Juniper SRX BranchϵÁзÀ»ðǽÅäÖùÜÀíÊÖ²á - ͼÎÄ ÏÂÔØ±¾ÎÄ

Juniper SRX BranchϵÁзÀ»ðǽÅäÖùÜÀíÊÖ²á

ÍõÏþ·½

Juniper ϵͳ¹¤³Ìʦ

Juniper Networks, Inc.

ÉϺ£Êл´º£Öз333ºÅÈ𰲹㳡1102-1104ÊÒ

Óʱà:200021 µç»°:61415000 http://www.juniper.net

µÚ 1 Ò³ ¹² 52 Ò³

Ŀ¼

Ò»¡¢JUNOS²Ù×÷ϵͳ½éÉÜ ...............................................................................................3 1.1 ²ã´Î»¯ÅäÖýṹ ........................................................................................................3 1.2 JunOSÅäÖùÜÀí .........................................................................................................4 1.3 SRXÖ÷ÒªÅäÖÃÄÚÈÝ.....................................................................................................4 ¶þ¡¢SRX·À»ðǽÅäÖòÙ×÷¾ÙÀý˵Ã÷ .................................................................................5 2.1 ³õʼ°²×° ..................................................................................................................5

2.1.1 É豸µÇ½ .......................................................................................................5

2.1.2 É豸»Ö¸´³ö³§½éÉÜ .........................................................................................5 2.1.3 ÉèÖÃrootÓû§¿ÚÁî .......................................................................................5 2.1.4 ÉèÖÃÔ¶³ÌµÇ½¹ÜÀíÓû§ ..................................................................................6 2.1.5 Ô¶³Ì¹ÜÀíSRXÏà¹ØÅäÖà ..................................................................................6 2.2 ÅäÖòÙ×÷ʵÑéÍØÆË ....................................................................................................7 2.3 ²ßÂÔÏà¹ØÅäÖÃ˵Ã÷ ....................................................................................................7

2.3.1 ²ßÂÔµØÖ·¶ÔÏó¶¨Òå .........................................................................................8

2.3.2 ²ßÂÔ·þÎñ¶ÔÏó¶¨Òå .........................................................................................8 2.3.3 ²ßÂÔʱ¼äµ÷¶È¶ÔÏó¶¨Òå ..................................................................................8 2.3.4 ²ßÂÔÅäÖþÙÀý ................................................................................................9 2.4 µØÖ·×ª»» ................................................................................................................ 10

2.4.1 Interface based NAT »ùÓÚ½Ó¿ÚµÄÔ´µØÖ·×ª»» ............................................. 10

2.4.2 Pool based Source NAT»ùÓÚµØÖ·³ØµÄÔ´µØÖ·×ª»» ....................................... 11 2.4.3 Pool base destination NAT»ùÓÚµØÖ·³ØµÄÄ¿±êµØÖ·×ª»» ............................ 12 2.4.4 Pool base Static NAT»ùÓÚµØÖ·³ØµÄ¾²Ì¬µØÖ·×ª»» ..................................... 13 2.5 IPSEC VPN .............................................................................................................. 13

2.5.1 »ùÓÚ·ÓɵÄLAN TO LAN IPSEC VPN.............................................................. 14 2.5.2 »ùÓÚ²ßÂÔµÄLAN TO LAN IPSEC VPN.............................................................. 15 2.5.3 »ùÓÚRemote VPN ¿Í»§¶Ë²¦ºÅVPN ................................................................ 15 2.5.4 »ùÓÚIPSEC¶¯Ì¬VPN .................................................................................... 24 2.6 Ó¦ÓòãÍø¹ØALGÅäÖü°ËµÃ÷................................................................................... 29 2.7 SRX Branch ϵÁÐJSRP HA¸ß¿ÉÓÃÐÔÅäÖü°ËµÃ÷ ...................................................... 29 2.8 SRX Branch ϵÁÐIDP¡¢UTMÅäÖòÙ×÷½éÉÜ ............................................................. 33 2.9 SRX Branch ϵÁÐÓëUACÁª¶¯ÅäÖÃ˵Ã÷ ................................................................... 38 2.10 SRX BranchϵÁÐFLOWÅäÖÃ˵Ã÷ .......................................................................... 42 2.11 SRX BranchϵÁÐSCREEN¹¥»÷·À»¤ÅäÖÃ˵Ã÷ ......................................................... 43 2.12 SRX BranchϵÁÐJ-WEB²Ù×÷ÅäÖüòҪ˵Ã÷ ............................................................ 44 Èý¡¢SRX·À»ðǽ³£¹æ²Ù×÷Óëά»¤ ................................................................................... 50 3.2 3.3 3.4 3.5 3.6

