[{"data":1,"prerenderedAt":897},["ShallowReactive",2],{"blog-\u002Fen\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web":3,"blog-\u002Fen\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web-surround":769,"blog-\u002Fen\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web-certifications":823},{"id":4,"title":5,"body":6,"categories":753,"cover":755,"cover_contain":756,"credly_badge_id":757,"date":758,"description":759,"extension":760,"meta":761,"navigation":756,"path":762,"related_certifications":763,"seo":765,"slug":766,"stem":767,"__hash__":768},"blog\u002Fen\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web.md","Configuring an SRX100 Gateway via J-Web",{"type":7,"value":8,"toc":737},"minimark",[9,14,18,22,72,100,105,112,119,138,154,169,173,180,187,192,223,233,247,251,274,278,294,299,310,366,370,384,425,430,435,444,449,469,474,482,487,496,501,508,513,517,543,551,561,566,589,611,616,642,646,656,679,689,694,730,734],[10,11,13],"h2",{"id":12},"real-world-use-case","Real-world use case",[15,16,17],"p",{},"You're discovering Juniper's SRX range: here's how to configure an SRX100 gateway via the J-Web interface.",[10,19,21],{"id":20},"juniper-networks-srx-series","Juniper Network's SRX series",[15,23,24,25,29,30,33,34,33,37,40,41,44,45,48,49,52,53,56,57,60,61,33,64,67,68,71],{},"Juniper Network's ",[26,27,28],"strong",{},"SRX"," range lets you manage ",[26,31,32],{},"security",", ",[26,35,36],{},"routing",[26,38,39],{},"switching",", and ",[26,42,43],{},"WAN connectivity",". Configuring ",[26,46,47],{},"IPSec VPN"," access is also possible.",[50,51],"br",{},"\nWith an additional subscription, it can also manage so-called ",[26,54,55],{},"unified threat management"," (",[26,58,59],{},"UTM","): antivirus, application security, ",[26,62,63],{},"IPS",[26,65,66],{},"anti-spam",", and enhanced ",[26,69,70],{},"web filtering"," (optional).",[15,73,74,75,78,79,82,83,86,87,89,90,92,93,86],{},"It's described as a ",[26,76,77],{},"services gateway"," for ",[26,80,81],{},"securing"," various ",[26,84,85],{},"corporate networks",".",[50,88],{},"\nThe device is very stable and powerful enough for small businesses (a dozen people or so).",[50,91],{},"\nTo discover the SRX range, head over here: ",[94,95,99],"a",{"href":96,"rel":97},"http:\u002F\u002Fwww.juniper.net\u002Ffr\u002Ffr\u002Fproducts-services\u002Fsecurity\u002Fsrx-series\u002F",[98],"nofollow","discover SRX",[101,102,104],"h3",{"id":103},"overview-of-the-srx100","Overview of the SRX100",[15,106,107,108,111],{},"The ",[26,109,110],{},"SRX100 services gateway"," offers, on the front panel (left to right):",[15,113,114],{},[115,116],"img",{"alt":117,"src":118},"","\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F475c5a3393.jpg",[120,121,122,126,129,132,135],"ul",{},[123,124,125],"li",{},"A Power button: shutdown and startup.",[123,127,128],{},"Various LEDs: alarm, power, status, ha.",[123,130,131],{},"A device reset button.",[123,133,134],{},"A management console port.",[123,136,137],{},"(8) 100Mb\u002Fs ports.",[15,139,140,141,143,144,147,148,86,151,153],{},"On the back of the device, you'll find the 12V power connector, the ground connector, and the security lock.",[50,142],{},"\nMy model is specifically the ",[26,145,146],{},"SRX100H2",", dated June 2014: purchased from ",[26,149,150],{},"IngramMicro",[50,152],{},"\nFor reference, in addition to the SRX100, the bundle includes:",[120,155,156,159,166],{},[123,157,158],{},"A quick start guide, the device's usage license, a