Solved

Basic VLAN config on Juniper EX3200

Posted on 2013-06-24
7
1,837 Views
Last Modified: 2013-10-26
Hi

I have inherited a Juniper EX3200 switch and am trying to configure it for our small branch office.  There are no downstream managed switches at present.  Note that I am very new to switch configuration and especially Junos.

What I want to achieve is to have 3 VLANs ( Server, Desktop & Wifi) with one uplink (ge-0/0/23) from the switch to our DSL router, address 192.168.1.1.

I can create the VLANs and RVIs.  If I plug devices into ports which have VLANs assigned I can also ping the addresses of the RVIs, but can't get "outside" of the switch i.e. I can't ping 192.168.1.1.

I have been playing around with this for a few days, creating static routes and whatnot, but all to no avail.

So, I stripped everything back to barebones.  The attached config file basically creates a VLAN & RVI, and assigns it to port ge-0/0/22.  Port ge-0/0/23 is still the uplink but is a standard access port.  The rest of the ports have no VLAN assigned at present.

What else do I need to configure to be able to talk to the router and the outside world?  I'm sure it's something really simple that I'm missing.

Any help and perhaps sample configs would be much appreciated!  

Thanks
config.txt
0
Comment
Question by:MarkoIreland
  • 4
  • 3
7 Comments
 
LVL 32

Expert Comment

by:harbor235
ID: 39274343
Did you set a default route on the devices pointing to the appropriate vlan RVI?

Did you set up a static default route or use a dynamic routing protocol so you can route to 192.168.1.1 from the Juniper switch?


harbor235 ;}
0
 

Author Comment

by:MarkoIreland
ID: 39275343
Hi harbor235

Yes, I set the default route on each of the devices e.g. desktops, to point to the relevant RVI as the default gateway.

As for a static route, I created a route with 0.0.0.0 as the address and 192.168.1.1 (router) as the next hop.  However, this didn't seem to work.

Is it best to use a static route or dynamic routing in this situation?

Thanks
0
 
LVL 32

Expert Comment

by:harbor235
ID: 39275891
So you have several things going on here, the WIFI vlan is the only vlan I see defined properly and you have not assigned vlans to any port.

for example to assign a vlan to a port;

ge-0/1/2 {
        description "Test Port"
        unit 0 {
            family ethernet-switching;
                 port-mode access;
        vlan {
              members WIFI;
        }


Static Routing;

routing-options {
    static {
        route 0.0.0.0/0 next-hop 192.168.1.1;
    }


as so on, you see?


harbor235 ;}
0
6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

 

Author Comment

by:MarkoIreland
ID: 39275959
Hi harbor235

I thought I had configured port ge-0/0/22 as belonging to VLAN "Wifi", just for testing ( see extract from config below)?

vlans {
    Wifi {
        vlan-id 40;
        interface {
            ge-0/0/22.0;
        }
        l3-interface vlan.1;
    }
    default {
        l3-interface vlan.0;
    }
}

From a laptop connected to port ge-0/0/22 I can ping the RVI (192.168.4.1) and the switch address (192.168.1.10), but not the DSL router at 192.168.1.1.

Even if I add the static router it doesn't seem to make any difference.

Thanks
0
 
LVL 32

Expert Comment

by:harbor235
ID: 39276001
vlans {
    Wifi {
        vlan-id 40;
        interface {
            ge-0/0/22.0;
        }
        l3-interface vlan.1;
    }
    default {
        l3-interface vlan.0;


You created a layer 3 inerface ge-0/0/22.0 linked to vlan 1 - 192.168.4.1, not quite the same.

http://kb.juniper.net/InfoCenter/index?page=content&id=KB11000


harbor235 ;}
0
 

Accepted Solution

by:
MarkoIreland earned 0 total points
ID: 39588202
In the end the issue was caused by have no reciprocated static links on the router.
0
 

Author Closing Comment

by:MarkoIreland
ID: 39602394
Problem was solved by defining reciprocal routes.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

I see many questions here on Experts Exchange regarding switch port configurations and trunks. This article is meant for beginners in the subject to help to get basic knowledge about Virtual Local Area Network (VLAN (http://en.wikipedia.org/wiki/Vir…
I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now