Quantcast
Channel: All Routing posts
Viewing all articles
Browse latest Browse all 8688

NAT Juniper MS-MIC-16G

$
0
0

Hello,

 

We have a juniper mx5-t + MS-MIC-16G

 

 

Model: mx5-t
Junos: 15.1F6.9
JUNOS Base OS boot [15.1F6.9]
JUNOS Base OS Software Suite [15.1F6.9]
JUNOS Crypto Software Suite [15.1F6.9]
JUNOS Packet Forwarding Engine Support (MX80) [15.1F6.9]
JUNOS Web Management [15.1F6.9]
JUNOS Online Documentation [15.1F6.9]
JUNOS Services Application Level Gateways [15.1F6.9]
JUNOS Services Jflow Container package [15.1F6.9]
JUNOS Services Stateful Firewall [15.1F6.9]
JUNOS Services NAT [15.1F6.9]
JUNOS Services RPM [15.1F6.9]
JUNOS Services Captive Portal and Content Delivery Container package [15.1F6.9]
JUNOS Macsec Software Suite [15.1F6.9]
JUNOS Services Crypto [15.1F6.9]
JUNOS Services IPSec [15.1F6.9]
JUNOS Kernel Software Suite [15.1F6.9]
JUNOS Routing Software Suite [15.1F6.9]
Hardware inventory:
Item             Version  Part number  Serial number     Description
Chassis                                ASDFGHH             MX5-T
Midplane         REV 06   711-061451   ASDFGHH           MX5-T
PEM 0            Rev 06   740-028288   ASDFGHH        AC Power Entry Module
PEM 1            Rev 06   740-028288   ASDFGHH        AC Power Entry Module
Routing Engine            BUILTIN      BUILTIN           Routing Engine
TFEB 0                    BUILTIN      BUILTIN           Forwarding Engine Processor
  QXM 0          REV 08   711-028408   ASDFGHH           MPC QXM
FPC 0                     BUILTIN      BUILTIN           MPC BUILTIN
  MIC 0                   BUILTIN      BUILTIN           4x 10GE XFP
    PIC 0                 BUILTIN      BUILTIN           4x 10GE XFP
      Xcvr 1     D        NON-JNPR     ASDFGHH          XFP-10G-LR
      Xcvr 2              NON-JNPR     ASDFGHH          XFP-10G-LR
      Xcvr 3     REV 01   740-014290   ASDFGHH         XFP-10G-ER
  MIC 1          REV 02   750-061622   ASDFGHH           MS-MIC-16G
    PIC 2                 BUILTIN      BUILTIN           MS-MIC-16G
FPC 1                     BUILTIN      BUILTIN           MPC BUILTIN
  MIC 0          REV 36   750-028392   ASDFGHH           3D 20x 1GE(LAN) SFP
    PIC 0                 BUILTIN      BUILTIN           10x 1GE(LAN) SFP
      Xcvr 6     +sc      NON-JNPR     ASDFGHH         UNSUPPORTED
    PIC 1                 BUILTIN      BUILTIN           10x 1GE(LAN) SFP
      Xcvr 0     1        NON-JNPR     ASDFGHH         UNSUPPORTED
      Xcvr 6              NON-JNPR     ASDFGHH         UNSUPPORTED
Fan Tray                                                 Fan Tray

 

 

set firewall family inet filter NAT-VALID term VALID-A from prefix-list NAT-PREFIX-LIST
set firewall family inet filter NAT-VALID term VALID-A then accept
set firewall family inet filter NAT-VALID term OTHER-D then count NOT-NAT-PREFIXES-DISCARD
set firewall family inet filter NAT-VALID term OTHER-D then discard

set interfaces ms-0/2/0 unit 100 family inet filter input NAT-VALID
set interfaces ms-0/2/0 unit 100 family inet filter output NAT-VALID
set interfaces ms-0/2/0 unit 100 service-domain inside
set interfaces ms-0/2/0 unit 200 family inet
set interfaces ms-0/2/0 unit 200 service-domain outside

set services service-set NAT-SERVICE-SET nat-rules NAT-RULE
set services service-set NAT-SERVICE-SET next-hop-service inside-service-interface ms-0/2/0.100
set services service-set NAT-SERVICE-SET next-hop-service outside-service-interface ms-0/2/0.200

set services nat pool NAT-POOL-1 address 78.31.41.16/32
set services nat pool NAT-POOL-1 port automatic random-allocation

set services nat rule NAT-RULE match-direction input
set services nat rule NAT-RULE term 1 from source-prefix-list NAT-PREFIX-LIST
set services nat rule NAT-RULE term 1 then translated source-pool NAT-POOL-1
set services nat rule NAT-RULE term 1 then translated translation-type napt-44

set firewall family inet filter FOR-NAT-FBF term NAT-LOCAL-A from source-prefix-list NAT-PREFIX-LIST
set firewall family inet filter FOR-NAT-FBF term NAT-LOCAL-A from destination-prefix-list NAT-PREFIX-LIST
set firewall family inet filter FOR-NAT-FBF term NAT-LOCAL-A then count ACCEPT-LOCAL-NAT-TRAFFIC
set firewall family inet filter FOR-NAT-FBF term NAT-LOCAL-A then accept
set firewall family inet filter FOR-NAT-FBF term NAT-TO-RI-F from source-prefix-list NAT-PREFIX-LIST
set firewall family inet filter FOR-NAT-FBF term NAT-TO-RI-F then count FORWARD-TO-NAT-RI
set firewall family inet filter FOR-NAT-FBF term NAT-TO-RI-F then routing-instance NAT-RI
set firewall family inet filter FOR-NAT-FBF term ALL-A then count ACCEPT-OTHER-TRAFFIC
set firewall family inet filter FOR-NAT-FBF term ALL-A then accept

set forwarding-options family inet filter input FOR-NAT-FBF

set routing-instances NAT-RI instance-type virtual-router
set routing-instances NAT-RI interface ms-0/2/0.100
set routing-instances NAT-RI routing-options static route 0.0.0.0/0 next-hop ms-0/2/0.100
set routing-instances NAT-RI routing-options static route 10.113.18.0/24 next-table inet.0

 

 

show configuration interfaces ge-1/0/6
vlan-tagging;
unit 80 {
    description "TEST vlan 80";
    vlan-id 80;
    family inet {
        address 10.113.18.1/24;

    }
}

We want to set up NAT
With the following configuration
But traffic does not run through nat, please tell me what is wrong, or what is missing, thank you.

 


Viewing all articles
Browse latest Browse all 8688

Trending Articles