hardware security guide.",[123,160,161,162,165],{},"A ",[26,163,164],{},"DB9-to-RJ45"," cable.",[123,167,168],{},"A power cable in addition to the power adapter.",[10,170,172],{"id":171},"pre-configuration-overview","Pre-configuration: overview",[15,174,175,176,179],{},"To start using the device, we need to understand its ",[26,177,178],{},"default configuration"," and the key points needed for a properly working SRX100 setup.",[15,181,182,183,186],{},"By default, the device's settings are as follows: (photo of my ",[26,184,185],{},"Nexus 4",").",[15,188,189],{},[115,190],{"alt":117,"src":191},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F3e9ed88152.png",[15,193,194,195,198,199,202,203,86,206,208,209,212,213,215,216,219,220,222],{},"The documentation is very clear; we can see that ports 0\u002F1 to 0\u002F7 let you get an address to configure the SRX, and that there are two zones, ",[26,196,197],{},"untrust"," and ",[26,200,201],{},"trust",", with ",[26,204,205],{},"policies",[50,207],{},"\nA ",[26,210,211],{},"source NAT"," rule from \"",[26,214,201],{},"\" ",[26,217,218],{},"to"," \"",[26,221,197],{},"\" is configured (allows access to the internet zone).",[15,224,225,226,229,230,232],{},"Now, we'll obviously modify the ",[26,227,228],{},"SRX configuration"," and adapt it to our needs.",[50,231],{},"\nBe aware that all of the following points will need to be configured:",[120,234,235,238,241,244],{},[123,236,237],{},"Interfaces will need to be configured with an IP address.",[123,239,240],{},"Interfaces will be tied to a security zone.",[123,242,243],{},"Zone policies will need to be configured between each other (allow or deny).",[123,245,246],{},"Source NAT rules will need to be adjusted to access the internet.",[10,248,250],{"id":249},"configuring-the-setup-wizard-in-j-web","Configuring the setup wizard in J-Web",[15,252,253,254,257,258,261,262,86,265,267,268,270],{},"We'll now discover the ",[26,255,256],{},"initial configuration"," of the ",[26,259,260],{},"SRX100"," under ",[26,263,264],{},"J-Web",[50,266],{},"\nJ-Web is Juniper Network's web interface, here it is in \"setup wizard\" mode:",[50,269],{},[271,272,273],"em",{},"I won't show all 30 screenshots of the \"setup\" steps: I'll go through it briefly.",[101,275,277],{"id":276},"basic-settings","Basic settings",[120,279,280],{},[123,281,282,283,289,290,293],{},"Go to the IP address: ",[26,284,285],{},[94,286,287],{"href":287,"rel":288},"http:\u002F\u002F192.168.1.1",[98],", and select ",[26,291,292],{},"step-by-step"," mode.",[15,295,296],{},[115,297],{"alt":117,"src":298},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F1296c062ac.png",[15,300,301,302,305,306,309],{},"A progress bar appears at the top: \"",[26,303,304],{},"Basic Settings","\" => \"",[26,307,308],{},"Security Topology","\", etc…. these are the minimum configuration steps for the device to work properly.",[120,311,312,337,354,363],{},[123,313,314,315,318,319,322,323,325,328,329,328,334],{},"Next, choose between \"",[26,316,317],{},"basic options","\" or \"",[26,320,321],{},"advanced options","\".",[50,324],{},[271,326,327],{},"I used the"," ",[271,330,331],{},[26,332,333],{},"advanced option",[271,335,336],{},"in order to explore the J-Web setup wizard interface as much as possible.",[123,338,339,340,343,344,347,348,215,351,86],{},"We're then asked to configure the \"",[26,341,342],{},"hostname","\", the \"",[26,345,346],{},"root account","\", as well as add a user (optional), I added mine with the \"",[26,349,350],{},"super user",[26,352,353],{},"role",[123,355,107,356,198,359,362],{},[26,357,358],{},"Time Zone",[26,360,361],{},"NTP"," configuration page appears next.",[123,364,365],{},"A summary of the basic settings configuration is shown, which can be edited again if needed.",[101,367,369],{"id":368},"security-topology","Security topology",[15,371,372,373,376,377,380,381,86],{},"In this section, we'll configure the ",[26,374,375],{},"internet zone",", the ",[26,378,379],{},"DMZ",", and the ",[26,382,383],{},"internal zone",[120,385,386,394,412],{},[123,387,388,389,391],{},"Next, you're asked whether to connect the internet zone to our local (internal) network.",[50,390],{},[271,392,393],{},"Personally, I connected the SRX to the internet, it sits in the DMZ zone of an Orange box.",[123,395,396,397,400,401,404,405,408,409],{},"Does internet access go through ",[26,398,399],{},"PPPoE"," on the SRX? Or ",[26,402,403],{},"DSL",", or ",[26,406,407],{},"none","? ",[271,410,411],{},"None, for me.",[123,413,414,415,56,418,421,422],{},"Is the ",[26,416,417],{},"IP",[26,419,420],{},"WAN",") address configuration dynamic or not? ",[271,423,424],{},"I use a static IP:",[15,426,427],{},[115,428],{"alt":117,"src":429},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002Fb618fc101a.png",[15,431,432],{},[271,433,434],{},"Remember, my SRX sits in a DMZ, so you'll notice Orange's DNS servers.",[120,436,437],{},[123,438,439,440,443],{},"For selecting the ",[26,441,442],{},"internet zone port",", we go with the default template, port fe-0\u002F0\u002F0.",[15,445,446],{},[115,447],{"alt":117,"src":448},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F98ea41fb48.png",[120,450,451,459],{},[123,452,453,454,456],{},"Next comes the creation and configuration of the DMZ zone, \"No\u002FYes\"?",[50,455],{},[271,457,458],{},"Personally, I don't need my SRX to create a DMZ zone.",[123,460,461,462,465,466,86],{},"We now move on to representing our internal network by ",[26,463,464],{},"selecting"," our ",[26,467,468],{},"diagram",[15,470,471],{},[115,472],{"alt":117,"src":473},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002Ffe1d85db98.png",[120,475,476],{},[123,477,478,481],{},[26,479,480],{},"Zone configuration"," appears; one zone per service can be created, here's an example:",[15,483,484],{},[115,485],{"alt":117,"src":486},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F390738bb04.png",[120,488,489],{},[123,490,491,492,495],{},"The next step is to configure our ",[26,493,494],{},"DHCP range"," for office employees:",[15,497,498],{},[115,499],{"alt":117,"src":500},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F6b294c6e18.png",[15,502,503,504,507],{},"A quick summary of the ",[26,505,506],{},"different zones"," created:",[15,509,510],{},[115,511],{"alt":117,"src":512},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002Fd6f6622f3d.png",[101,514,516],{"id":515},"security-policy","Security policy",[15,518,519,520,523,524,328,527,328,530,465,533,535,536,539,540,86],{},"The third step involves adding one or more ",[26,521,522],{},"UTM licenses"," (optional), ",[26,525,526],{},"defining",[26,528,529],{},"access",[26,531,532],{},"between",[26,534,506],{},", configuring the ",[26,537,538],{},"management"," interface, and ",[26,541,542],{},"remote access VPN",[15,544,545,546,548],{},"Activating purchased licenses can be done manually or downloaded directly via a code.",[50,547],{},[271,549,550],{},"In my case, I don't have a UTM