Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Problems getting Juniper SRX210 to communicate with Cisco3560

Posted on 2013-02-06
5
732 Views
Last Modified: 2013-04-12
Can someone send me steps to communicate with Cisco3560 interface gig0/1 with Juniper srx210 ge-0/0/0 unit 0 family inet address 192.168.10.1/27.  Can someone show me how to communicate through vlan example vlan 21 as well as trucking from Cisco3560 on another interface gig0/7 example to fe-0/0/7.
0
Comment
Question by:Alvin70
  • 3
  • 2
5 Comments
 
LVL 18

Expert Comment

by:deimark
ID: 38860531
An example of normal layer 3 interface config, ie only one IP address and no VLAN

ge-0/0/0 {
    unit 0 {
        family inet {
            address 192.168.254.1/24;
        }
    }
}

For a layer 3 interface with VLANs (to connect to a switch trunk port)

ge-0/0/0 {
    vlan-tagging;
    unit 10 {
        vlan-id 10;
        family inet {
            address 10.1.1.1/24;
        }
    }
    unit 20 {
        vlan-id 20;
        family inet {
            address 10.2.2.1/24;
        }
    }
}

Basically we set the interface to VLAN tagging and then create logical units underneath with VLAN IDs and IP addresses.  I would recommend keeping the logical unit number the same as the VLAN ID

We can acheive the same kind of results by configuring the interface in layer 2 mode , ie family ethernet-switching port mode trunk and then assign all required vlans to it.

This will also mean that you need to create vlan interfaces if you need layer 3 routing on the SRX.

HTH
0
 

Author Comment

by:Alvin70
ID: 38862448
For testing purposes what needs to be setup on the cisco 3560...Here is the information below I have on  Switch A
 
switchA(config)#interface gigbbit 0/1
switchA(config-if)#switchport mode trunk
switchA(config-if)#switchport trunk encapsulation dot1q
switchA(config-if)#switchport trunk native vlan 21
switchA(config-if)#switchport trunk allowed vlan 21,101

I have a test setup with my laptop.  I have my cat6 cable coming out of my laptop plugged into srx210 ge-0/0/0.   The Cisco switch 3560 interface gig0/1 is plugged  into ge-0/0/1 on srx210.  I also have a connection coming out of fe-0/0/7 to Cisco 3560 interface gig0/7.  I would like to get these interfaces communicating with trunking and static routes.  Any ip address can be used.


Thanks
0
 
LVL 18

Expert Comment

by:deimark
ID: 38863032
OK, so ge-0/0/0 is the normal layer 3 connection fro your laptop, so have this set up as foillows:

ge-0/0/0 {
    unit 0 {
        family inet {
            address 192.168.254.1/24;
        }
    }
}

For ge-0/0/1 connecting to the switch trunk configure it as follows:

ge-0/0/1 {
    vlan-tagging;
    unit 21{
        vlan-id 21;
        family inet {
            address 10.1.1.1/24;
        }
    }
    unit 101{
        vlan-id 101;
        family inet {
            address 10.2.2.1/24;
        }
    }
}

A similar set up for fe-0/0/7 and gig0/7 on the cisco would also do here.  Ensure that the VLANs and IPs are set correctly though.

Static routes can be added on the SRX under [ edit routing-options static ] similar to


[edit routing-options]
test@test# show
static {
    route 0.0.0.0/0 next-hop at-1/0/0.0;
    route 192.168.20.0/22 next-hop 10.1.2.2;
}

etc
0
 

Author Comment

by:Alvin70
ID: 38865917
The information above is not working. I am receiving the following error VLAN-ID must be specified on tagged ethernet interface.  

Can you please give me the configuration of what needs to be on the Cisco 3560?  No information was given concerning the connection

Here is my current setup:
1-I have a connection from srx210 ge0/0/0 to Cisco 3560gig0/1.
2-Connection from laptop...The ip address of the laptop is (192.168.254.5) with a gateway of (192.168.254.1) to SRX210 ge0/0/1
3-Connection from srx210 fe-0/0/7 to Cisco3560 Gig0/7.

What is the best way to get these devices talking.  I am missing something and I don't know what.  I am new to Juniper.

I also set fe-0/0/7 to trusted and ge-0/0/0 to untrusted.

Can someone just give me any generic ip address setup with the information above please.

Thanks for your continued support.  Sorry to be a headache.  
I am use to Cisco gear only.  
Once I get this test working I can then hookup srx650 and both srx210 for testing.
0
 
LVL 18

Accepted Solution

by:
deimark earned 500 total points
ID: 38865936
For the interface connected to ge-0/0/0 this just needs to be a normal layer 3 port (sorry havent used Cisco for years but if I recall its simply adding an IP address when configuring the interface)

For the ge-0/0/0 connecting to the cisco trunk, configure the cisco as a switch port with trunk mode and then allow the vlans
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Sbs2011 has been hacked. Foreign users in AD 7 154
Class Map is not matching traffic on Global Policy??? 2 52
palo alto VM series in AWS 3 116
Watchguard Firewall Setup 3 93
Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question