[not working ]POGO E02 to Openwrt

image_pdfimage_print

Inspired by

https://wiki.openwrt.org/toh/seagate/dockstar

On tftp server the following files

kirkwood-pogo_e02-u-boot.bin
kirkwood-pogoe02-zImage
kirkwood-pogo_e02.dtb
kirkwood-pogoe02-rootfs.ubifs
kirkwood-pogo_e02-u-boot.kwb

 

https://downloads.openwrt.org/chaos_calmer/15.05/kirkwood/generic/uboot-kirkwood-pogo_e02/openwrt-kirkwood-pogo_e02-u-boot.bin
https://downloads.openwrt.org/chaos_calmer/15.05/kirkwood/generic/openwrt-15.05-kirkwood-pogoe02-rootfs.ubifs
https://downloads.openwrt.org/chaos_calmer/15.05/kirkwood/generic/openwrt-15.05-kirkwood-pogo_e02.dtb
https://downloads.openwrt.org/chaos_calmer/15.05/kirkwood/generic/openwrt-15.05-kirkwood-pogoe02-zImage
https://downloads.openwrt.org/chaos_calmer/15.05/kirkwood/generic/uboot-kirkwood-pogo_e02/openwrt-kirkwood-pogo_e02-u-boot.kwb

On U-boot, set up partitions

PogoE02> mtdparts delall
PogoE02> mtdparts
mtdparts variable not set, see 'help mtdparts'
no partitions defined

Upgrade U-boot via tftp: Get single stage bootloader.

U-Boot 2014.10 (Jul 24 2015 - 20:11:30)
Pogo E02

SoC:   Kirkwood 88F6281_A0
DRAM:  256 MiB
WARNING: Caches not enabled
NAND:  128 MiB
In:    serial
Out:   serial
Err:   serial
Net:   egiga0
Hit any key to stop autoboot:  0
PogoE02>
PogoE02> mw 0x800000 0xffff 0x80000
PogoE02> tftpboot 0x800000 openwrt-kirkwood-pogo_e02-u-boot.kwb
Using egiga0 device
TFTP from server 192.168.12.186; our IP address is 192.168.12.124
Filename 'openwrt-kirkwood-pogo_e02-u-boot.kwb'.
Load address: 0x800000
Loading: ################################
         3.8 MiB/s
done
Bytes transferred = 457084 (6f97c hex)
PogoE02> nand erase 0x0 0xa4fff

NAND erase: device 0 offset 0x0, size 0xa4fff
Erasing at 0xa0000 -- 100% complete.
OK
PogoE02> nand write.e 0x800000 0x0 0x80000

NAND write: device 0 offset 0x0, size 0x80000
 524288 bytes written: OK
PogoE02> setenv bootcmd nand read.e 0x2000000 0x100000 0x400000\; go 0x2000000
PogoE02> saveenv
Saving Environment to NAND...
Erasing NAND...
Erasing at 0xe0000 -- 100% complete.
Writing to NAND... OK
PogoE02>

Install rootfs

setenv mtdids         nand0=orion_nand
setenv mtdparts       mtdparts=orion_nand:0xe0000@0x0(uboot),0x20000@0xe0000(uboot_env),0x100000@0x100000(second_stage_uboot),-@0x200000(root)
setenv bootargs_root  ubi.mtd=3 root=ubi0:rootfs rootfstype=ubifs rw
setenv bootcmd        'setenv bootargs ${console} ${mtdparts} ${bootargs_root}; ubi part root; ubifsmount ubi:rootfs; ubifsload 0x800000 ${kernel}; ubifsload 0x700000 ${fdt}; ubifsumount; fdt addr 0x700000; fdt resize; fdt chosen; bootz 0x800000 - 0x700000'
setenv fdt            /boot/pogo_e02.dtb
setenv kernel         /boot/zImage
saveenv
PogoE02> setenv bootcmd 'setenv bootargs ${console} ${mtdparts} ${bootargs_root}; ubi part root; ubifsmount ubi:rootfs; run ubifinish1'
PogoE02> setenv ubifinish1 'ubifsload 0x800000 ${kernel}; ubifsload 0x700000 ${fdt}; ubifsumount; run ubifinish2'
PogoE02> setenv ubifinish2 'fdt addr 0x700000; fdt resize; fdt chosen; bootz 0x800000 - 0x700000'
PogoE02> saveenv


setenv bootcmd 'setenv bootargs ${console} ${mtdparts} ${bootargs_root}; ubi part root; ubifsmount ubi:rootfs; run ubiboot_n1'
setenv ubiboot_n1 'ubifsload 0x800000 ${kernel}; ubifsumount; bootz 0x800000'

Delete and create

PogoE02> nand erase 0x200000 0x7e00000

NAND erase: device 0 offset 0x200000, size 0x7e00000
Skipping bad block at  0x07c40000
Erasing at 0x7fe0000 -- 100% complete.
OK
PogoE02> ubi part root
UBI: attaching mtd1 to ubi0
UBI: scanning is finished
UBI: empty MTD device detected
UBI: attached mtd1 (name "mtd=3", size 126 MiB) to ubi0
UBI: PEB size: 131072 bytes (128 KiB), LEB size: 129024 bytes
UBI: min./max. I/O unit sizes: 2048/2048, sub-page size 512
UBI: VID header offset: 512 (aligned 512), data offset: 2048
UBI: good PEBs: 1007, bad PEBs: 1, corrupted PEBs: 0
UBI: user volume: 0, internal volumes: 1, max. volumes count: 128
UBI: max/mean erase counter: 1/0, WL threshold: 4096, image sequence number: 0
UBI: available PEBs: 984, total reserved PEBs: 23, PEBs reserved for bad PEB handling: 19
PogoE02> ubi create rootfs 0xA00000
Creating dynamic volume rootfs of size 10485760

tftp boot

PogoE02> tftpboot 0x800000 openwrt-15.05-kirkwood-pogoe02-rootfs.ubifs
Using egiga0 device
TFTP from server 192.168.12.186; our IP address is 192.168.12.124
Filename 'openwrt-kirkwood-pogoe02-rootfs.ubifs'.
Load address: 0x800000
Loading: #################################################################
         #################################################################
         #################################################################
         ########
         3.5 MiB/s
done
Bytes transferred = 2967552 (2d4800 hex)
PogoE02> ubi write 0x800000 rootfs ${filesize}
2967552 bytes written to volume rootfs
PogoE02> ubi create rootfs_data
No size specified -> Using max size (116379648)
Creating dynamic volume rootfs_data of size 116379648
PogoE02>

tftp zImage

setenv bootargs ${console} ${mtdparts} ${bootargs_root}
PogoE02> tftpboot 0x800000 openwrt-15.05-kirkwood-pogoe02-zImage


PogoE02> bootz 0x800000;

afterboot

root@OpenWrt:/# mkdir -p /rom/boot
wget -O /rom/boot/pogo_e02.dtb http://downloads.openwrt.org/chaos_calmer/15.05/kirkwood/generic/openwrt-15.05-kirkwood-pogo_e02.dtb
wget -O /rom/boot/zImage       http://downloads.openwrt.org/chaos_calmer/15.05/kirkwood/generic/openwrt-15.05-kirkwood-pogoe02-zImage

root@OpenWrt:/# reboot
root@OpenWrt:/# [  203.640952] reboot: Restarting system

Cisco Small Bussiness SG-300-10 Update firmware

image_pdfimage_print

 

Check Current version


Sttus and Statistics > System Summary.

Current version: 1.3.0.59

 

 

From release notes


When upgrading the device from version prior to 1.3.5:

For Sx200/Sx300 models, first upgrade the device image to image version 1.3.5.x and upgrade the boot file to 1.3.5.06

 

Upload version 1.3.5.8 and boot file


Administration > File Management > Upgrade/Backup Firmware

Upload sx300_fz-13558.ros via HTTP

 

Upload sx300_boot-13506.rfb via TFTP

Change the Active Image on

File Management > Active Image

Reboot

Upgrade to 1486


 

select active image and reboot

 

 

 

[EX2200] WARNING: THIS DEVICE HAS BOOTED FROM THE BACKUP JUNOS IMAGE

image_pdfimage_print

Message after logging in


--- JUNOS 12.3R12.4 built 2016-01-20 04:27:03 UTC

***********************************************************************
**                                                                   **
**  WARNING: THIS DEVICE HAS BOOTED FROM THE BACKUP JUNOS IMAGE      **
**                                                                   **
**  It is possible that the primary copy of JUNOS failed to boot up  **
**  properly, and so this device has booted from the backup copy.    **
**                                                                   **
**  Please re-install JUNOS to recover the primary copy in case      **
**  it has been corrupted and if auto-snapshot feature is not        **
**  enabled.                                                         **
**                                                                   **
***********************************************************************

{master:0}
root@STOCKELA-SW-EX01> show system alarms
2 alarms currently active
Alarm time               Class  Description
2017-10-25 02:23:19 CEST Minor  Host 0 Boot from backup root

 

 

Repair primary partition


root@STOCKELA-SW-EX01:RE:0% cli
{master:0}
root@STOCKELA-SW-EX01> request system snapshot media internal slice alternate
fpc0:
--------------------------------------------------------------------------
Formatting alternate root (/dev/da0s1a)...
Copying '/dev/da0s2a' to '/dev/da0s1a' .. (this may take a few minutes)
The following filesystems were archived: /

{master:0}
root@STOCKELA-SW-EX01> show system storage partitions
fpc0:
————————————————————————–
Boot Media: internal (da0)
Active Partition: da0s1a
Backup Partition: da0s2a
Currently booted from: backup (da0s2a)

Partitions information:
Partition Size Mountpoint
s1a 183M altroot
s2a 184M /
s3d 369M /var/tmp
s3e 123M /var
s4d 62M /config

Rgo back to Primary partition


{master:0}
root@STOCKELA-SW-EX01> request system reboot slice alternate media internal
Reboot the system ? [yes,no] (no) yes

Shutdown at Wed Oct 25 02:38:15 2017.
[pid 1546]

{master:0}
root@STOCKELA-SW-EX01>
*** System shutdown message from root@STOCKELA-SW-EX01 ***

System going down in 1 minute

 

References


 

Juniper

Pogoplug troop

image_pdfimage_print
  • 9 Pogoplugs
  • 3 Cisco sg-300 (factory defaulted)
  • 1 dhcp server.