license, so I just leave the defaults and continue.",[15,552,553,554,557,558,560],{},"Now let's move on to ",[26,555,556],{},"configuring traffic"," between our ",[26,559,506],{},":",[15,562,563],{},[115,564],{"alt":117,"src":565},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F69943bfed5.png",[15,567,568,328,583,588],{},[271,569,570,571,576,577,582],{},"For example, in the image above, we find the policy \"",[26,572,573],{},[26,574,575],{},"office_worker","\"\u002F",[26,578,579],{},[26,580,581],{},"mayor"," in action",[271,584,585],{},[26,586,587],{},"deny","*, since the employees' zone shouldn't be able to communicate with the mayor.*",[120,590,591,605],{},[123,592,593,594,597,598,86,600,602],{},"You can choose whether ",[26,595,596],{},"zones"," are allowed to access the SRX's ",[26,599,538],{},[50,601],{},[271,603,604],{},"The access protocols are: http\u002Fssh\u002Fnsm\u002Fhttps\u002Ftelnet, I chose a single zone: mayor.",[123,606,607,608,610],{},"The SRX asks whether a remote worker coming from the internet zone will be allowed to connect.",[50,609],{},"\nAs an example, I answered yes, here's the creation of my user \"ffonaissak.\"",[15,612,613],{},[115,614],{"alt":117,"src":615},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F1834005e05.png",[120,617,618],{},[123,619,620,621,623,328,626,328,631,328,634,328,639],{},"The rest of the remote user's configuration involves granting them access to available zones.",[50,622],{},[271,624,625],{},"I allowed the",[271,627,628],{},[26,629,630],{},"server",[271,632,633],{},"and",[271,635,636],{},[26,637,638],{},"printer",[271,640,641],{},"zones, they'll be able to access the server and print, which is practical!",[101,643,645],{"id":644},"sourcedestination-nat","Source\u002Fdestination NAT",[15,647,648,649,651,652,655],{},"Granting our different zones internet access is done through ",[26,650,211],{},", while ",[26,653,654],{},"destination NAT"," enables communication from the internet into our private network.",[120,657,658,671],{},[123,659,660,661,663,328,666,670],{},"Which zones will have access to the internet zone?",[50,662],{},[271,664,665],{},"I checked all zones, even",[271,667,668],{},[26,669,638],{},"*, since it also faxes.*",[123,672,673,674,676],{},"Next comes the option to set up destination NAT.",[50,675],{},[271,677,678],{},"I didn't configure destination NAT.",[15,680,681,684,685,688],{},[26,682,683],{},"Configuring the SRX100"," under the ",[26,686,687],{},"J-Web setup wizard"," is now complete.",[15,690,691],{},[115,692],{"alt":117,"src":693},"\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002Ffaf1a35e14.png",[15,695,696,697,261,700,702,703,186,706,708,709,257,712,86,715,717,718,721,722,724,725],{},"Access to the ",[26,698,699],{},"configuration interface",[26,701,264],{}," is now possible in the mayor's zone (",[26,704,705],{},"https",[50,707],{},"\nI now encourage you to explore the ",[26,710,711],{},"https management interface",[26,713,714],{},"SRX 100 under J-Web",[50,716],{},"\nNote that it's important to ",[26,719,720],{},"update"," the ",[26,723,28],{}," via the ",[94,726,729],{"href":727,"rel":728},"https:\u002F\u002Fwww.juniper.net\u002Fsupport\u002Fdownloads\u002F?p=srx100#sw",[98],"software download page.",[10,731,733],{"id":732},"conclusion","Conclusion",[15,735,736],{},"This walkthrough of the SRX100 via the J-Web \"setup wizard\" covers the basic settings, security topology (internet\u002FDMZ\u002Finternal zones), inter-zone policies, as well as