jimmy1829
asked on
HA on Juniper SRX650
Hi Experts,
I have a few questions regarding configuring HA on Juniper SRX650.
1. How do I remotely manage SRX650?
2. Is reth1.0 IP 1.2.0.233 actually the WAN IP in the network diagram in the KB article?
http://kb.juniper.net/InfoCenter/index?page=content&id=KB15503
Thanks,
Jimmy
I have a few questions regarding configuring HA on Juniper SRX650.
1. How do I remotely manage SRX650?
2. Is reth1.0 IP 1.2.0.233 actually the WAN IP in the network diagram in the KB article?
http://kb.juniper.net/InfoCenter/index?page=content&id=KB15503
Thanks,
Jimmy
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Nope. The fxp0 is ONLY for management bud. It cannot be used for transit traffic.
Clustering on srx requires 3 clustering interfaces. The mgmt link on fxp0 and also 2 sync connections for the control and data planes. None of these cluster links can be used for production traffic. It is a bit of a drawback that on the branch office devices you end up losing 3 revenue ports for the clustering but on the high end devices the mgmt and control connections are on specific ports.
Hth
Clustering on srx requires 3 clustering interfaces. The mgmt link on fxp0 and also 2 sync connections for the control and data planes. None of these cluster links can be used for production traffic. It is a bit of a drawback that on the branch office devices you end up losing 3 revenue ports for the clustering but on the high end devices the mgmt and control connections are on specific ports.
Hth
ASKER
Thanks again, and I guess I have a little confusion regarding "management"
Since fxp0 is for management, do I physically connect it somewhere?
If I want to configure the firewall via J-Web portal through the internet, what IP should use, and which port should I configure this IP on?
Jimmy
Since fxp0 is for management, do I physically connect it somewhere?
If I want to configure the firewall via J-Web portal through the internet, what IP should use, and which port should I configure this IP on?
Jimmy
The mgmt net is a net specifically designed for log and control traffic. Historically this was used in more service provider areas so that this extra traffic did not touch the production customer networks. You can still use the reth interfaces for j web and ssh but this will only ever take you to the active routing engine. That us why we use the fxp0 to allow us to connect to both nodes. P
ASKER
Then how do I physically connect fxp0 interfaces? For instance, I want to manage each individual node via internet.
Thanks!
Thanks!
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Great! Thanks deimark for the prompt answer!
I will give it a try, and let you know how everything goes.
I will give it a try, and let you know how everything goes.
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.
ASKER
So that means I need to configure a WAN IP on fxp0 for remote management, is that correct?