 

Hosts


 

Nmap scan report for firewall.prod.youaresecure.be (192.168.12.1)
Nmap scan report for avayaswitch.prod.youaresecure.be (192.168.12.7)
Nmap scan report for dns.prod.youaresecure.be (192.168.12.10)
Nmap scan report for 192.168.12.21
Nmap scan report for 192.168.12.26
Nmap scan report for 192.168.12.27
Nmap scan report for 192.168.12.28
Nmap scan report for wlc.prod.youaresecure.be (192.168.12.30)
Nmap scan report for kali.prod.youaresecure.be (192.168.12.186)
Nmap scan report for qazwsxs-MBP-2.prod.youaresecure.be (192.168.12.233)
Nmap done: 256 IP addresses (10 hosts up) scanned in 11.95 seconds

ping6


$ ping6 ff02::2%en0
PING6(56=40+8+8 bytes) fe80::f65c:89ff:fe92:f861%en0 --> ff02::2%en0
16 bytes from fe80::225:31ff:fe04:9bf4%en0, icmp_seq=0 hlim=64 time=89.397 ms
16 bytes from fe80::b4d0:5eff:fe0f:a117%en0, icmp_seq=0 hlim=64 time=89.552 ms
16 bytes from fe80::225:31ff:fe04:9bf4%en0, icmp_seq=1 hlim=64 time=1.062 ms
16 bytes from fe80::b4d0:5eff:fe0f:a117%en0, icmp_seq=1 hlim=64 time=1.166 ms
16 bytes from fe80::225:31ff:fe04:9bf4%en0, icmp_seq=2 hlim=64 time=2.039 ms
16 bytes from fe80::b4d0:5eff:fe0f:a117%en0, icmp_seq=2 hlim=64 time=2.181 ms
16 bytes from fe80::225:31ff:fe04:9bf4%en0, icmp_seq=3 hlim=64 time=2.135 ms
16 bytes from fe80::b4d0:5eff:fe0f:a117%en0, icmp_seq=3 hlim=64 time=2.247 ms

Debian check network config


 

root@SpeedyJ:~# cat /etc/network/interfaces
# interfaces(5) file used by ifup(8) and ifdown(8)
auto lo
iface lo inet loopback

auto eth0
iface eth0 inet static
address 172.30.30.98
netmask 255.255.255.0
gateway 172.30.30.1
root@SpeedyJ:~#
# interfaces(5) file used by ifup(8) and ifdown(8)
auto lo
iface lo inet loopback

auto eth0
iface eth0 inet dhcp


root@SpeedyJ:~# /etc/init.d/networking restart
[warn] Running /etc/init.d/networking restart is deprecated because it may not re-enable some interfaces ... (warning).
[....] Reconfiguring network interfaces...err, eth0: dhcpcd not running
didnt work
root@cox:~# vi .bashrc
export LC_ALL="en_US.UTF-8"


perl: warning: Please check that your locale settings:
	LANGUAGE = (unset),
	LC_ALL = (unset),
	LC_CTYPE = "UTF-8",
	LANG = "C"
    are supported and installed on your system.

locally edit and comment the following line:
sudo vi ~/.ssh/config
#SendEnv LANG LC_*

Debian iperf and hping


 

 

root@cox:~# apt-get install iperf
Unpacking iperf (from .../iperf_2.0.5-3_armel.deb) ...


root@cox:~# apt-get install hping3
Setting up hping3 (3.a2.ds2-6) ...

 

LEDE intall packages


 

 

root@DIGWEED:~# opkg update
root@DIGWEED:~# opkg install hping

 

Bailey pogo E02


root@BAILEY:~# cat /proc/cpuinfo
processor	: 0
model name	: Feroceon 88FR131 rev 1 (v5l)
BogoMIPS	: 1191.11
Features	: swp half fastmult edsp
CPU implementer	: 0x56
CPU architecture: 5TE
CPU variant	: 0x2
CPU part	: 0x131
CPU revision	: 1

Hardware	: Marvell Kirkwood (Flattened Device Tree)
Revision	: 0000
Serial		: 0000000000000000

root@BAILEY:~# cat /proc/meminfo
MemTotal:         254684 kB
MemFree:          238288 kB
MemAvailable:     221336 kB

Linux BAILEY 4.4.50 #0 Mon Feb 20 15:02:54 2017 armv5tel GNU/Linux

Iperf version.

BAILEY:~# iperf -v
iperf version 2.0.9 (9 Sept 2016) pthreads

Lede version.

root@BAILEY:~# cat /etc/openwrt_release
DISTRIB_ID='LEDE'
DISTRIB_RELEASE='17.01.0'
DISTRIB_REVISION='r3205-59508e3'
DISTRIB_CODENAME='reboot'
DISTRIB_TARGET='kirkwood/generic'
DISTRIB_ARCH='arm_xscale'
DISTRIB_DESCRIPTION='LEDE Reboot 17.01.0 r3205-59508e3'
DISTRIB_TAINTS='no-all'
root@BAILEY:~#

Cox


 

root@cox:~# cat /proc/cpuinfo
processor	: 0
model name	: ARMv6-compatible processor rev 5 (v6l)
Features	: half thumb fastmult edsp java tls
CPU implementer	: 0x41
CPU architecture: 7
CPU variant	: 0x0
CPU part	: 0xb02
CPU revision	: 5

processor	: 1
model name	: ARMv6-compatible processor rev 5 (v6l)
Features	: half thumb fastmult edsp java tls
CPU implementer	: 0x41
CPU architecture: 7
CPU variant	: 0x0
CPU part	: 0xb02
CPU revision	: 5

Hardware	: PLXTECH NAS782X SoC (Flattened Device Tree)
Revision	: 0000
Serial		: 0000000000000000
root@cox:~# cat /proc/meminfo
MemTotal:         121920 kB
MemFree:           26176 kB
MemAvailable:     104808 kB


root@cox:~# cat /proc/version
Linux version 3.17.0-oxnas-tld-1 (root@tldDebian) (gcc version 4.6.3 (Debian 4.6.3-14) ) #1 SMP PREEMPT Sat Oct 25 15:59:43 PDT 2014

SNMP on Cisco SG300


 

1 configure community String

 

1.1 Enable service

2 Create LAG

 

 

 

PRTG


 

 

 

 

Installing IPERF3 on Debian wheezy


 

cd /etc/apt/sources.list.d/
wget http://downloads.perfsonar.net/debian/perfsonar-wheezy-release.list
wget -qO - http://downloads.perfsonar.net/debian/perfsonar-debian-official.gpg.key | apt-key add -
apt-get update
apt-get install iperf3
iperf3 -v



iperf 3.2 (cJSON 1.5.2)
Linux Beyer 3.14.0-kirkwood-tld-1 #1 PREEMPT Tue Apr 1 22:54:58 PDT 2014 armv5tel
Optional features available: CPU affinity setting, IPv6 flow label, TCP congestion algorithm setting, sendfile / zerocopy

lshw


root@SpeedyJ:~# lshw
speedyj.dc2.youaresecure.be
    description: Computer
    width: 32 bits
  *-core
       description: Motherboard
       physical id: 0
     *-memory
          description: System memory
          physical id: 0
          size: 249MiB
     *-cpu
          physical id: 1
          bus info: cpu@0
     *-scsi
          physical id: 2
          bus info: usb@1:1.3
          logical name: scsi0
          capabilities: emulated
        *-disk
             description: SCSI Disk
             physical id: 0.0.0
             bus info: scsi@0:0.0.0
             logical name: /dev/sda
             size: 14GiB (16GB)
             capabilities: partitioned partitioned:dos
             configuration: sectorsize=512 signature=ed806f07
           *-volume:0
                description: Linux filesystem partition
                vendor: Linux
                physical id: 1
                bus info: scsi@0:0.0.0,1
                logical name: /dev/sda1
                logical name: /
                version: 1.0
                serial: 7a0b2b93-2587-46ce-a18c-3146942fa174
                size: 977MiB
                capacity: 977MiB
                capabilities: primary bootable extended_attributes large_files ext2 initialized
                configuration: filesystem=ext2 modified=2017-11-05 17:39:22 mount.fstype=ext2 mount.options=rw,noatime,errors=remount-ro mounted=2017-11-05 17:39:22 state=mounted
           *-volume:1
                description: Linux swap volume
                physical id: 2
                bus info: scsi@0:0.0.0,2
                logical name: /dev/sda2
                version: 1
                size: 245MiB
                capacity: 245MiB
                capabilities: primary swap initialized
                configuration: filesystem=swap pagesize=4096
  *-network:0
       description: Wireless interface
       physical id: 1
       bus info: usb@1:1.1
       logical name: wlan0
       serial: 00:26:5a:1a:33:cd
       capabilities: ethernet physical wireless
       configuration: broadcast=yes driver=rt73usb driverversion=3.2.0-4-kirkwood firmware=1.7 ip=192.168.12.117 link=yes multicast=yes wireless=IEEE 802.11bg
  *-network:1 DISABLED
       description: Ethernet interface
       physical id: 2
       logical name: eth0
       serial: 00:25:31:04:98:9a
       size: 1Gbit/s
       capacity: 1Gbit/s
       capabilities: ethernet physical tp aui bnc mii fibre 10bt 10bt-fd 100bt 100bt-fd 1000bt-fd autonegotiation
       configuration: autonegotiation=on broadcast=yes driver=mv643xx_eth driverversion=1.4 duplex=full firmware=N/A ip=192.168.12.104 link=no multicast=yes port=MII speed=1Gbit/s