source and destination NAT. The graphical interface makes accessible a configuration that would remain more complex via CLI, while still being well suited to the needs of a small business. This gateway provides a good entry point before getting familiar with the more complete CLI configuration of the SRX range.",{"title":117,"searchDepth":738,"depth":738,"links":739},2,[740,741,745,746,752],{"id":12,"depth":738,"text":13},{"id":20,"depth":738,"text":21,"children":742},[743],{"id":103,"depth":744,"text":104},3,{"id":171,"depth":738,"text":172},{"id":249,"depth":738,"text":250,"children":747},[748,749,750,751],{"id":276,"depth":744,"text":277},{"id":368,"depth":744,"text":369},{"id":515,"depth":744,"text":516},{"id":644,"depth":744,"text":645},{"id":732,"depth":738,"text":733},[754],"Réseau","\u002Fimages\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web\u002F1b4814003c.jpg",true,null,"2014-07-10","Discovering Juniper Network's SRX range. The SRX100, an affordable gateway for small businesses. First-boot configuration: \"setup wizard\" mode.","md",{},"\u002Fen\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web",[764],"certificat-junos-associe-jncia-junos",{"title":5,"description":759},"configuration-une-passerelle-srx100-sous-web","en\u002Fblog\u002Fconfiguration-une-passerelle-srx100-sous-web","FzvxTOAfsl2eZqihLVn_IQwlZqLIwDoXLIVE0cGUJ2k",[770,778,784,790,797,804,810,817],{"title":771,"path":772,"stem":773,"date":774,"cover":775,"categories":776,"children":-1},"My Feedback on Training at Greta-Viva5 in Valence: Work-Study, the Start of the Year, the Classes","\u002Fen\u002Fblog\u002Fle-temoignage-formation-greta-viva5-valence-alternance-rentree-les-cours","en\u002Fblog\u002Fle-temoignage-formation-greta-viva5-valence-alternance-rentree-les-cours","2014-09-01","\u002Fimages\u002Fblog\u002Fle-temoignage-formation-greta-viva5-valence-alternance-rentree-les-cours\u002Fe27f7627f8.jpg",[777],"Évènement",{"title":779,"path":780,"stem":781,"date":782,"cover":783,"categories":757,"children":-1},"Installing a Gandi SSL Certificate with Pound","\u002Fen\u002Fblog\u002Finstallation-certificat-ssl-gandi-avec-pound","en\u002Fblog\u002Finstallation-certificat-ssl-gandi-avec-pound","2014-08-12","\u002Fimages\u002Fblog\u002Finstallation-certificat-ssl-gandi-avec-pound\u002Fec4618d7ad.jpg",{"title":785,"path":786,"stem":787,"date":788,"cover":789,"categories":757,"children":-1},"Security Patches and Updates on VMware ESXi 5","\u002Fen\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi","en\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi","2014-07-15","\u002Fimages\u002Fblog\u002Fpatchs-securite-mises-jour-sous-vmware-esxi\u002Fd8c6089e77.png",{"title":791,"path":792,"stem":793,"date":794,"cover":795,"categories":796,"children":-1},"Migrating from Vyatta 6.6R1 to VyOS Hydrogen","\u002Fen\u002Fblog\u002Fmigration-vyatta-6r1-vers-vyos-hydrogen","en\u002Fblog\u002Fmigration-vyatta-6r1-vers-vyos-hydrogen","2014-07-14","\u002Fimages\u002Fblog\u002Fmigration-vyatta-6r1-vers-vyos-hydrogen\u002F8a3fd53886.png",[754],{"title":798,"path":799,"stem":800,"date":801,"cover":802,"categories":803,"children":-1},"Hack In Paris and Nuit du Hack, June 26-29, 2014","\u002Fen\u002Fblog\u002Fhack-paris-nuit-hack-juin-2014","en\u002Fblog\u002Fhack-paris-nuit-hack-juin-2014","2014-04-11","\u002Fimages\u002Fblog\u002Fhack-paris-nuit-hack-juin-2014\u002Fd1c6cbea4e.jpg",[777],{"title":805,"path":806,"stem":807,"date":808,"cover":809,"categories":757,"children":-1},"Configuring