Description

Replacing a Failed Firewall in Juniper Networks NetScreen-Security Manager

Symptoms


Solution

Should a NetScreen device ever need to be sent back to the factory and replaced with a new device, the device status can be set to "RMA" in NSM. This allows NSM to retain the device configuration without a serial number or connection statistics.

While in the "RMA" state, the device object is functionally identical to a modeled device, but its status displays as "RMA" in the Device Monitor. All that is required to reactivate the device is the serial number of the replacement unit.

To replace a failed firewall in Juniper Networks NetScreen-Security Manager, perform the following steps:

alt Connect to the NetScreen-Security Manager. For more information on this, go to Connecting to the NetScreen-Security Manager [juniper.net] .

alt Expand Device Manager , and click to select FW/VPN Devices .

Image of step two


alt From the FW/VPN Device Tree tab, right-click the device to RMA, and click RMA Device .

Image of step three


alt From the Confirm RMA Device dialog box, click OK .

Image of step four


alt Expand Realtime Monitor , and click to select Device Monitor .

Image of step five


alt From the Device Monitor screen, locate the failed device and confirm the Config Status displays RMA .

Image of step six


alt When ready to activate the replacement unit, expand Device Manager , and click to select FW/VPN Devices .

Image of step seven


alt From the FW/VPN Device Tree tab, right-click the device, and click Activate Device .

Image of step eight


alt From the FW/VPN Device dialog box, click to select Device deployed and IP is reachable . Click Next .

Image of step nine

note Once the activation process has finished, NSM will push the saved device configuration to the replacement unit.

Former Article Id

ns10624