 

References


Locale
https://askubuntu.com/questions/162391/how-do-i-fix-my-locale-issue

[failed] Pogoplug v2

image_pdfimage_print

Check Hardware and specs Pogoplug v2 (No Longer in Production):

Processor: ARM926EJ-S rev 1 (v5l)
CPU Hardware: Feroceon-KW
Processor: ARM926EJ-S rev 1 (v5l)
BogoMIPS: 1192.75
Total Memory: 256MB

Confirming specs

-sh-4.3# cat /proc/cpuinfo | grep Hardware
Hardware        : Feroceon-KW
-sh-4.3# dmesg | more                     
[    0.000000] Linux version 2.6.22.18 (bdietrich@buildman) (gcc version 4.2.1) #81 Tue Oct 19 16:05:00 PDT 2010
[    0.000000] CPU: ARM926EJ-S [56251311] revision 1 (ARMv5TE), cr=00053177
[    0.000000] Machine: Feroceon-KW
[    0.000000] Using UBoot passing parameters structure
[    0.000000] Memory policy: ECC disabled, Data cache writeback
[    0.000000] On node 0 totalpages: 65536
[    0.000000]   DMA zone: 512 pages used for memmap
[    0.000000]   DMA zone: 0 pages reserved
[    0.000000]   DMA zone: 65024 pages, LIFO batch:15
[    0.000000]   Normal zone: 0 pages used for memmap
[    0.000000] CPU0: D VIVT write-back cache
[    0.000000] CPU0: I cache: 16384 bytes, associativity 4, 32 byte lines, 128 sets
[    0.000000] CPU0: D cache: 16384 bytes, associativity 4, 32 byte lines, 128 sets
[    0.000000] Built 1 zonelists.  Total pages: 65024
[    0.000000] Kernel command line: console=ttyS0,115200 root=/dev/mtdblock2 ro
[    0.000000] PID hash table entries: 1024 (order: 10, 4096 bytes)
[    0.000000] Console: colour dummy device 80x30
[    0.000000] Dentry cache hash table entries: 32768 (order: 5, 131072 bytes)
[    0.000000] Inode-cache hash table entries: 16384 (order: 4, 65536 bytes)
[    0.010000] Memory: 256MB 0MB 0MB 0MB = 256MB total

Reboot and look on U-Boot

pri


U-Boot 1.1.4 (Sep 28 2009 - 11:55:23) Cloud Engines v2.0 (3.4.16)

U-Boot code: 00600000 -> 0067FFF0  BSS: -> 00690D60

Soc: 88F6281 A0 (DDR2)
CPU running @ 1200Mhz L2 running @ 400Mhz
SysClock = 400Mhz , TClock = 200Mhz

DRAM CAS Latency = 5 tRP = 5 tRAS = 18 tRCD=6
DRAM CS[0] base 0x00000000   size 256MB
DRAM Total size 256MB  16bit width
Flash:  0 kB
Addresses 8M - 0M are saved for the U-Boot usage.
Mem malloc Initialization (8M - 7M): Done
NAND:128 MB

CPU : Marvell Feroceon (Rev 1)
CLOUD ENGINES BOARD: PPV2

Streaming disabled
Write allocate disabled


USB 0: host mode
PEX 0: interface detected no Link.
Net:   egiga0 [PRIME], egiga1
Hit any key to stop autoboot:  0

Print U-Boot variables

CE>> print
baudrate=115200
loads_echo=0
rootpath=/mnt/ARM_FS/
netmask=255.255.0.0
run_diag=yes
console=console=ttyS0,115200
CASset=min
MALLOC_len=1
ethprime=egiga0
bootargs_root=root=/dev/mtdblock2 ro
ethmtu=1500
usb0Mode=host
nandEcc=1bit
ethact=egiga0
bootargs=console=ttyS0,115200 root=/dev/mtdblock2 ro
serverip=169.254.254.252
ipaddr=169.254.254.253
ethaddr=00:25:31:00:85:95
cesvcid=LBQQMQE25WHZ4AADWHN653JRCN
ceboardver=PPV2
bootcmd=nand read.e 0x800000 0x100000 0x200000; setenv bootargs $(console) $(bootargs_root);bootm 0x800000
stdin=serial
stdout=serial
stderr=serial
mainlineLinux=no
enaMonExt=no
enaCpuStream=no
enaWrAllo=no
pexMode=RC
disL2Cache=no
setL2CacheWT=yes
disL2Prefetch=yes
enaICPref=yes
enaDCPref=yes
sata_dma_mode=yes
netbsd_en=no
vxworks_en=no
bootdelay=3
disaMvPnp=no

Download openwrt-kirkwood-pogo_e02_second_stage-u-boot.img to pogoplug via TFTP

CE>> setenv ipaddr 192.168.12.240
CE>> setenv serverip 192.168.12.186
CE>> setenv netmask 255.255.255.0
CE>> saveenv
Saving Environment to NAND...
Erasing Nand...Writing to Nand... done
CE>> tftpboot 0x800000 openwrt-kirkwood-pogo_e02_second_stage-u-boot.img
Using egiga0 device
TFTP from server 192.168.12.186; our IP address is 192.168.12.240
Filename 'openwrt-kirkwood-pogo_e02_second_stage-u-boot.img'.
Load address: 0x800000
Loading: T #################################################################
         ########################
done
Bytes transferred = 454920 (6f108 hex)
CE>> 

Erase and Write NAND


CE>> nand erase 0x100000 0x80000

NAND erase: device 0 offset 0x100000, size 0x80000
Erasing at 0x160000 -- 100% complete.
OK
CE>> nand write.e 0x800000 0x100000 0x80000

NAND write: device 0 offset 0x100000, size 0x80000

Writing data at 0x17f800 -- 100% complete.
 524288 bytes written: OK
CE>> 

FIRST time got stuck

U-Boot code: 00600000 -> 0067FFF0  BSS: -> 00690D60

Soc: 88F6281 A0 (DDR2)
CPU running @ 1200Mhz L2 running @ 400Mhz
SysClock = 400Mhz , TClock = 200Mhz 

DRAM CAS Latency = 5 tRP = 5 tRAS = 18 tRCD=6
DRAM CS[0] base 0x00000000   size 256MB 
DRAM Total size 256MB  16bit width
Flash:  0 kB
Addresses 8M - 0M are saved for the U-Boot usage.
Mem malloc Initialization (8M - 7M): Done
NAND:128 MB

CPU : Marvell Feroceon (Rev 1)
CLOUD ENGINES BOARD: PPV2

Streaming disabled 
Write allocate disabled


USB 0: host mode
PEX 0: interface detected no Link.
Net:   egiga0 [PRIME], egiga1
Hit any key to stop autoboot:  0 

NAND read: device 0 offset 0x100000, size 0x200000

Bad block at 0x180000 in erase block from 0x180000 will be skipped
Reading data from 0x31f800 -- 100% complete.
 2097152 bytes read: OK
## Booting image at 00800000 ...
   Image Name:   OpenWrt Das U-Boot uImage
   Created:      2015-07-24  18:12:43 UTC
   Image Type:   ARM Linux Kernel Image (uncompressed)
   Data Size:    454856 Bytes = 444.2 kB
   Load Address: 00600000
   Entry Point:  00600000
   Verifying Checksum ... OK


LA MIGRA from Avaya core to Juniper core

image_pdfimage_print

Intro.


Documenting how I moved from an avaya home network to a juniper.

 

Initial switch port documentation


 

Documentation verification after inspection.


 

VLAN to assigned PORTS Check


With that information, checked now VLAN to port assignation.

There are mainly 5 VLANS

  • VLAN 1: LAB
  • VLAN 200: PROD
  • VLAN 300: TEST
  • VLAN 500: TEST DMZ
  • VLAN 700: INET

There are also a couple of others: 100,400,600 and 999 not well clear what their purpose was.

Fro that check is possible to conclude that to start with the procedure and to gain more visibility of the migration process, a good start is to prepare the migration of VLAN 700.

Migrating VLAN 700.


This approach is simple to check, in the way that if it doesnt work, it will be noticed quickly because no internet.

Is understood this VLAN doesnt require any special treatment: no routing instance, no routing, nothing.

the ports selected are port from ge-0/0/16 to ge-0/0/19.

