JUNOS for Security Platforms
9.a
Lab Diagrams
1194 North Mathilda Avenue Sunnyvale, CA 94089 USA 408-745-2000 www.juniper.net Course Number: EDU-JUN-JSEC
Juniper Networks, the Juniper Networks logo, JUNOS, NetScreen, and ScreenOS are registered trademarks of Juniper Networks, Inc. in the United States and other countries. JUNOSe is a trademark of Juniper Networks, Inc. All other trademarks, service marks, registered trademarks, or registered service marks are the property of their respective owners. JUNOS for Security Platforms Lab Diagrams, Revision 9.a Copyright 2009, Juniper Networks, Inc. All rights reserved. Printed in USA. Revision History: Revision 9.aJuly 2009 The information in this document is current as of the date listed above. The information in this document has been carefully verified and is believed to be accurate for software Release 9.5R1.8. Juniper Networks assumes no responsibilities for any inaccuracies that may appear in this document. In no event will Juniper Networks be liable for direct, indirect, special, exemplary, incidental or consequential damages resulting from any defect or omission in this document, even if advised of the possibility of such damages.
Juniper Networks reserves the right to change, modify, transfer or otherwise revise this publication without notice. YEAR 2000 NOTICE Juniper Networks hardware and software products do not suffer from Year 2000 problems and hence are Year 2000 compliant. The JUNOS Software has no known time-related limitations through the year 2038. However, the NTP application is known to have some difficulty in the year 2036. SOFTWARE LICENSE The terms and conditions for using Juniper Networks software are described in the software license provided with the software, or to the extent applicable, in an agreement executed between you and Juniper Networks, or Juniper Networks agent. By using Juniper Networks software, you indicate that you understand and agree to be bound by its license terms and conditions. Generally speaking, the software license restricts the manner in which you are permitted to use the Juniper Networks software, may contain prohibitions against certain uses, and may state conditions under which the license is automatically terminated. You should consult the software license for further details.
Management Network Diagram
ge-0/0/0 (on all student devices)
host1host1-a Serial Console host2Connections host2-a . .
Management Network Student Workstations
Terminal Server
10.210.__.__/27
Management Addressing
host2host2-d
host1host1-a host2host2-a host1host1-b ____________/___ ____________/___ ____________/___ ____________/___ ____________/___ ____________/___ host1-d host1host2host2-d vrvr-device Server GW ___________/___ ___________/___ ___________/___ _______________ _______________
vr-device vr-
host2host2-b host1host1-c host2host2-c
Term Server _______________
Server
2009 Juniper Networks, Inc. All rights reserved.
Note: Instructor will provide address and access information.
Education Services
Network Diagram: Labs 17
VLAN Assignments vlan(v=remainder of vlan-id) Hostname host1-a host2-a host1-b host2-b host1-c host2-c host1-d host2-d VLAN-ID 100, 200 101, 201 102, 202 103, 203 104, 204 105, 205 106, 206 107, 207
(.2 ) (.1 )
Host 172.31.15.1
Internet
(.1 )
8 .1 2 17
0 /3 .0 .1
17 2. 18 .2 .0 /3 0
x = Pod (a, b, c, or d)
(.2 )
/1 Untrust Zone /0 0 eg
ge Untrust Zone -0/0 /1
host1host1-x
lo0: 192.168.1.1
host2host2-x
lo0: 192.168.2.1
fe-0/0/5.10v fe-0/0/5.10v 172.20.10v.0/24 (.10) vr10v vr10v
fe-0/0/5.20v (.1) fe-0/0/5.20v 172.20.20v.0/24 (.10) vr20v vr20v
Tagged Interface (see table above)
fe-0/0/5.10v fe-0/0/5.10v 172.20.10v.0/24 (.10) vr10v vr10v
fe-0/0/5.20v (.1) fe-0/0/5.20v 172.20.20v.0/24 (.10) vr20v vr20v
hr zone
2009 Juniper Networks, Inc. All rights reserved.
eng zone
Virtual Routers
Education Services
dc zone
it zone
Network Diagram: Lab 8
LAN Addresses Pod a b c d 172.20.y 172.20.y/24 172.20.10/24 172.20.20/24 172.20.30/24 172.20.40/24
8 .1 2 17 0 /3 .0 .1
(.1 )
Internet
(.1 )
Untrust Zone
(.2
17 2. 18 .2 .0 /3 0
(.2 )
/1 /0 -0 ge
fefe-0/0/7 fefe-0/0/2
ClusterCluster-ID 1 fxp1 fab0 reth0
(.1)
ge -2 /0 /1
x = Pod (a, b, c, or d)
fefe-2/0/7
host1host1-x
node0
fab1
fefe-2/0/2
host2host2-x
node1
fefe-0/0/5
fefe-2/0/5
LAN 172.20.y 172.20.y.z/24 (see table above)
Switch Trust Zone
2009 Juniper Networks, Inc. All rights reserved.
Education Services