HP LST1FW3A1 User manual

Manual Version: 6P103-20130916 BOM:
3123A0MN
Part number: 5998-3444
1
HP 12500 20Gbps VPN Firewall module (JG371A)
1 Module introduction
The LST1FW3A1 (JG371A) module integrates the firewall, VPN, content filtering, and NAT functions. By
installing an LST1FW3A1 (JG371A) module in a 12500 switch, you can provide complete and reliable
security protection for users, without changing the network topology.
Figure 1 LST1FW3A1 (JG371A) firewall module
2 Specifications
Figure 2 Front panel of the LST1FW3A1 (JG371A) module
(1) Console port (CONSOLE) (2)
USB
ports (hardware reserved, software not supported)
(3) 10/100/1000BASE-T copper combo
port
(4) 10/100/1000BASE-T copper combo port LED (LINK/ACT)
(5) 1000BASE-X fiber combo port (6) 1000BASE-X fiber combo port LED (LINK/ACT)
(7)
A
larm LED (ALM) (8)
System LED (RUN)
(9) Ejector lever (10)
Captive screw
Table 1 Module specifications
Item S
p
ecification
Flash 4 MB
Memory
DDR3 SDRAM
2 memory slots
Standard: 16 GB (two 8-GB memory cards)

Manual Version: 6P103-20130916 BOM:
3123A0MN
Part number: 5998-3444
2
Item S
p
ecification
CF card One built-in CF card slot
Default: 256 MB
Dimensions (H × W × D) 40.1 × 399.2 × 498.8 mm (1.58 × 15.72 × 19.64 in)
Power consumption 128 W to 168 W
Weight 4.8 kg (10.58 lb)
Hot swapping Supported
Interfaces
•1 console port
•2 USB ports (hardware reserved, software not supported)
•2 combo interfaces, which can operate in 10/100/1000BASE-T copper port
mode or 1000BASE-X SFP fiber port mode at a time.
You can use the combo enable { copper | fiber } command to activate either
port. By default, the copper combo port is activated.
Ambient temperature
•Operating: 0°C to 45°C (32°F to 113°F)
•Not operating: –40°C to +70°C (–40°F to +158°F)
Ambient relative humidity
•Operating: 10% to 95%, noncondensing
•Non-operating: 5% to 95%, noncondensing
Compatible device models
and slots
•12504 switches (slot 2 to slot 5)
•12508 switches (slot 2 to slot 9)
•12518 switches (slot 2 to 19)
Table 2 Console port specifications
Item S
p
ecification
Connector RJ-45
Interface standard RS-232
Transmission baud rate 9600 bps (default) to 115200 bps
Transmission medium Asynchronous serial cable
Transmission distance ≤15 m (49.21 ft)
Services
•Provides connection to an ASCII terminal.
•Provides connection to the serial port of a local or remote (through a
pair of modems) PC running terminal emulation program.
•Supports command line interface (CLI)
Table 3 10/100/1000BASE-T copper port specifications
Item S
p
ecification
Connector RJ-45
Interface standard 802.3, 802.3u, and 802.3ab
Interface type MDI/MDIX autosensing
Supported cable Category-5 (or above) twisted pair cable
Transmission distance 100 m (328.08 ft)

Manual Version: 6P103-20130916 BOM:
3123A0MN
Part number: 5998-3444
3
Item S
p
ecification
Port transmission rate
•10 Mbps, half/full duplex
•100 Mbps, half/full duplex
•1000 Mbps, full duplex
Table 4 1000BASE-X fiber port specifications
Item S
p
ecification
Transceiver module SFP
Connector type LC
Interface standard 802.3, 802.3u, and 802.3ab
Transmit
power
Module
type
Multi-mode
short-haul
(850 nm)
Single mode
medium-haul
(1310 nm)
Long-haul
(1310 nm)
Long-haul
(1550 nm)
Ultra-long-haul
(1550 nm)
Min. –9.5 dBm –9 dBm –2 dBm –4 dBm –4 dBm
Max. 0 dBm –3 dBm 5 dBm 1 dBm 2 dBm
Receive sensitivity –17 dBm –20 dBm –23 dBm –21 dBm –22 dBm
Central wave length 850 nm 1310 nm 1310 nm 1550 nm 1550 nm
Fiber type
62.5/125 μm
multi-mode
fiber
9/125 μm
single mode
fiber
9/125 μm
single mode
fiber
9/125 μm
single mode
fiber
9/125 μm
single mode
fiber
Max. transmission
distance
0.55 km (0.34
miles)
10 km (6.21
miles)
40 km (24.86
miles)
40 km
(24.86 miles)
70 km (43.50
miles)
Operating mode 1000 Mbps, full duplex
3 LEDs
The LST1FW3A1 (JG371A) module provides LEDs to show the operating status of the module and
interfaces.
Table 5 LED description
LED Status Descri
p
tion
Alarm LED (ALM)
Off The system is operating properly.
Steady red A serious failure has occurred. Read the system log for
troubleshooting.
System LED (RUN)
Off No power input or the module is faulty.
Steady green The system is not operating properly.
Flashing green (1 Hz) The system has started up and is operating properly.
Flashing green (8 Hz) The system is loading the software or is not operating.
Combo interface
LED (LINK/ACT)
Off No link is present on the port.
Steady green A link is present on the port.
Flashing green The port is sending or receiving data.