 

EX2200 creating Internet VLAN for WAN ports on small firewalls


Creating VLAN 700 and assign VLANS to port

 

 

Initial configuration

This configuration highligth’s are:

  • 2 configures vlans v11 and v12 with their respective l3-interfaces
  • 2 aggregated member interfaces:
    • ae0 to SRX node 0
    • ae1 to SRX node 1
  • LAN routing instance that includes those two interfaces and helps with the routing.
root@STOCKELA-SW-EX01# show | display set
set version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set chassis aggregated-devices ethernet device-count 2
set interfaces ge-0/0/1 unit 0 family ethernet-switching
set interfaces ge-0/0/5 unit 0 family ethernet-switching
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v11
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/20 description "           ==== ae0 member === "
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 description "           ==== ae0 member === "
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 description "           ==== ae1 member === "
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 description "           ==== ae1 member === "
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "           ==== ae0  TRUNK to SRX node 0 ==== "
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members all
set interfaces ae1 description "           ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 aggregated-ether-options lacp active
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members all
set interfaces me0 description "                                ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "                       ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "                       ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set routing-instances LAN description "                         ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set vlans v11 description "                                     ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "                                     ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12
set poe interface all

Afterwards configuration:
VLAN 700 is create
Ports ge-0/0/16,17,18,19 are selected for internet access.

root@STOCKELA-SW-EX01# show | display set
set version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$219TEinH$Mnlr/utzhlMefCRNwkdDN0"
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set chassis aggregated-devices ethernet device-count 2
set interfaces ge-0/0/1 unit 0 family ethernet-switching
set interfaces ge-0/0/5 unit 0 family ethernet-switching
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v11
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/16 description "                          ==== ge-0/0/16 V700 member === "
set interfaces ge-0/0/16 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/16 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/17 description "                          ==== ge-0/0/17 V700 member === "
set interfaces ge-0/0/17 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/17 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/18 description "                          ==== ge-0/0/18 V700 member === "
set interfaces ge-0/0/18 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/18 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/19 description "                          ==== ge-0/0/19 V700 member === "
set interfaces ge-0/0/19 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/19 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/20 description "                          ==== ae0 member === "
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 description "                          ==== ae0 member === "
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 description "                          ==== ae1 member === "
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 description "                          ==== ae1 member === "
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "                                ==== ae0  TRUNK to SRX node 0 ==== "
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members all
set interfaces ae1 description "                                ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 aggregated-ether-options lacp active
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members all
set interfaces me0 description "                                ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "                       ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "                       ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set routing-instances LAN description "                         ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set vlans v11 description "                                     ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "                                     ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12
set vlans v700 description "                                    ==== VLAN 700             ==== "
set vlans v700 vlan-id 700
set poe interface all

Tests successfull.

Creating to be migrated of the VLANS and reserving ports for WLC and access points


Create vlans

  • VLAN 1: LAB (Will become 100).
  • VLAN 200: PROD.
  • VLAN 300: TEST.
  • VLAN 500: TEST DMZ.

and reserving ports for WLC and access points. ge-0/0/11 to ge-0/0/15

Note: that from now, TRUNKS need to be specific in the vlans they carry.

set version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set chassis aggregated-devices ethernet device-count 2
set interfaces ge-0/0/1 unit 0 family ethernet-switching
set interfaces ge-0/0/5 unit 0 family ethernet-switching
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v11
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/11 description "                          ==== RESERVED FOR WLC  === "
set interfaces ge-0/0/12 description "                          ==== RESERVED FOR AP 1 === "
set interfaces ge-0/0/13 description "                          ==== RESERVED FOR AP 2 === "
set interfaces ge-0/0/14 description "                          ==== RESERVED FOR AP 3 === "
set interfaces ge-0/0/15 description "                          ==== RESERVED FOR AP 4 === "
set interfaces ge-0/0/16 description "                          ==== ge-0/0/16 V700 member === "
set interfaces ge-0/0/16 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/16 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/17 description "                          ==== ge-0/0/17 V700 member === "
set interfaces ge-0/0/17 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/17 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/18 description "                          ==== ge-0/0/18 V700 member === "
set interfaces ge-0/0/18 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/18 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/19 description "                          ==== ge-0/0/19 V700 member === "
set interfaces ge-0/0/19 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/19 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/20 description "                          ==== ge-0/0/20 ae0 member === "
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 description "                          ==== ge-0/0/21 ae0 member === "
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 description "                          ==== ge-0/0/22 ae1 member === "
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 description "                          ==== ge-0/0/23 ae1 member === "
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "                                ==== ae0  TRUNK to SRX node 0 ==== "
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members v11
set interfaces ae0 unit 0 family ethernet-switching vlan members v12
set interfaces ae1 description "                                ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 aggregated-ether-options lacp active
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members v11
set interfaces ae1 unit 0 family ethernet-switching vlan members v12
set interfaces me0 description "                                ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "                       ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "                       ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set routing-instances LAN description "                         ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set vlans v100 description "                                    ==== VLAN 100  LAB        ==== "
set vlans v100 vlan-id 100
set vlans v11 description "                                     ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "                                     ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12
set vlans v200 description "                                    ==== VLAN 200  PROD       ==== "
set vlans v200 vlan-id 200
set vlans v300 description "                                    ==== VLAN 300  TEST       ==== "
set vlans v300 vlan-id 300
set vlans v500 description "                                    ==== VLAN 500  DMZ        ==== "
set vlans v500 vlan-id 500
set vlans v700 description "                                    ==== VLAN 700  INTERNET   ==== "
set vlans v700 vlan-id 700
set poe interface all

Check VLANS are on the right interfaces.

With the command show vlans, is possivle to appreciate that ae0.0 and ae1.0 are only carrying v11 and v12

{master:0}[edit]
root@STOCKELA-SW-EX01# run show vlans
Name           Tag     Interfaces
default
                       ge-0/0/1.0*, ge-0/0/5.0
v100           100
                       None
v11            11
                       ae0.0*, ae1.0, ge-0/0/6.0*
v12            12
                       ae0.0*, ae1.0, ge-0/0/7.0*
v200           200
                       None
v300           300
                       None
v500           500
                       None
v700           700
                       ge-0/0/16.0*, ge-0/0/17.0, ge-0/0/18.0*, ge-0/0/19.0*

 

Select 1 port for each LAN interface in PROD, LAB, TEST, and DMZ


The first 4 ports from the switch are taken to interconct to each LAN of those networks.

 

set version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set chassis aggregated-devices ethernet device-count 2
set interfaces ge-0/0/0 description "                           ==== RESERVED FOR LAB  === "
set interfaces ge-0/0/0 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/1 description "                           ==== RESERVED FOR PROD  === "
set interfaces ge-0/0/1 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/2 description "                           ==== RESERVED FOR TEST  === "
set interfaces ge-0/0/2 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/2 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/3 description "                           ==== RESERVED FOR DMZ  === "
set interfaces ge-0/0/3 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/3 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/5 description "                           ==== RESERVED FOR DEFAULT  === "
set interfaces ge-0/0/5 unit 0 family ethernet-switching
set interfaces ge-0/0/6 description "                           ==== RESERVED FOR v11  === "
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v11
set interfaces ge-0/0/7 description "                           ==== RESERVED FOR v12  === "
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/11 description "                          ==== RESERVED FOR WLC  === "
set interfaces ge-0/0/12 description "                          ==== RESERVED FOR AP 1 === "
set interfaces ge-0/0/13 description "                          ==== RESERVED FOR AP 2 === "
set interfaces ge-0/0/14 description "                          ==== RESERVED FOR AP 3 === "
set interfaces ge-0/0/15 description "                          ==== RESERVED FOR AP 4 === "
set interfaces ge-0/0/16 description "                          ==== ge-0/0/16 V700 member === "
set interfaces ge-0/0/16 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/16 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/17 description "                          ==== ge-0/0/17 V700 member === "
set interfaces ge-0/0/17 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/17 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/18 description "                          ==== ge-0/0/18 V700 member === "
set interfaces ge-0/0/18 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/18 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/19 description "                          ==== ge-0/0/19 V700 member === "
set interfaces ge-0/0/19 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/19 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/20 description "                          ==== ge-0/0/20 ae0 member === "
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 description "                          ==== ge-0/0/21 ae0 member === "
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 description "                          ==== ge-0/0/22 ae1 member === "
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 description "                          ==== ge-0/0/23 ae1 member === "
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "                                ==== ae0  TRUNK to SRX node 0 ==== "
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members v11
set interfaces ae0 unit 0 family ethernet-switching vlan members v12
set interfaces ae1 description "                                ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 aggregated-ether-options lacp active
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members v11
set interfaces ae1 unit 0 family ethernet-switching vlan members v12
set interfaces me0 description "                                ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "                       ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "                       ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set routing-instances LAN description "                         ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set vlans v100 description "                                    ==== VLAN 100  LAB        ==== "
set vlans v100 vlan-id 100
set vlans v11 description "                                     ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "                                     ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12
set vlans v200 description "                                    ==== VLAN 200  PROD       ==== "
set vlans v200 vlan-id 200
set vlans v300 description "                                    ==== VLAN 300  TEST       ==== "
set vlans v300 vlan-id 300
set vlans v500 description "                                    ==== VLAN 500  DMZ        ==== "
set vlans v500 vlan-id 500
set vlans v700 description "                                    ==== VLAN 700  INTERNET   ==== "
set vlans v700 vlan-id 700
set poe interface all

 

Assign APs ports and WLC as TRUNKS, put designated VLANS and native vlan as 100.


