This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| network_stuff:juniper:srx [2016/02/05 20:45] – external edit 127.0.0.1 | network_stuff:juniper:srx [2023/11/02 14:38] (current) – external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 38: | Line 38: | ||
| Unrelated is the monitored interface priority. Basically the priority is subtracted from 255 (forget about the node priority! and there is a fail-over when the cumulative weights reach 0! | Unrelated is the monitored interface priority. Basically the priority is subtracted from 255 (forget about the node priority! and there is a fail-over when the cumulative weights reach 0! | ||
| + | ---- | ||
| + | **HARDWARE** | ||
| + | CHASSIS \\ | ||
| + | |||
| + | CARDS:\\ | ||
| + | * IOC: Input/ | ||
| + | * SCB: Switch Control Board: Monitors and interconnect IOCs | ||
| + | * NPC: Network Processing Card: One unit minimum. srx3000.Performs session lookup. To distribute inbound and outbound traffic to the SPCs/IOCs. Also QoS policy and shaping | ||
| + | * SPC: Services Processing Card:One unit minimum.They process all the services so doesn’t sit idle. SPC/SPU session management | ||
| + | * SPU: They are the SPC processors. Establish and manage traffic flows and perform most of the packet processing on a packet as it transits the device. Hash table for fast session lookup. | ||
| + | * RE: Routing Engine: Intel based PC platform. Runs JUNOS | ||
| + | |||
| + | ---- | ||
| + | **ETHERNET SWITCHING mode on SRX**\\ | ||
| + | |||
| + | * To Enable it in SRX 300 Series [[https:// | ||
| + | set protocols l2-learning global-mode switching | ||
| + | reboot | ||
| + | show ethernet-switching global-information | ||
| + | |||
| + | \\ | ||
| + | [[http:// | ||
| + | Create the l2 vlan-trust: | ||
| + | set vlans vlan-trust vlan-id 3 | ||
| + | Add interface vlan.0 L3]] interface | ||
| + | set vlans vlan-trust l3-interface vlan.0 | ||
| + | And put ip on it: | ||
| + | set interfaces vlan.0 family inet address 192.168.1.1/ | ||
| + | Add physical interfaces to vlan-trust | ||
| + | set interfaces ge-0/0/10.0 family ethernet-switching vlan members vlan-trust | ||
| + | \\ | ||
| + | * See different modes to configure and manage Layer 2 and bridge settings (bridge settings are needed for transparent mode, ready of it lately users family ethernet-switching options. See last section in transparent mode review document) | ||
| + | * See this link for differences between family bridge (uses flow mode (full set of security functionalities ) and family ethernet-switch (switch local)): [[http:// | ||
| + | |||
| + | |||
| + | ---- | ||
| + | **BGP SRX**\\ | ||
| + | To get inspiration: | ||
| + | \\ | ||
| + | See this [[https:// | ||
| + | * Disable flow mode and enable packet mode: [[http:// | ||
| + | configure | ||
| + | delete security | ||
| + | < confirm this will delete everything below this level> | ||
| + | set security forwarding-options family mpls mode packet-based | ||
| + | commit and-quit | ||
| + | request system reboot | ||
| + | |||
| + | * Define irb gateway | ||
| + | * policy options | ||
| + | * BOGON-LIST | ||
| + | * irb.1 148.64.57.1 / 254 (decide which one) | ||
| + | * vlans? | ||
| + | * irb export term (called iBGP-export in the slingshots) | ||
| + | |||
| + | Note that in packet mode, no security policies are allowed, no point on defining zones either.. [[http:// | ||
| + | |||
| + | |||
| + | If we are in flow mode, To allow communication: | ||
| + | Put all interfaces in the same zone: | ||
| + | |||
| + | set security zones security-zone trust interface ge-0/0/2.0 | ||
| + | set security zones security-zone trust interface ge-0/0/3.0 | ||
| + | |||
| + | Create a policy to permit intra-zone traffic. | ||
| + | |||
| + | set security policies from-zone trust to-zone trust policy trust-to-trust match source-address any destination address any application any | ||
| + | set security policies from-zone trust to-zone trust policy trust-to-trust then permit | ||
| + | |||
| + | |||
| + | ---- | ||
| + | |||
| + | **SRX DIRECTORIES**\\ | ||
| + | * /junos : This is a read-only dir created in runtime by malloc. Expected to be 100%. See [[https:// | ||
| + | |||