Configuring Virtual IP addresses on Juniper SSG

Posted on 2010-11-11
Medium Priority
Last Modified: 2012-05-10
I have a client that is moving away from a DS3 to a TW Telecom circuit. They specified they were told they no longer needed a router. The current configuration has a Cicso 6501 router going to the Juniper SSG 140. The new circuit is simply a switch at the customers location. Is it possible to create two virtual interaces and route between them to accomplish this. Would the config be similar to the one below:

set int e0/2.10 ip   (interface for ISP)
set int e0/2.10 route
set int e0/2.20 ip (customer firewall side)
set int e0/2.20 route
set route interface ethernet0/2.10 gateway

I am more accustom to having both the router and then the Juniper device.
Question by:Rodney Barnhardt
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3

Expert Comment

ID: 34117257
It sound like what you are trying to do is VLAN trunking on your ethernet 0/2.  You can run 2 sub-interfaces on one physical interface with VLAN trunking or tagging.  

Here is an example of a configuration I am using:

set zone id 100 "Internal1"
set zone id 101 "Internal2"

set interface "ethernet0/1.102" tag 102 zone "Internal1"
set interface "ethernet0/1.105" tag 205 zone "Internal2

set interface ethernet0/1.102 ip
set interface ethernet0/1.102 route
set interface ethernet0/1.105 ip
set interface ethernet0/1.105 route

I set my zones up in the first two commands.  The next 2 commands may the interface to the zone name.  The tag IDs are the VLAN numbers.  This interface
connects to a Cisco switch that is setup as a VLAN trunk, trunking VLANS 102 and 105.

LVL 32

Author Comment

by:Rodney Barnhardt
ID: 34120066
Yes, this may be what I am looking for. I do have a question though. The switch I am connecting to is provided by TW telecom to connect to, so I do not know that it is set up as a VLAN trunk. Basically, the IT director was told there would be no need for a router. However, they provided two sets of IP's. One with a CIDR of 30 (now presumably a router) and the other with a CIDR of 28 (the external IP's for services). Would this still work not knowing how TWC configures their end?

Expert Comment

ID: 34120442
If  the switch you are connecting to belongs to your ISP, you may not be able to share e0/2 with both the external and internal connection.  Their switch would need to support trunking and they would need to provide you wtih an additional port off their switch that would carry the internal connection to your LAN.  You could possible insert a switch of your own in between the firewall and their switch.  This switch would have a trunk port to e0/2 to our firewall, carrying both VLANs.  Then that switch would have one port going to your ISP switch and one port or many ports going to your internal LAN.  These ports would not be trunk ports, but would be access ports tagged for the appropriate VLANs.

As for the IP addressing question, it is most likely that the /30 subnet is a transit network between your firewall and the ISP router.  The additional block is probably going to be routed to your firewall.  You can check with the ISP, but this most likely the case.  The have probably given you an address in that /30 to setup on your firewall.  The /28 can than be used as a NAT pool or it can be configured on an internal interface and used as an actual subnet.  NAT however will allow you to conserve the address space and allow for more flexibility in the future when changing public IPs.  
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 32

Author Comment

by:Rodney Barnhardt
ID: 34124364
Well, if I am going to go to the trouble of adding a switch, I might as well place my own router. I have extra routers due to company downsizing. Typically, with our DS3, we had our own router that interfaced to the ISP with our /30 IP, then used the /28 for MIP\VIP's on our SSG. I guess we will just go with that same set up. TWC told the director we would just connect to our firewall without anyone asking specific questions.

Expert Comment

ID: 34125110
if you have a free interface on your firewall, you could separate out the 2 networks.  That way you could just connect the firewalls ISP facing network to the ISP.   The second interface would connect to your LAN.  I assumed that since you were trying to do it all on one interface, that you are short on firewall interfaces.
LVL 32

Accepted Solution

Rodney Barnhardt earned 0 total points
ID: 34227834
We just installed a router and configured it in between the firewall and the ISP.
LVL 32

Author Closing Comment

by:Rodney Barnhardt
ID: 34265387
We just used a router.

Featured Post

Ransomware Attacks Keeping You Up at Night?

Will your organization be ransomware's next victim?  The good news is that these attacks are predicable and therefore preventable. Learn more about how you can  stop a ransomware attacks before encryption takes place with our Ransomware Prevention Kit!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month12 days, 11 hours left to enroll

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question