 

set version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set chassis aggregated-devices ethernet device-count 2
set interfaces ge-0/0/0 description "                           ==== RESERVED FOR LAB  === "
set interfaces ge-0/0/0 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/1 description "                           ==== RESERVED FOR PROD  === "
set interfaces ge-0/0/1 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/2 description "                           ==== RESERVED FOR TEST  === "
set interfaces ge-0/0/2 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/2 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/3 description "                           ==== RESERVED FOR DMZ  === "
set interfaces ge-0/0/3 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/3 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/5 description "                           ==== RESERVED FOR DEFAULT  === "
set interfaces ge-0/0/5 unit 0 family ethernet-switching
set interfaces ge-0/0/6 description "                           ==== RESERVED FOR v11  === "
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v11
set interfaces ge-0/0/7 description "                           ==== RESERVED FOR v12  === "
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/11 description "                          ==== RESERVED FOR WLC  === "
set interfaces ge-0/0/11 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/11 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/12 description "                          ==== RESERVED FOR AP 1 === "
set interfaces ge-0/0/12 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/12 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/13 description "                          ==== RESERVED FOR AP 2 === "
set interfaces ge-0/0/13 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/13 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/14 description "                          ==== RESERVED FOR AP 3 === "
set interfaces ge-0/0/14 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/14 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/15 description "                          ==== RESERVED FOR AP 4 === "
set interfaces ge-0/0/15 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/15 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/16 description "                          ==== ge-0/0/16 V700 member === "
set interfaces ge-0/0/16 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/16 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/17 description "                          ==== ge-0/0/17 V700 member === "
set interfaces ge-0/0/17 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/17 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/18 description "                          ==== ge-0/0/18 V700 member === "
set interfaces ge-0/0/18 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/18 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/19 description "                          ==== ge-0/0/19 V700 member === "
set interfaces ge-0/0/19 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/19 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/20 description "                          ==== ge-0/0/20 ae0 member === "
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 description "                          ==== ge-0/0/21 ae0 member === "
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 description "                          ==== ge-0/0/22 ae1 member === "
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 description "                          ==== ge-0/0/23 ae1 member === "
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "                                ==== ae0  TRUNK to SRX node 0 ==== "
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members v11
set interfaces ae0 unit 0 family ethernet-switching vlan members v12
set interfaces ae1 description "                                ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 aggregated-ether-options lacp active
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members v11
set interfaces ae1 unit 0 family ethernet-switching vlan members v12
set interfaces me0 description "                                ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "                       ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "                       ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set routing-instances LAN description "                         ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set vlans v100 description "                                    ==== VLAN 100  LAB        ==== "
set vlans v100 vlan-id 100
set vlans v11 description "                                     ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "                                     ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12
set vlans v200 description "                                    ==== VLAN 200  PROD       ==== "
set vlans v200 vlan-id 200
set vlans v300 description "                                    ==== VLAN 300  TEST       ==== "
set vlans v300 vlan-id 300
set vlans v500 description "                                    ==== VLAN 500  DMZ        ==== "
set vlans v500 vlan-id 500
set vlans v700 description "                                    ==== VLAN 700  INTERNET   ==== "
set vlans v700 vlan-id 700
set poe interface all

{master:0}[edit]
root@STOCKELA-SW-EX01#

 

Checking AP status


MXR-2# show ap status
Flags: o = operational[4], c = configure[0], d = download[0], b = boot[0]
       a = auto AP, m = mesh AP, p/P = mesh portal (ena/actv), r = redundant[0]
       z = remote AP in outage, i/I = insecure (control/control+data)
       u = unencrypted, e/E = encrypted (control/control+data)
Radio: E = enabled - 20MHz channel, S = sentry, s = spectral-data
       W/w = enabled - 40MHz wide channel (HTplus/HTminus)
       D = admin disabled, U = mesh uplink
IP Address: * = AP behind NAT

AP   Flag IP Address      Model        MAC Address       Radio 1 Radio 2 Uptime
---- ---- --------------- ------------ ----------------- ------- ------- ------
   1 o--i 192.168.10.241  WLA522-WW    40:b4:f0:a5:fb:80 S 11/14 S 48/14 03d22h
   2 o--i 192.168.10.242  WLA522-WW    40:b4:f0:15:1b:40 E  1/14 E 44/14 14d20h
   3 o--i 192.168.10.243  WLA522-WW    40:b4:f0:a6:e0:c0 E 11/14 W 36/14 13d20h
   5 o--i 192.168.10.244  MP-82        00:26:3e:23:80:c0 E 11/16 E 36/12 08m48s

Disable interface of AP 5

{master:0}[edit]
root@STOCKELA-SW-EX01# set interfaces ge-0/0/15 disable
{master:0}[edit]
root@STOCKELA-SW-EX01# commit
configuration check succeeds
commit complete

Device get reported as Down

MXR-2# APM Oct 14 17:40:06.801129 ERROR AP_NOTICE: AP 5 timed out, state was operational
SM Oct 14 17:40:06.801898 NOTICE SM-EVENT: APM reports AP 5 is down

Re enable interface

{master:0}[edit]
root@STOCKELA-SW-EX01# delete interfaces ge-0/0/15 disable

{master:0}[edit]
root@STOCKELA-SW-EX01# commit
configuration check succeeds
commit complete

Device is detected again

MXR-2# APM_FMX Oct 14 17:41:25.937878 NOTICE AP_NOTIFY: SW-find request from AP serial_id 09e3700966 mac 00:26:3e:23:80:c0 port 1 vlan default succeeded with IP-address 192.168.10.30 flags 25 bias 1 sec 1 old=0
WLA Oct 14 17:41:35.428897 ALERT AP 5 AP Buffered Log (0): 644.923 tapa: tapa_ping_send(tapa_ping): 192.168.10.30(PAM) is down! (3 2 5)
WLA Oct 14 17:41:35.529351 ALERT AP 5 AP Buffered Log (1): 644.931 agent: AP Reset: TAPA Announce timeout
APM_FMX Oct 14 17:41:51.803431 NOTICE AP_NOTIFY: serialid already connected to Switch 192.168.10.30, responding with that switch's IP address.
APM_FMX Oct 14 17:41:51.804214 NOTICE AP_NOTIFY: SW-find request from AP serial_id 09e3700966 mac 00:26:3e:23:80:c0 port 1 vlan default succeeded with IP-address 192.168.10.30 flags 25 bias 1 sec 1 old=0
APM Oct 14 17:41:58.169567 CRITICAL AP_NOTICE: AP 5 booted OK from AP resident image
WLA Oct 14 17:41:58.178347 INFO AP 5 agent: Boot count: 82  [BsVS: 3.0.5 (04/xx/2009)]

 

Powering off Avaya switch (too early maybe).


 

Powering off the switch to check if the AP movement was successful proves some missing points.

 

After the power down:

  1. LAB network gives an IP and internet access.
  2. TEST doesn’t provide internet.
  3. PROD network doesnt provide IP address.

Possible cause?

Some DNS/DHCP servers could be connected to avaya switch hence leaving without DHCP some networks.

Proposed solution.

TEST NETWORK: Checking TEST configuration, the DNS servers received on the DHCP config are 192.168.12.10 and 192.168.10.2. This means that from test network this servers are unreacheable and to solve this, some routes are needed. a new routing instance on the switch seems required.

PROD NETWORK: Checking onsite displayed a misconfigured port for connecting Juniper switch to the PROD network, changing port fixed the issue.

 

To complete the missing ports movement, also had to reserve ports for:

4 OFFICE cabled

5 NUC with several VLANS

6 SHEEVA MAIN PORT

Regarding SRX: ge-0/0/0 on each cluster member not more in user due to powering off avaya.

set version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$219TEinH$Mnlr/utzhlMefCRNwkdDN0"
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set chassis aggregated-devices ethernet device-count 2
set interfaces ge-0/0/0 description "                           ==== RESERVED FOR LAB  === "
set interfaces ge-0/0/0 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/1 description "                           ==== RESERVED FOR PROD  === "
set interfaces ge-0/0/1 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/2 description "                           ==== RESERVED FOR TEST  === "
set interfaces ge-0/0/2 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/2 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/3 description "                           ==== RESERVED FOR DMZ  === "
set interfaces ge-0/0/3 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/3 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/4 description "                           ==== RESERVED FOR OFFICE  === "
set interfaces ge-0/0/4 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/4 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/5 description "                           ==== RESERVED FOR NUC  === "
set interfaces ge-0/0/5 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/5 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/6 description "                           ==== RESERVED FOR SHEEVA MAIN to LAB  === "
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/7 description "                           ==== RESERVED FOR v12  === "
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/11 description "                          ==== RESERVED FOR WLC  === "
set interfaces ge-0/0/11 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/11 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/12 description "                          ==== RESERVED FOR AP 1 === "
set interfaces ge-0/0/12 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/12 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/13 description "                          ==== RESERVED FOR AP 2 === "
set interfaces ge-0/0/13 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/13 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/14 description "                          ==== RESERVED FOR AP 3 === "
set interfaces ge-0/0/14 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/14 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/15 description "                          ==== RESERVED FOR AP 4 === "
set interfaces ge-0/0/15 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/15 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/16 description "                          ==== ge-0/0/16 V700 member === "
set interfaces ge-0/0/16 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/16 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/17 description "                          ==== ge-0/0/17 V700 member === "
set interfaces ge-0/0/17 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/17 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/18 description "                          ==== ge-0/0/18 V700 member === "
set interfaces ge-0/0/18 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/18 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/19 description "                          ==== ge-0/0/19 V700 member === "
set interfaces ge-0/0/19 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/19 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/20 description "                          ==== ge-0/0/20 ae0 member === "
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 description "                          ==== ge-0/0/21 ae0 member === "
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 description "                          ==== ge-0/0/22 ae1 member === "
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 description "                          ==== ge-0/0/23 ae1 member === "
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "                                ==== ae0  TRUNK to SRX node 0 ==== "
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members v11
set interfaces ae0 unit 0 family ethernet-switching vlan members v12
set interfaces ae1 description "                                ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 aggregated-ether-options lacp active
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members v11
set interfaces ae1 unit 0 family ethernet-switching vlan members v12
set interfaces me0 description "                                ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "                       ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "                       ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set routing-instances LAN description "                         ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set vlans v100 description "                                    ==== VLAN 100  LAB        ==== "
set vlans v100 vlan-id 100
set vlans v11 description "                                     ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "                                     ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12
set vlans v200 description "                                    ==== VLAN 200  PROD       ==== "
set vlans v200 vlan-id 200
set vlans v300 description "                                    ==== VLAN 300  TEST       ==== "
set vlans v300 vlan-id 300
set vlans v500 description "                                    ==== VLAN 500  DMZ        ==== "
set vlans v500 vlan-id 500
set vlans v700 description "                                    ==== VLAN 700  INTERNET   ==== "
set vlans v700 vlan-id 700
set poe interface all

After confirming SHEEVA main accessibility only trough LAB network, now its time to create a routing instance.

