• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 508
  • Last Modified:

NSRP lite active/passive


I am having a pair of NS25 and has configured to run NSRP lite in active/passive mode with 1 ISP connection.  Each of the untrust interface connected to the ISP through the switch.  I would like to know if configure both untrust interface the same IP is a problem with NSRP lite version?  I have set to monitor both the untrust and trust interface in the same vsd-group.

  • 2
2 Solutions
For NSRP to work, anyways you need to have both interfaces with the same ip address since you have it in active/passive model right ? The config should be exactly same on both units except for the management ips.

I knew Rajesh with that new job would take some of my Juniper questions :) *poke Raj*
He's right :)

stuff needed in active/passive mode: meaning they share a virtual IP and each have there own manage ip
Cluster name:
VSD Group and priority
untrust interfaceces on both boxes same IP: set int ethX ip x.x.x.x/32
untrust interfaces on both boxes different management: set int ethX manage-ip x.x.x.(1 or 2)/32
a HA interface between the 2
cluster ID
:-) I just got my own 5gt on my desk so that I can play around and understand the differences...

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

WEBINAR: GDPR Implemented - Tips & Lessons Learned

Join the WatchGuard team on Thursday, March 29th as we recount some valuable lessons learned in weighing the needs of a business against the new regulatory environment, look ahead at the two months left before implementation, and help you understand the steps you can take today!

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now