Re: Need An Advice
I'm still not sure I understand the goal, so forgive me if this is the wrong direction. I think you want internal gateways and routing on the MX and the MX to also handle and sort the internet traffic...
View ArticleRe: device Routing over IPSec VPN
I can't find documentation to verify, but my recollection is that you can't hit a source nat rule with self traffic when I've tried that in the past.
View ArticleRe: Need An Advice
I am sorry maybe i've described wrong let me tell you what i need and what we have we have 1x MX80 2xSRX3600 1xEx4500 30xEx4200 (10G connected to Ex 4500)Conditions : SRX needs to see return...
View ArticleRe: Need An Advice
ISP -------- VR1 A ----- SRX/UDP FW -------- VR1 B return -------- VR2 (Vlans / Static routes ....etc) ------ EX4500 Yes that should be the solution : For the internal gateways, you might...
View ArticleRe: device Routing over IPSec VPN
ok. I see. So exactly what address is needed as the source address? Where does he want the source address to come from? Where is the address configured on teh SRX that he wants to use as the source?He...
View ArticleRe: Need An Advice
You can build your desired setup with the two VR but you will need to have a pair of interfaces put in the two VR and loop those two tegether in this configuration. There are some internal connection...
View ArticleRe: Need An Advice
I've checked them and start building config but just need a little help how should i put a firewall filter on R1's input traffic that comes from R2 to R1 chassis { aggregated-devices { ethernet {...
View ArticleRe: Need An Advice
Your issue is that you really can't apply a filter when you make the connection between R1 and R2 via instance import. To use the filtering methods you will need to assign one interface to R1 and...
View ArticleRe: Need An Advice
We do not have empty interface but should we create virtual interface on MX80 ?
View ArticleRe: Need An Advice
You can use logical tunnel interfaces to make the internal connection between the VR. But I don't believe you will be able to apply the filters on these interfaces. You can give it a shot. And it...
View ArticleRe: Need An Advice
Wonderfull idea !!!!!!O think it should work let me complete the config , so i have 2 last questions , do you think it is better to complete BGP under R1 or general config ? I am working with virtual...
View ArticleRe: Need An Advice
I assume you will be creating your VLAN gateway addresses on the MX VR based on this. On the EX we use RVI for this on the MX you will be creating IRB interfaces. You will assign the IRB interface to...
View Articlevirtual-router routing issue
we want to route the 10.100.101.0/24 to 10.0.8.18 but it does not show up on the route table root@mx80-core# show routing-instances r1 instance-type virtual-router; interface lt-0/0/0.0; interface...
View ArticleRe: device Routing over IPSec VPN
[edit] root# set interfaces vlan.10 family inet primary [edit] root# [edit] root# commit check configuration check succeeds [edit] root# commit confirmed 5 commit confirmed will be automatically rolled...
View ArticleRe: device Routing over IPSec VPN
I did confrim that's what's going on though: root# run show interfaces Physical interface: ge-0/0/0, Enabled, Physical link is Up Interface index: 134, SNMP ifIndex: 508 Link-level type: Ethernet, MTU:...
View ArticleRe: device Routing over IPSec VPN
set interfaces vlan.10 unit 10 family inet address 172.27.2.1/24 primary
View ArticleRe: device Routing over IPSec VPN
I had to keep 172.27.2.1 on the vlan interface, it's the gateway for the network. I found a solution along those lines though, I set up an unnumbered address statement to reference the VLAN IP, and it...
View ArticleRe: device Routing over IPSec VPN
Great! I was about to suggest that, but I have never used it and was kind of unsure if it could be used in that situation. Thanks for the update. I can keep this information for future use case. Go...
View ArticleRe: device Routing over IPSec VPN
I've never used an unnumbered loopback either. Normally I would just assign a loopback interface IP and call it good, but I'd have to add it to the ASA on the other end. I don't want to touch that...
View ArticleRe: I've LOOKED AND LOOKED AND LOOKED AND LOOKED for two years now. j2350...
Hello- I just emailed you to your hotmail account. Thank you!Julie
View Article