 

Creating L3 interfaces and a Routing instance for interconnecting networks.


 

In the image below you can see the current configuration of the LAB firewall in regards to routes to other networks.

The interconnection configuration existed previously on each firewall.

Creating a routing instance and a couple of L3 interfaces would perform the same purpose.

 

set version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set chassis aggregated-devices ethernet device-count 2
set interfaces ge-0/0/0 description "                           ==== RESERVED FOR LAB  === "
set interfaces ge-0/0/0 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/1 description "                           ==== RESERVED FOR PROD  === "
set interfaces ge-0/0/1 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/2 description "                           ==== RESERVED FOR TEST  === "
set interfaces ge-0/0/2 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/2 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/3 description "                           ==== RESERVED FOR DMZ  === "
set interfaces ge-0/0/3 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/3 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/4 description "                           ==== RESERVED FOR OFFICE  === "
set interfaces ge-0/0/4 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/4 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/5 description "                           ==== RESERVED FOR NUC  === "
set interfaces ge-0/0/5 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/5 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/6 description "                           ==== RESERVED FOR SHEEVA MAIN to LAB  === "
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/7 description "                           ==== RESERVED FOR v12  === "
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/11 description "                          ==== RESERVED FOR WLC  === "
set interfaces ge-0/0/11 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/11 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/12 description "                          ==== RESERVED FOR AP 1 === "
set interfaces ge-0/0/12 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/12 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/13 description "                          ==== RESERVED FOR AP 2 === "
set interfaces ge-0/0/13 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/13 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/14 description "                          ==== RESERVED FOR AP 3 === "
set interfaces ge-0/0/14 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/14 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/15 description "                          ==== RESERVED FOR AP 4 === "
set interfaces ge-0/0/15 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/15 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/16 description "                          ==== ge-0/0/16 V700 member === "
set interfaces ge-0/0/16 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/16 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/17 description "                          ==== ge-0/0/17 V700 member === "
set interfaces ge-0/0/17 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/17 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/18 description "                          ==== ge-0/0/18 V700 member === "
set interfaces ge-0/0/18 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/18 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/19 description "                          ==== ge-0/0/19 V700 member === "
set interfaces ge-0/0/19 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/19 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/20 description "                          ==== ge-0/0/20 ae0 member === "
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 description "                          ==== ge-0/0/21 ae0 member === "
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 description "                          ==== ge-0/0/22 ae1 member === "
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 description "                          ==== ge-0/0/23 ae1 member === "
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "                                ==== ae0  TRUNK to SRX node 0 ==== "
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members v11
set interfaces ae0 unit 0 family ethernet-switching vlan members v12
set interfaces ae1 description "                                ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 aggregated-ether-options lacp active
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members v11
set interfaces ae1 unit 0 family ethernet-switching vlan members v12
set interfaces me0 description "                                ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "                       ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "                       ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set interfaces vlan unit 100 description "                       ==== VLAN unit 100 INTERFACE ==== "
set interfaces vlan unit 100 family inet address 192.168.10.7/24
set interfaces vlan unit 200 description "                       ==== VLAN unit 200 INTERFACE ==== "
set interfaces vlan unit 200 family inet address 192.168.12.7/24
set interfaces vlan unit 300 description "                       ==== VLAN unit 300 INTERFACE ==== "
set interfaces vlan unit 300 family inet address 10.128.10.7/24
set interfaces vlan unit 500 description "                       ==== VLAN unit 500 INTERFACE ==== "
set interfaces vlan unit 500 family inet address 10.128.20.7/24
set routing-instances LAN description "                         ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set routing-instances OLDNET description "                         ==== OLDNET ROUTING INSTANCE ==== "
set routing-instances OLDNET instance-type virtual-router
set routing-instances OLDNET interface vlan.100
set routing-instances OLDNET interface vlan.200
set routing-instances OLDNET interface vlan.300
set routing-instances OLDNET interface vlan.500
set vlans v100 description "                                    ==== VLAN 100  LAB        ==== "
set vlans v100 vlan-id 100
set vlans v100 l3-interface vlan.100
set vlans v11 description "                                     ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "                                     ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12
set vlans v200 description "                                    ==== VLAN 200  PROD       ==== "
set vlans v200 vlan-id 200
set vlans v200 l3-interface vlan.200
set vlans v300 description "                                    ==== VLAN 300  TEST       ==== "
set vlans v300 vlan-id 300
set vlans v300 l3-interface vlan.300
set vlans v500 description "                                    ==== VLAN 500  DMZ        ==== "
set vlans v500 vlan-id 500
set vlans v500 l3-interface vlan.500
set vlans v700 description "                                    ==== VLAN 700  INTERNET   ==== "
set vlans v700 vlan-id 700
set poe interface all

 

 

ICMP checks from LAB to PROD and TEST

root@sheevaplug:~# ping 192.168.12.10
PING 192.168.12.10 (192.168.12.10) 56(84) bytes of data.
From 10.128.10.2: icmp_seq=1 Redirect Host(New nexthop: 10.128.10.7)
64 bytes from 192.168.12.10: icmp_req=3 ttl=62 time=1.57 ms


root@sheevaplug:~# ping 10.128.10.2
PING 10.128.10.2 (10.128.10.2) 56(84) bytes of data.
64 bytes from 10.128.10.2: icmp_req=1 ttl=64 time=4.28 ms

ICMP checks from PROD to LAB and TEST

$ ping 192.168.10.2
PING 192.168.10.2 (192.168.10.2): 56 data bytes
64 bytes from 192.168.10.2: icmp_seq=0 ttl=62 time=5.686 ms
2 packets transmitted, 2 packets received, 0.0% packet loss

$ ping 10.128.10.126
PING 10.128.10.126 (10.128.10.126): 56 data bytes
64 bytes from 10.128.10.126: icmp_seq=0 ttl=62 time=4.933 ms

ICMP checks from TEST to LAB and PROD

$ ping 192.168.10.2
PING 192.168.10.2 (192.168.10.2): 56 data bytes
64 bytes from 192.168.10.2: icmp_seq=0 ttl=63 time=2.586 ms
64 bytes from 192.168.10.2: icmp_seq=1 ttl=63 time=4.859 ms
64 bytes from 192.168.10.2: icmp_seq=2 ttl=63 time=3.944 ms
^C
--- 192.168.10.2 ping statistics ---
3 packets transmitted, 3 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 2.586/3.796/4.859/0.934 ms
qazwsxs-MBP-2:~ qazwsxedcrfv$ ping 192.168.12.10
PING 192.168.12.10 (192.168.12.10): 56 data bytes
64 bytes from 192.168.12.10: icmp_seq=0 ttl=62 time=48.238 ms
64 bytes from 192.168.12.10: icmp_seq=1 ttl=62 time=14.443 ms
64 bytes from 192.168.12.10: icmp_seq=2 ttl=62 time=1.915 ms
^C
--- 192.168.12.10 ping statistics ---
3 packets transmitted, 3 packets received, 0.0% packet loss
round-trip min/avg/max/stddev = 1.915/21.532/48.238/19.564 ms
qazwsxs-MBP-2:~ qazwsxedcrfv$


Request timeout for icmp_seq 60
Request timeout for icmp_seq 61
Request timeout for icmp_seq 62
Request timeout for icmp_seq 63
Request timeout for icmp_seq 64
Request timeout for icmp_seq 65
Request timeout for icmp_seq 66
(After changing the network)
64 bytes from 192.168.12.21: icmp_seq=67 ttl=64 time=9.239 ms
64 bytes from 192.168.12.21: icmp_seq=68 ttl=64 time=1.798 ms
64 bytes from 192.168.12.21: icmp_seq=69 ttl=64 time=1.447 ms
64 bytes from 192.168.12.21: icmp_seq=70 ttl=64 time=2.400 ms
64 bytes from 192.168.12.21: icmp_seq=71 ttl=64 time=1.162 ms
64 bytes from 192.168.12.21: icmp_seq=72 ttl=64 time=1.095 ms
64 bytes from 192.168.12.21: icmp_seq=73 ttl=64 time=1.090 ms

WLC wan-outage

image_pdfimage_print

 

 

Enable remote site and cached config, from the book


 

 

 

Set service-profile 00TESTwirelessNetwork as backup-ssid.


set service-profile 00TESTwirelessNetwork backup-ssid mode dual

 

Create remote-site REMOTE-SITE-HOUSE, configure local-switching, wlc-polling, vlans and cached config.


set remote-site REMOTE-SITE-HOUSE
set remote-site REMOTE-SITE-HOUSE local-switching mode enable
set remote-site REMOTE-SITE-HOUSE wlc-polling enable
set remote-site REMOTE-SITE-HOUSE vlan-profile PROFILE-VLANS
set remote-site REMOTE-SITE-HOUSE cached-config on

 

Set Access point 1 on remote-site REMOTE-SITE-HOUSE


set ap 1 remote-site REMOTE-SITE-HOUSE

This may cause the AP(s) to reboot. Are you sure? (y/n) [n]: y

Set Access point 1 as remote-ap, enable and tweak wan-outage.


set ap 1 remote-ap wan-outage mode enable
set ap 1 remote-ap wan-outage extended-timeout 72h
set ap 1 remote-ap wan-outage eval-period 5

 

Display AP configuration.