ruTorrent's Web Interface with Apache2","\u002Fen\u002Fblog\u002Fconfigurer-interface-web-rutorrent-avec-apache2","en\u002Fblog\u002Fconfigurer-interface-web-rutorrent-avec-apache2","2014-03-31","\u002Fimages\u002Fblog\u002Fconfigurer-interface-web-rutorrent-avec-apache2\u002F672919258b.png",{"title":811,"path":812,"stem":813,"date":814,"cover":815,"categories":816,"children":-1},"The Destruction of Net Neutrality Is Underway: Get Angry!","\u002Fen\u002Fblog\u002Fdestruction-neutralite-net-est-marche-indignez-vous","en\u002Fblog\u002Fdestruction-neutralite-net-est-marche-indignez-vous","2014-03-23","\u002Fimages\u002Fblog\u002Fdestruction-neutralite-net-est-marche-indignez-vous\u002Fddb702d91a.jpg",[777],{"title":818,"path":819,"stem":820,"date":821,"cover":822,"categories":757,"children":-1},"Jailing an SSH User on Linux","\u002Fen\u002Fblog\u002Femprisonner-utilisateur-ssh-sous-linux","en\u002Fblog\u002Femprisonner-utilisateur-ssh-sous-linux","2014-02-23","\u002Fimages\u002Fblog\u002Femprisonner-utilisateur-ssh-sous-linux\u002F5e5571284a.png",[824],{"id":825,"title":826,"body":827,"categories":886,"cover":888,"cover_contain":756,"credly_badge_id":889,"date":890,"description":891,"extension":760,"meta":892,"navigation":756,"path":893,"related_certifications":757,"seo":894,"slug":764,"stem":895,"__hash__":896},"blog\u002Fen\u002Fblog\u002Fcertificat-junos-associe-jncia-junos.md","Junos Associate (JNCIA-Junos)",{"type":7,"value":828,"toc":882},[829,831,834,837,874,877,879],[10,830,13],{"id":12},[15,832,833],{},"To confidently work on Juniper equipment for clients, I completed this Arrow course and obtained the JNCIA-Junos certification.",[15,835,836],{},"The \"Junos Associate (JNCIA-Junos)\" training path is designed for IT professionals in charge of computer networks.\nThe course catalog covers the following modules:",[120,838,839,844,849,854,859,864,869],{},[123,840,841],{},[26,842,843],{},"Networking fundamentals",[123,845,846],{},[26,847,848],{},"Junos OS fundamentals",[123,850,851],{},[26,852,853],{},"User interfaces",[123,855,856],{},[26,857,858],{},"Configuration basics",[123,860,861],{},[26,862,863],{},"Monitoring and maintaining operations",[123,865,866],{},[26,867,868],{},"Routing fundamentals",[123,870,871],{},[26,872,873],{},"Routing policy and firewall filters",[15,875,876],{},"The training takes about 3 days.\nYou should then allow around 1h30 for the certification exam itself: Junos Associate (JNCIA-Junos).",[10,878,733],{"id":732},[15,880,881],{},"This Arrow course covers networking fundamentals and the Junos OS, from basic configuration to routing and firewall filters. It validates a solid understanding of Juniper network equipment, useful for any professional in charge of network infrastructure administration. A certification that complements skills already acquired on other environments.",{"title":117,"searchDepth":738,"depth":738,"links":883},[884,885],{"id":12,"depth":738,"text":13},{"id":732,"depth":738,"text":733},[887,754],"Certifications","\u002Fimages\u002Fblog\u002Fcertificat-junos-associe-jncia-junos\u002F773018337d.png","907dbe59-515c-4d6b-9ce1-e40082c63c2e","2023-01-17","Junos Associate (JNCIA-Junos): Arrow course, completed as part of my professional watch in cybersecurity and IT.",{},"\u002Fen\u002Fblog\u002Fcertificat-junos-associe-jncia-junos",{"title":826,"description":891},"en\u002Fblog\u002Fcertificat-junos-associe-jncia-junos","xYQ66vuN9RwTPB6jnNJm-LxGXEEPDQ3Buj_X9Dx3_pg",1786644890893]