This is an old revision of the document!
SRX
To see what policy is being hit by a flow:
show security match-policies ? Possible completions: destination-ip Match policy for the given destination IP destination-port Match policy for the given destination port) (1..65535)
[…]
source-port Match policy for the given source port) (1..65535) to-zone Match policy for the given destination zone
Packet processing chain: SRX vs J-Series (Important to notice that, in j series, all nat happens after policy and routing):
CLUSTER - HACheck logs :show log jsrpd To log into shell/cli from the pair node:
rlogin -Jk -T node1
To force the failover to node 1 request chassis cluster failover node 1 redundancy-group 1
Normally, after force failover, we reset the priority values to the ones determined in the config: request chassis cluster failover reset redundancy-group 1
redundancy-group 1 {
node 0 priority 100;
node 1 priority 99;
This priority is only used when two devices come up at the exact same time or when preempt is enabled. (see this link)
Unrelated is the monitored interface priority. Basically the priority is subtracted from 255 (forget about the node priority! and there is a fail-over when the cumulative weights reach 0!
HARDWARE
CHASSIS
CARDS:
ETHERNET SWITCHING mode on SRX
set vlans vlan-trust vlan-id 3
set vlans vlan-trust l3-interface vlan.0
set interfaces vlan.0 family inet address 192.168.1.1/24
set interfaces ge-0/0/10.0 family ethernet-switching vlan members vlan-trust