MXR-2# show ap config verbose
AP 1 (AP_FLOOR_2)
  Model:                  WLA522-WW
  Mode:
  Bias:                   high
  Options:                upgrade-firmware, local-switching, led-off
  Connection:             network
  High latency:           disabled
  Serial number:          kx0212509705
  Fingerprint:
  Remote site:            REMOTE-SITE-HOUSE (system country code BE is used)
  Communication timeout:  25
  Path MTU:               0
  Extended timeout:       0h
  Evaluation period:      300
  Location:
  Contact:
  Description:            AP located Floor 2
  Vlan-profile:           PROFILE-VLANS
  Tunnel affinity:        4
  AP Tunnel:              disabled
  Lldp-mode:              tx
  Lldp-med mode:          enable
  Power-via-mdi TLV:      disable
  Inventory TLV:          disable
Radio 1 (802.11ng)
  Mode:                 sentry
  Radio profile:        RADIO-PROFILE-WPA
  Channel:              auto              Load balancing:        YES
  Tx power:             auto              Load balancing group:
  Auto tune max power:  default           Force rebalance:       NO
  Antenna location:     indoors           Antenna type:          INTERNAL
  Service profiles:
    00TESTwirelessNetwork
    01PRODwirelessNetwork
    02LABwirelessNetwork
  Snoop filters on radio: none
  Snoop filters on radio profile: none
Radio 2 (802.11na)
  Mode:                 sentry
  Radio profile:        RADIO-PROFILE-WPA
  Channel:              auto              Load balancing:        YES
  Tx power:             auto              Load balancing group:
  Auto tune max power:  default           Force rebalance:       NO
  Antenna location:     indoors           Antenna type:          INTERNAL
  Service profiles:
    00TESTwirelessNetwork
    01PRODwirelessNetwork
    02LABwirelessNetwork
  Snoop filters on radio: none
  Snoop filters on radio profile: none

 

Full configuration.


# Configuration nvgen'd at 2017-10-10 19:41:08
# Image 9.6.0.2.0
# Model MXR-2
# Last change occurred at 2017-10-10 19:36:24
set ip route default 192.168.10.1 1
set ip dns domain lab.youaresecure.be
set ip dns enable
set ip dns server 192.168.10.2 PRIMARY
set log console enable severity info
set log session enable severity info
set log server 10.128.100.102 severity debug
set web-portal ssl-mode none
set system name MXR-2
set system ip-address 192.168.10.30
set system countrycode BE
set timezone CET 1 00
set service-profile 00TESTwirelessNetwork ssid-name "YouAreSecure TEST WLAN"
set service-profile 00TESTwirelessNetwork auth-fallthru last-resort
set service-profile 00TESTwirelessNetwork psk-encrypted 
set service-profile 00TESTwirelessNetwork multicast-conversion enable
set service-profile 00TESTwirelessNetwork backup-ssid mode dual
set service-profile 00TESTwirelessNetwork wpa-ie cipher-tkip enable
set service-profile 00TESTwirelessNetwork wpa-ie auth-psk enable
set service-profile 00TESTwirelessNetwork wpa-ie auth-dot1x disable
set service-profile 00TESTwirelessNetwork rsn-ie cipher-tkip enable
set service-profile 00TESTwirelessNetwork rsn-ie auth-psk enable
set service-profile 00TESTwirelessNetwork rsn-ie auth-dot1x disable
set service-profile 00TESTwirelessNetwork rsn-ie enable
set service-profile 00TESTwirelessNetwork attr vlan-name TESTVLAN
set service-profile 01PRODwirelessNetwork ssid-name "YouAreSecure PROD WLAN"
set service-profile 01PRODwirelessNetwork auth-fallthru last-resort
set service-profile 01PRODwirelessNetwork psk-encrypted 
set service-profile 01PRODwirelessNetwork wpa-ie cipher-ccmp enable
set service-profile 01PRODwirelessNetwork wpa-ie auth-psk enable
set service-profile 01PRODwirelessNetwork wpa-ie auth-dot1x disable
set service-profile 01PRODwirelessNetwork rsn-ie cipher-tkip enable
set service-profile 01PRODwirelessNetwork rsn-ie auth-psk enable
set service-profile 01PRODwirelessNetwork rsn-ie auth-dot1x disable
set service-profile 01PRODwirelessNetwork rsn-ie enable
set service-profile 01PRODwirelessNetwork attr vlan-name PRODVLAN
set service-profile 02LABwirelessNetwork ssid-name "YouAreSecure LAB WLAN"
set service-profile 02LABwirelessNetwork auth-fallthru last-resort
set service-profile 02LABwirelessNetwork psk-encrypted 0
set service-profile 02LABwirelessNetwork multicast-conversion enable
set service-profile 02LABwirelessNetwork wpa-ie auth-psk enable
set service-profile 02LABwirelessNetwork wpa-ie auth-dot1x disable
set service-profile 02LABwirelessNetwork rsn-ie cipher-tkip enable
set service-profile 02LABwirelessNetwork rsn-ie auth-psk enable
set service-profile 02LABwirelessNetwork rsn-ie auth-dot1x disable
set service-profile 02LABwirelessNetwork rsn-ie enable
set service-profile 02LABwirelessNetwork attr vlan-name default
set service-profile ProfileYouAreSecure ssid-name "YouAreSecure Guest WLAN"
set service-profile ProfileYouAreSecure ssid-type clear
set service-profile ProfileYouAreSecure auth-fallthru web-portal
set service-profile ProfileYouAreSecure web-portal-acl portalacl
set service-profile ProfileYouAreSecure wpa-ie auth-dot1x disable
set service-profile ProfileYouAreSecure rsn-ie auth-dot1x disable
set service-profile ProfileYouAreSecure attr vlan-name default
set vlan-profile PROFILE-VLANS vlan PRODVLAN tag 200
set vlan-profile PROFILE-VLANS vlan TESTVLAN tag 300
set vlan-profile PROFILE-VLANS vlan LABVLAN
set enablepass password 
set authentication web ssid "YouAreSecure Guest WLAN" ** local
set usergroup GuestNet attr vlan-name default
set user admin password encrypted 
set user admin group usersrsrsrsr
set user guest1 password encrypted 
set user guest1 group GuestNet
set user guest1 attr ssid YouAreSecure Guest WLAN
set user guest1 attr vlan-name default
set radio-profile RADIO-PROFILE-WPA
set radio-profile RADIO-PROFILE-WPA 11n channel-width-na 20MHz
set radio-profile RADIO-PROFILE-WPA power-policy max-coverage
set radio-profile RADIO-PROFILE-WPA service-profile 02LABwirelessNetwork
set radio-profile RADIO-PROFILE-WPA service-profile 01PRODwirelessNetwork
set radio-profile RADIO-PROFILE-WPA service-profile 00TESTwirelessNetwork
set radio-profile default power-policy max-coverage
set radio-profile default service-profile 02LABwirelessNetwork
set radio-profile default service-profile 01PRODwirelessNetwork
set radio-profile default service-profile 00TESTwirelessNetwork
set radio-profile default service-profile ProfileYouAreSecure
set remote-site REMOTE-SITE-HOUSE
set remote-site REMOTE-SITE-HOUSE local-switching mode enable
set remote-site REMOTE-SITE-HOUSE vlan-profile PROFILE-VLANS
set remote-site REMOTE-SITE-HOUSE wan-outage mode enable extended-timeout 72h eval-period 5
set remote-site REMOTE-SITE-HOUSE wlc-polling enable
set remote-site REMOTE-SITE-HOUSE cached-config on
set ap auto mode enable
set ap auto force-image-download enable
set ap 1 serial-id kx0212509705 remote-site REMOTE-SITE-HOUSE model WLA522-WW
set ap 1 name AP_FLOOR_2
set ap 1 led-mode off
set ap 1 description AP located Floor 2
set ap 1 radio 1 radio-profile RADIO-PROFILE-WPA
set ap 1 radio 2 radio-profile RADIO-PROFILE-WPA
set ap 1 local-switching mode enable vlan-profile PROFILE-VLANS
set ap 2 serial-id KX0212422852 model WLA522-WW
set ap 2 name AP_FLOOR_1
set ap 2 radio 1 radio-profile RADIO-PROFILE-WPA mode enable
set ap 2 radio 2 radio-profile RADIO-PROFILE-WPA mode enable
set ap 2 local-switching mode enable vlan-profile PROFILE-VLANS
set ap 3 serial-id KX0212511571 model WLA522-WW
set ap 3 name AP_FLOOR_0
set ap 3 led-mode off
set ap 3 location Ground Floor
set ap 3 radio 1 mode enable
set ap 3 radio 2 mode enable
set ap 3 local-switching mode enable vlan-profile PROFILE-VLANS
set ap 5 serial-id 09E3700966 model MP-82
set ap 5 name AP_UNDERGROUND
set ap 5 radio 1 radio-profile RADIO-PROFILE-WPA mode enable
set ap 5 radio 2 radio-profile RADIO-PROFILE-WPA mode enable
set ap 5 local-switching mode enable vlan-profile PROFILE-VLANS
set ip snmp server enable
set ip telnet server enable
set band-preference 5ghz strictness low
set snmp protocol v2c enable
set snmp protocol usm enable
set vlan 1 port 1
set vlan 200 name PRODVLAN
set vlan 200 port 1 tag 200
set vlan 300 name TESTVLAN
set vlan 300 port 1 tag 300
set vlan 300 port 2 tag 300
set vlan 500 name DMZGUESTVLAN
set vlan 500 port 1 tag 500
set vlan 500 port 2 tag 500
set interface 1 ip 192.168.10.30 255.255.255.0
set interface 200 ip 192.168.12.30 255.255.255.0
set interface 300 ip 10.128.10.30 255.255.255.0
set snmp community name public access read-only
set security acl name portalacl permit udp 0.0.0.0 255.255.255.255 eq 68 0.0.0.0 255.255.255.255 eq 67
set security acl name portalacl deny 0.0.0.0 255.255.255.255 capture
commit security acl portalacl
set ntp enable
set ntp update-interval 1024
set ntp server 46.254.216.12
set ntp server 91.121.160.173
set ntp server 185.77.199.1
MXR-2#

