Chapter 3 Configuring the Device
4 User’s Guide
DEFAULT SETTINGS
This section describes the default settings and operation of the NetScreen-5GT as it is
shipped from the factory. These default settings are such that, in most cases, there are
only a few items that you must configure. The figure below shows the default
configuration for the NetScreen-5GT.
The Untrust interface is bound to the Untrust zone and is configured with the IP address
0.0.0.0/0. To allow the NetScreen-5GT (and the devices on your network) to connect to the
Internet, you must configure the Untrust interface according to information obtained
from your Internet Service Provider (ISP). Refer to “Untrust Interface Address” on page 5.
Any user in the subnetwork can manage the NetScreen-5GT if they know the login and
password. To change the default login and password, refer to “Admin Name and
Password” on page 5. To restrict management of the NetScreen-5GT to specific
workstations, refer to “Restricting Management” on page 6.
The Trust interface is bound to the Trust zone and is configured with the subnetwork
address 192.168.1.1/24. This means that all devices in your network that you connect to
the Trust interface must be in the same subnetwork and have IP addresses in that
subnetwork. The NetScreen-5GT is also configured to assign IP addresses for the
192.168.1.1/24 subnetwork to your devices. For more information, refer to “Trust Interface
Address” on page 6.
The NetScreen-5GT allows any type of traffic to the Internet that originates from devices
in your network, but does not allow any traffic that originates in the Internet to reach
your network. You can configure additional restrictions; refer to “Additional Policies” on
page 7.
Trust Interface
192.168.1.1/24
Untrust Interface
0.0.0.0/0
Trust Zone
Untrust Zone
To Internet
The NetScreen-5GT
assigns IP addresses to
devices in your network
via DHCP. Addresses are
in the range 192.168.1.33
- 192.168.1.126.
WebUI and Telnet access to the NetScreen-5GT allowed from any device in the subnetwork.
All types of traffic
originated from your
network is allowed to the
Internet, but traffic
originated from the
Internet is not allowed to
your network.
External Router
Hub
Artisan Technology Group - Quality Instrumentation ... Guaranteed | (888) 88-SOURCE | www.artisantg.com