É豸¹Ø»ú ............................................................................................................ 50 Éè±¸ÖØÆô ............................................................................................................ 50 ²Ù×÷ϵͳÉý¼¶ ..................................................................................................... 50 ÃÜÂë»Ö¸´ ............................................................................................................ 51 ³£ÓÃ¼à¿ØÎ¬»¤ÃüÁî .............................................................................................. 51

µÚ 2 Ò³ ¹² 52 Ò³

Juniper SRX BranchϵÁзÀ»ðǽÅäÖùÜÀíÊÖ²á˵Ã÷

SRXϵÁзÀ»ðǽÊÇJuniper¹«Ë¾»ùÓÚJUNOS²Ù×÷ϵͳµÄ°²È«ÏµÁвúÆ·£¬JUNOS¼¯³ÉÁË·ÓÉ¡¢½»»»¡¢°²È«ÐÔºÍһϵÁзḻµÄÍøÂç·þÎñ¡£Ä¿Ç°Juniper¹«Ë¾µÄȫϵÁзÓÉÆ÷²úÆ·¡¢½»»»»ú²úÆ·ºÍSRX°²È«²úÆ·¾ù²ÉÓÃͳһԴ´úÂëµÄJUNOS²Ù×÷ϵͳ£¬JUNOSÊÇÈ«ÇòÊ׿ת·¢Óë¿ØÖÆ¹¦ÄÜÏà¸ôÀ룬²¢²ÉÓÃÄ£¿é»¯Èí¼þ¼Ü¹¹µÄÍøÂç²Ù×÷ϵͳ¡£JUNOS×÷ΪµçÐż¶²úÆ·µÄ¾«ËèÊÇJuniperÕæÕý³É¹¦µÄ»ùʯ£¬ËüÈÃÆóÒµ¼¶²úƷͬÑù¾ßÓеçÐż¶µÄ²»¼ä¶ÏÔËÓªÌØÐÔ£¬¸üºÃµÄ°²È«ÐԺ͹ÜÀíÌØÐÔ£¬JUNOSÈí¼þ´´Ðµķֲ¼Ê½¼Ü¹¹Îª¸ßÐÔÄÜ¡¢¸ß¿ÉÓᢸ߿ÉÀ©Õ¹µÄÍøÂçµì¶¨ÁË»ù´¡¡£»ùÓÚNP¼Ü¹¹µÄSRXϵÁвúÆ·²úƷͬʱÌṩÐÔÄÜÓÅÒìµÄ·À»ðǽ¡¢NAT¡¢IPSEC¡¢IPS¡¢UTMµÈȫϵÁа²È«¹¦ÄÜ£¬Æä°²È«¹¦ÄÜÖ÷ÒªÀ´Ô´ÓÚÒѱ»¹ã·ºÖ¤Ã÷µÄScreenOS²Ù×÷ϵͳ¡£

±¾ÎÄÖ¼ÔÚΪÊìϤNetscreen·À»ðǽScreenOS²Ù×÷ϵͳµÄ¹¤³ÌʦÌṩSRX·À»ðǽ²Î¿¼ÅäÖã¬ÒÔ±ãÓÚ´ó¼ÒÄܹ»¿ìËÙ²¿ÊðºÍά»¤SRX·À»ðǽ£¬Îĵµ½éÉÜJUNOS²Ù×÷ϵͳ£¬²¢²Î¿¼ScreenOSÅäÖýéÉÜSRX·À»ðǽÅäÖ÷½·¨£¬×îºó¶ÔSRX·À»ðǽ³£¹æ²Ù×÷Óëά»¤×ö¼òҪ˵Ã÷¡£

¼øÓÚSRXϵÁзÀ»ðǽµÍ¶ËϵÁÐÓë¸ß¶Ë3K¡¢5KϵÁÐÔÚ¹¦ÄÜÅäÖÃÓë°ü´¦ÀíÁ÷³ÌÓÐËù²îÒì,±¾ÈËÖ÷ÒªÒԵͶËϵÁй¦ÄÜÅäÖýéÉÜΪÖ÷,BranchϵÁÐÐͺÅĿǰ°üº¬£ºSRX100\\210\\240\\650½«À´»áÓÐеIJúÆ·¼ÓÈëµ½Branch¼Ò×å,ÇëËæÊ±¹Ø×¢¹Ù·½ÍøÕ¾¶¯Ì¬£¬ÅäÖôóͬСÒì¡£

