Solved

routing in Juniper EX4200

Posted on 2014-11-14
4
516 Views
Last Modified: 2014-12-01
I am new to Juniper switches and I am trying to understand the routing for this config. I got the following routing-options and the routing-instances in my config. How does it work?

The usergp2 is vlan200 10.10.200.0/24. I am not sure what usergp1 is as I could not find where it was defined.
10.10.200.2 and 10.10.10.2 are FWs. I am not sure what 10.10.10.3 is at this time.

routing-options {
    interface-routes {
        rib-group inet VRF-group;
    }
    static {
        route 0.0.0.0/0 next-hop 10.10.10.2;
    }
    rib-groups {
        VRF-group {
            import-rib [ inet.0 usergp1.inet.0 usergp2.inet.0 ];...
...
routing-instances {
    usergp2 {
        instance-type forwarding;
        routing-options {
            static {
                route 0.0.0.0/0 next-hop 10.10.200.2;
            }
        }
    }
    usergp1 {
        instance-type forwarding;
        routing-options {
            static {
                route 0.0.0.0/0 next-hop 10.10.10.3;
            }
        }
    }

Open in new window

0
Comment
Question by:leblanc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 32

Accepted Solution

by:
dpk_wal earned 167 total points
ID: 40445531
In Junos we configure static route and other settings related to static routing or route leake using rib groups under routing-options hierarchy.
http://www.juniper.net/documentation/en_US/junos13.2/information-products/pathway-pages/ex-series/routing-options.html

routing-instance is used to create VRF.
https://www.juniper.net/techpubs/en_US/junos14.1/topics/example/bridging-vrf-ex-series.html

Looks to me usergp1 and usergp2 are two distinct routing tables where the admin wanted to have different default route.

Something where we want traffic to egress ISP link1 and then other traffic out from ISP link2.

Please let us know if you need more details.

Thank you.
0
 
LVL 17

Assisted Solution

by:pergr
pergr earned 333 total points
ID: 40445636
In Cisco language, this configuration is part of Policy Based Routing.

There is probably a firewall list (ACL) applied to some interface or VLAN, which directs the traffic into these "instance-type forwarding" that will make a routing decision that is different than what the main routing table (inet.0) has.
0
 
LVL 1

Author Comment

by:leblanc
ID: 40445764
What confused me is when I did the traceroute 4.2.2.2 source with usergp2 IP address, I did not going through 10.10.200.2 FW, rather I was still going through 10.10.10.2 FW. Am I missing something? I am not sure how to locate match-internal & match-external. Thanks

firewall
family inet {
...
filter usergp2-internet {
            term match-internal {
                from {
                    destination-address {
                        10.10.28.0/24;
                      }
                }
                then accept;
            }
            term match-external {
                then {
                    routing-instance usergp2;
...

Open in new window

0
 
LVL 17

Assisted Solution

by:pergr
pergr earned 333 total points
ID: 40445774
You need to have a firewall list, saying that the source address of that user you get 'next table usergp2', and that firewall list must be applied to an interface.

Obviously, the 10.10.200.2 also need to be reachable.
0

Featured Post

Don't miss ATEN at NAB Show April 24-27!

Visit ATEN at NAB Show to learn how our "Seamlessly Entertaining" solutions deliver fast, precise video streaming without delays for the broadcasting and media environment. ATEN will showcase its 16x16 Modular Matrix Switch (VM1600) and KVM Over IP Solution (KE6900 series).

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Multicast on 3750x cisco router 1 57
impossible to connect to ex2013 from forein domain 9 37
eigrp routing loop 5 73
Password recovery 2960S 4 34
I wrote this article to help simplify the process of combining multiple subnets. This can be used for route summarization also but there are other better ways to summarize routes, This article is a result of questions I participate in here at Ex…
Hello to you all, I hear of many people congratulate AWS (Amazon Web Services) on how easy it is to spin up and create new EC2 (Elastic Compute Cloud) instances, but then fail and struggle to connect to them using simple tools such as SSH (Secure…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question