG 550M
Only)” on page 48.
NOTE: Do not mix SSG 550M PSU types. The only supported combinations are AC+AC
and DC+DC.
The POWER LED on the front panel of an SSG 500M-series device glows either
green or red. Green indicates correct function and red indicates PSU failure.
I Power switch
O Power cord
receptacle
The field-replaceable AC PSU faceplate for an SSG 550M device contains an ejector
tab handle, an input power light, and a power cord receptacle.
Back Panel 15
SSG 500M-series Installation and Configuration Guide
Ejector tab
Input
power light
Power cord
receptacle
Handle
Ejector tab
Input
power light -48V
DC power RTN
terminal
blocks
Ejector tab
Input
power light
-48V
DC power
terminal
blocks RTN
Handle
Grounding Lug
A two-hole grounding lug is provided on the left rear of the chassis to connect the
device to earth ground (see Figure 4 on page 14).
16 Back Panel
Hardware Overview
To ground the device before connecting power, connect a grounding cable to earth
ground and then attach the cable to the lug on the rear of the chassis. For more
information, see “Chassis Grounding” on page 22.
Back Panel 17
SSG 500M-series Installation and Configuration Guide
18 Back Panel
Chapter 2
Installing and Connecting the Device
NOTE: For safety warnings and instructions, refer to the Juniper Networks Security
Products Safety Guide. When working on any equipment, be aware of the hazards
involved with electrical circuitry, and follow standard practices for preventing
accidents.
19
SSG 500M-series Installation and Configuration Guide
Before installation, always check that the power supply is disconnected from
any power source.
Ensure that the room in which you operate the device has adequate air
circulation and that the room temperature does not exceed 104° F (40° C).
Allow three feet (one meter) of clear space to the front and back of the device.
This device exceeds 18 pounds (8.2 kilograms). Take precautions when lifting
and stabilizing the device.
Correct these hazardous conditions before any installation: moist or wet floors,
leaks, ungrounded or frayed power cables, or missing safety grounds.
Installing Equipment
You can rack-mount the SSG 550M-series device into a standard 19-inch equipment
rack. The device is shipped with mounting brackets. The equipment is suitable for
installation in locations where the National Electrical Code (NEC) applies, as well as
in Network Telecommunication Facilities.
NOTE: If you are installing multiple devices in one rack, install the lowest one first and
proceed upward in the rack.
CAUTION: The device weighs between 23 lb. (10.4 kg) and 31 lb. (14.1 kg).
Installing it into the rack requires at least one person to lift the device and a
second person to secure the mounting screws.
To mount the device, you must have number-2 phillips screwdriver (not provided)
and four screws that are compatible with the equipment rack (not provided).