Ò»¡¢JUNOS²Ù×÷ϵͳ½éÉÜ 1.1 ²ã´Î»¯ÅäÖýṹ

JUNOS²ÉÓûùÓÚFreeBSDÄں˵ÄÈí¼þÄ£¿é»¯²Ù×÷ϵͳ£¬Ö§³ÖCLIÃüÁîÐкÍWEBUIÁ½ÖÖ½Ó¿ÚÅäÖ÷½Ê½£¬±¾ÎÄÖ÷Òª¶ÔCLIÃüÁîÐз½Ê½½øÐÐÅäÖÃ˵Ã÷¡£JUNOS CLIʹÓòã´Î»¯ÅäÖýṹ£¬·ÖΪ²Ù×÷£¨operational£©ºÍÅäÖã¨configure£©Á½Ààģʽ£¬ÔÚ²Ù×÷ģʽÏ¿ɶԵ±Ç°ÅäÖá¢É豸ÔËÐÐ״̬¡¢Â·Óɼ°»á»°±íµÈ״̬½øÐв鿴¼°É豸ÔËά²Ù×÷£¬²¢Í¨¹ýÖ´ÐÐconfig»òeditÃüÁî½øÈëÅäÖÃģʽ£¬ÔÚÅäÖÃģʽÏ¿ɶԸ÷Ïà¹ØÄ£¿é½øÐÐÅäÖò¢Äܹ»Ö´ÐвÙ×÷ģʽϵÄËùÓÐÃüÁrun£©¡£ÔÚÅäÖÃģʽÏÂJUNOS²ÉÓ÷ֲã·Ö¼¶Ä£¿éÏÂÅäÖýṹ£¬ÈçÏÂͼËùʾ£¬editÃüÁî½øÈëÏÂÒ»¼¶ÅäÖã¨ÀàËÆunix cdÃüÁ,exitÃüÁîÍË»ØÉÏÒ»¼¶£¬topÃüÁî»Øµ½¸ù¼¶¡£

µÚ 3 Ò³ ¹² 52 Ò³

1.2 JunOSÅäÖùÜÀí

JUNOSͨ¹ýsetÓï¾ä½øÐÐÅäÖã¬ÅäÖÃÊäÈëºó²¢²»»áÁ¢¼´ÉúЧ£¬¶øÊÇ×÷ΪºòÑ¡ÅäÖã¨Candidate Config£©µÈ´ý¹ÜÀíÔ±ÌύȷÈÏ£¬¹ÜÀíԱͨ¹ýÊäÈëcommitÃüÁîÀ´Ìá½»ÅäÖã¬ÅäÖÃÄÚÈÝÔÚͨ¹ýSRXÓï·¨¼ì²éºó²Å»áÉúЧ£¬Ò»µ©commitͨ¹ýºóµ±Ç°ÅäÖü´³ÉΪÓÐЧÅäÖã¨Active config£©¡£ÁíÍ⣬JUNOSÔÊÐíÖ´ÐÐcommitÃüÁîʱҪÇó¹ÜÀíÔ±¶ÔÌá½»µÄÅäÖýøÐÐÁ½´ÎÈ·ÈÏ£¬ÈçÖ´ÐÐcommit confirmed 2ÃüÁîÒªÇó¹ÜÀíÔ±±ØÐëÔÚÊäÈë´ËÃüÁîºó2·ÖÖÓÄÚÔÙ´ÎÊäÈëcommitÒÔÈ·ÈÏÌá½»£¬·ñÔò2·ÖÖÓºóÅäÖý«×Ô¶¯»ØÍË£¬ÕâÑù¿ÉÒÔ±ÜÃâÔ¶³ÌÅäÖñä¸üʱ¹ÜÀíԱʧȥ¶ÔSRXµÄÔ¶³ÌÁ¬½Ó·çÏÕ¡£

ÔÚÖ´ÐÐcommitÃüÁîǰ¿Éͨ¹ýÅäÖÃģʽÏÂshowÃüÁî²é¿´µ±Ç°ºòÑ¡ÅäÖã¨Candidate Config£©£¬ÔÚÖ´ÐÐcommitºóÅäÖÃģʽÏ¿Éͨ¹ýrun show configÃüÁî²é¿´µ±Ç°ÓÐЧÅäÖã¨Active config£©¡£´ËÍâ¿Éͨ¹ýÖ´ÐÐshow | compare±È¶ÔºòÑ¡ÅäÖúÍÓÐЧÅäÖõIJîÒì¡£