Manual Version: 6P103-20130916 BOM:
3123A0MN
Part number: 5998-3444
4
4 Installing and removing the LST1FW3A1 (JG371A) module
CAUTION:
•Wear a well-grounded ESD-preventive wrist strap before you install or remove the module.
•Do not touch the surface-mounted components directly with your hands when you install or remove the
module.
4.1 Installing the LST1FW3A1 (JG371A) module
1. Face the front panel of the switch.
2. Identify the slot to install the module, and remove the filler panel from the slot.
This manual uses slot 7 as an example.
3. Place the module vertically with the surface-mounted components facing left. Pull outward the
ejector levers and gently push the module in along the slot guide rails until the module is in close
contact with the backplane. (See callout 1 in Figure 3.)
4. Push the ejector levers inward. (See callout 2 in Figure 3.)
5. Tighten the captive screws with a Phillips screwdriver to secure the module in the slot. (See callout
3 in Figure 3.)
Figure 3 Installing an LST1FW3A1 (JG371A) module
(1) Gently push the module in along the slot guide rails until the module is in close contact with the backplane.
(2) Push the ejector levers inward. (3) Ti
g
hten the captive
screws
with a Phillips screwdriver.
(4) Installation is finished.

Manual Version: 6P103-20130916 BOM:
3123A0MN
Part number: 5998-3444
5
4.2 Removing the LST1FW3A1 (JG371A) module
1. Use a Phillips screwdriver to loosen the captive screws at both sides of the module until all pressure
is released.
2. Pull the ejector levers at both sides of the module outward, and pull the module along the guide
rails until it completely comes out of the backplane.
3. Place the module on an anti-static workbench with the surface-mounted components up, or put it in
an anti-static bag.
4. If no new module is to be installed, install a filler panel to prevent dust and ensure good ventilation
in the switch.
5 Logging in to the LST1FW3A1 (JG371A) module
Log in to the module through Open Application Platform (OAP).
Table 6 Log in to the module through OAP
Task Command
Remarks
Log in to the module
through OAP.
•In standalone mode:
oap connect slot slot-number
•In IRF mode:
oap connect chassis chassis-number slot
slot-number
Available in user view of the
switch.
To return to the CLI interface of the
switch, press Ctrl+K.
NOTE:
Besides this login method, you can also log in to the firewall module through Web, Telnet, SSH, or console
port. For more information about these login methods, see
HP VPN Firewall Appliances Configuration
Guides
.
6 Software upgrade
You can upgrade the LST1FW3A1 (JG371A) module software through its console port or Ethernet ports.
The LST1FW3A1 (JG371A) module uses a different BootWare and system software image than the
switch. You can upgrade the system software image of the module by using the following methods:
6.1 Upgrading software in the Web interface
You can use the following default settings to log in to the Web interface through HTTP:
•Username—admin
•Password—admin
•IP address of the Ethernet port GigabitEthernet 0/1— 19 2.16 8 .0 .1 / 24 .
To upgrade software in the Web interface, select Device Management > Software Upgrade from the
navigation tree, and perform related configurations on the page.
The software upgrade process takes some time. During the upgrade process, do not perform any
operation in the Web interface. Otherwise, software upgrade may be interrupted.

Manual Version: 6P103-20130916 BOM:
3123A0MN
Part number: 5998-3444
6
6.2 Upgrading software at the CLI
Upgrade the software by using FTP/TFTP through the module's Ethernet port.
6.3 Upgrading software from the boot menu
•Using XMODEM to upgrade software through the console port.
•Using FTP/TFTP to upgrade software through the Ethernet port.
7 Obtaining documentation
For software upgrade, see the HP Security Modules Software Upgrade Guide.
To find related documents, browse to the Manuals page of the HP Business Support Center website:
http://www.hp.com/support/manuals
© Copyright 2013 Hewlett-Packard Development Company, L.P.
The information in this document is subject to change without notice.
5998-3444
This manual suits for next models
1
Table of contents
Other HP Firewall manuals
Popular Firewall manuals by other brands

Watchguard
Watchguard SOHO Features guide

Watchguard
Watchguard Firebox T30 quick start guide

PaloAlto Networks
PaloAlto Networks PA-4000 Series reference guide

Fortinet
Fortinet FortiGate 5140-R Chassis guide

ZyXEL Communications
ZyXEL Communications ZyWALL SEM-DUAL user guide

Cisco
Cisco 5580-40 - ASA Firewall Edition Hardware installation guide

websense
websense V10000 quick start guide

Draytek
Draytek Vigor2866 Series quick start guide

SonicWALL
SonicWALL NSA E7500 Getting started guide

NetScreen Technologies
NetScreen Technologies 5GT user guide

D-Link
D-Link DFL-210 - NetDefend - Security Appliance user manual

SMC Networks
SMC Networks ELITECONNECT SMC2504W overview