SRXÉÏÓÉÓÚÅ䱸´óÈÝÁ¿´æ´¢Æ÷£¬È±Ê¡°´ÏȺócommit˳Ðò×Ô¶¯±£´æ50·ÝÓÐЧÅäÖ㬲¢¿Éͨ¹ýÖ´ÐÐrolbackºÍcommitÃüÁî·µ»Øµ½ÒÔǰÅäÖã¨Èçrollback 0/commit¿É·µ»Øµ½Ç°Ò»commitÅäÖã©£»Ò²¿ÉÒÔÖ±½Óͨ¹ýÖ´ÐÐsave configname.confÊÖ¶¯±£´æµ±Ç°ÅäÖ㬲¢Ö´ÐÐload override configname.conf / commitµ÷ÓÃǰÆÚÊÖ¶¯±£´æµÄÅäÖá£Ö´ÐÐload factory-default / commitÃüÁî¿É»Ö¸´µ½³ö³§È±Ê¡ÅäÖá£

SRX¿É¶ÔÄ£¿é»¯ÅäÖýøÐй¦ÄܹرÕÓ뼤»î£¬ÈçÖ´ÐÐdeactivate security nat/comitÃüÁî¿ÉʹNATÏà¹ØÅäÖò»ÉúЧ£¬²¢¿Éͨ¹ýÖ´ÐÐactivate security nat/commitʹNATÅäÖÃÔÙ´ÎÉúЧ¡£

SRXͨ¹ýsetÓï¾äÀ´ÅäÖ÷À»ðǽ£¬Í¨¹ýdeleteÓï¾äÀ´É¾³ýÅäÖã¬Èçdelete security natºÍedit security nat / deleteÒ»Ñù£¬¾ù¿Éɾ³ýsecurity·À»ðǽ²ã¼¶ÏÂËùÓÐNATÏà¹ØÅäÖã¬É¾³ýÅäÖúÍScreenOS²»Í¬£¬ÅäÖùý³ÌÖÐÐè¼ÓÒÔÁôÒâ¡£

1.3 SRXÖ÷ÒªÅäÖÃÄÚÈÝ

²¿ÊðSRX·À»ðǽÖ÷ÒªÓÐÒÔϼ¸¸ö·½ÃæÐèÒª½øÐÐÅäÖãº

System£ºÖ÷ÒªÊÇϵͳ¼¶ÄÚÈÝÅäÖã¬ÈçÖ÷»úÃû¡¢¹ÜÀíÔ±Õ˺ſÚÁȨÏÞ¡¢Ê±ÖÓÊ±Çø¡¢Syslog¡¢SNMP¡¢ÏµÍ³¼¶¿ª·ÅµÄÔ¶³Ì¹ÜÀí·þÎñ£¨Èçtelnet£©µÈÄÚÈÝ¡£

Interface:½Ó¿ÚÏà¹ØÅäÖÃÄÚÈÝ¡£

Security: ÊÇSRX·À»ðǽµÄÖ÷ÒªÅäÖÃÄÚÈÝ£¬°²È«Ïà¹Ø²¿·ÖÄÚÈÝÈ«²¿ÔÚSecurity²ã¼¶ÏÂÍê³ÉÅäÖã¬ÈçNAT¡¢Zone¡¢Policy¡¢Address-book¡¢Ipsec¡¢Screen¡¢Idp¡¢UTMµÈ£¬¿É¼òµ¥Àí½âΪScreenOS·À»ðǽ°²È«Ïà¹ØÄÚÈݶ¼Ç¨ÒÆÖÁ´ËÅäÖòã´ÎÏ£¬³ýÁËApplication×Ô¶¨Òå·þÎñ¡£

Application£º×Ô¶¨Òå·þÎñµ¥¶ÀÔڴ˽øÐÐÅäÖã¬ÅäÖÃÄÚÈÝÓëScreenOS»ù±¾Ò»Ö¡£

routing-options£º ÅäÖþ²Ì¬Â·ÓÉ»òrouter-idµÈϵͳȫ¾Ö·ÓÉÊôÐÔÅäÖá£

µÚ 4 Ò³ ¹² 52 Ò³