References


Juniper

WLC set radio-profile

image_pdfimage_print
MXR-2# show configuration
# Configuration nvgen'd at 2017-10-09 22:02:56
# Image 9.6.0.2.0
# Model MXR-2
# Last change occurred at 2017-10-09 21:42:37
set ip route default 192.168.10.1 1
set ip dns domain lab.youaresecure.be
set ip dns enable
set ip dns server 192.168.10.2 PRIMARY
set log console enable severity info
set log session enable severity info
set log server 10.128.100.102 severity debug
set web-portal ssl-mode none
set system name MXR-2
set system ip-address 192.168.10.30
set system countrycode BE
set timezone CET 1 00
set service-profile 00TESTwirelessNetwork ssid-name "YouAreSecure TEST WLAN"
set service-profile 00TESTwirelessNetwork auth-fallthru last-resort
set service-profile 00TESTwirelessNetwork psk-encrypted 
set service-profile 00TESTwirelessNetwork multicast-conversion enable
set service-profile 00TESTwirelessNetwork wpa-ie cipher-tkip enable
set service-profile 00TESTwirelessNetwork wpa-ie auth-psk enable
set service-profile 00TESTwirelessNetwork wpa-ie auth-dot1x disable
set service-profile 00TESTwirelessNetwork rsn-ie cipher-tkip enable
set service-profile 00TESTwirelessNetwork rsn-ie auth-psk enable
set service-profile 00TESTwirelessNetwork rsn-ie auth-dot1x disable
set service-profile 00TESTwirelessNetwork rsn-ie enable
set service-profile 00TESTwirelessNetwork attr vlan-name TESTVLAN
set service-profile 01PRODwirelessNetwork ssid-name "YouAreSecure PROD WLAN"
set service-profile 01PRODwirelessNetwork auth-fallthru last-resort
set service-profile 01PRODwirelessNetwork psk-encrypted 
set service-profile 01PRODwirelessNetwork wpa-ie cipher-ccmp enable
set service-profile 01PRODwirelessNetwork wpa-ie auth-psk enable
set service-profile 01PRODwirelessNetwork wpa-ie auth-dot1x disable
set service-profile 01PRODwirelessNetwork rsn-ie cipher-tkip enable
set service-profile 01PRODwirelessNetwork rsn-ie auth-psk enable
set service-profile 01PRODwirelessNetwork rsn-ie auth-dot1x disable
set service-profile 01PRODwirelessNetwork rsn-ie enable
set service-profile 01PRODwirelessNetwork attr vlan-name PRODVLAN
set service-profile 02LABwirelessNetwork ssid-name "YouAreSecure LAB WLAN"
set service-profile 02LABwirelessNetwork auth-fallthru last-resort
set service-profile 02LABwirelessNetwork psk-encrypted 
set service-profile 02LABwirelessNetwork multicast-conversion enable
set service-profile 02LABwirelessNetwork wpa-ie auth-psk enable
set service-profile 02LABwirelessNetwork wpa-ie auth-dot1x disable
set service-profile 02LABwirelessNetwork rsn-ie cipher-tkip enable
set service-profile 02LABwirelessNetwork rsn-ie auth-psk enable
set service-profile 02LABwirelessNetwork rsn-ie auth-dot1x disable
set service-profile 02LABwirelessNetwork rsn-ie enable
set service-profile 02LABwirelessNetwork attr vlan-name default
set service-profile ProfileYouAreSecure ssid-name "YouAreSecure Guest WLAN"
set service-profile ProfileYouAreSecure ssid-type clear
set service-profile ProfileYouAreSecure auth-fallthru web-portal
set service-profile ProfileYouAreSecure web-portal-acl portalacl
set service-profile ProfileYouAreSecure wpa-ie auth-dot1x disable
set service-profile ProfileYouAreSecure rsn-ie auth-dot1x disable
set service-profile ProfileYouAreSecure attr vlan-name default
set vlan-profile PROFILE-VLANS vlan PRODVLAN tag 200
set vlan-profile PROFILE-VLANS vlan TESTVLAN tag 300
set vlan-profile PROFILE-VLANS vlan LABVLAN
set enablepass password 
set authentication web ssid "YouAreSecure Guest WLAN" ** local
set usergroup GuestNet attr vlan-name default
set user admin password encrypted 
set user admin group usersrsrsrsr
set user guest1 password encrypted 
set user guest1 group GuestNet
set user guest1 attr ssid YouAreSecure Guest WLAN
set user guest1 attr vlan-name default
set radio-profile RADIO-PROFILE-WPA
set radio-profile RADIO-PROFILE-WPA 11n channel-width-na 20MHz
set radio-profile RADIO-PROFILE-WPA power-policy max-coverage
set radio-profile RADIO-PROFILE-WPA service-profile 02LABwirelessNetwork
set radio-profile RADIO-PROFILE-WPA service-profile 01PRODwirelessNetwork
set radio-profile RADIO-PROFILE-WPA service-profile 00TESTwirelessNetwork
set radio-profile default power-policy max-coverage
set radio-profile default service-profile 02LABwirelessNetwork
set radio-profile default service-profile 01PRODwirelessNetwork
set radio-profile default service-profile 00TESTwirelessNetwork
set radio-profile default service-profile ProfileYouAreSecure
set ap auto mode enable
set ap auto force-image-download enable
set ap 1 serial-id kx0212509705 model WLA522-WW
set ap 1 name AP_FLOOR_2
set ap 1 led-mode off
set ap 1 description AP located Floor 2
set ap 1 radio 1 radio-profile RADIO-PROFILE-WPA channel 1 mode enable
set ap 1 radio 2 radio-profile RADIO-PROFILE-WPA mode enable
set ap 1 local-switching mode enable vlan-profile PROFILE-VLANS
set ap 2 serial-id KX0212422852 model WLA522-WW
set ap 2 name AP_FLOOR_1
set ap 2 radio 1 radio-profile RADIO-PROFILE-WPA mode enable
set ap 2 radio 2 radio-profile RADIO-PROFILE-WPA mode enable
set ap 2 local-switching mode enable vlan-profile PROFILE-VLANS
set ap 3 serial-id KX0212511571 model WLA522-WW
set ap 3 name AP_FLOOR_0
set ap 3 led-mode off
set ap 3 location Ground Floor
set ap 3 radio 1 mode enable
set ap 3 radio 2 mode enable
set ap 3 local-switching mode enable vlan-profile PROFILE-VLANS
set ap 5 serial-id 09E3700966 model MP-82
set ap 5 name AP_UNDERGROUND
set ap 5 radio 1 radio-profile RADIO-PROFILE-WPA mode enable
set ap 5 radio 2 radio-profile RADIO-PROFILE-WPA mode enable
set ap 5 local-switching mode enable vlan-profile PROFILE-VLANS
set ip snmp server enable
set ip telnet server enable
set snmp protocol v2c enable
set snmp protocol usm enable
set vlan 1 port 1
set vlan 200 name PRODVLAN
set vlan 200 port 1 tag 200
set vlan 300 name TESTVLAN
set vlan 300 port 1 tag 300
set vlan 300 port 2 tag 300
set vlan 500 name DMZGUESTVLAN
set vlan 500 port 1 tag 500
set vlan 500 port 2 tag 500
set interface 1 ip 192.168.10.30 255.255.255.0
set interface 200 ip 192.168.12.30 255.255.255.0
set interface 300 ip 10.128.10.30 255.255.255.0
set snmp community name public access read-only
set security acl name portalacl permit udp 0.0.0.0 255.255.255.255 eq 68 0.0.0.0 255.255.255.255 eq 67
set security acl name portalacl deny 0.0.0.0 255.255.255.255 capture
commit security acl portalacl
set ntp enable
set ntp update-interval 1024
set ntp server 46.254.216.12
set ntp server 91.121.160.173
set ntp server 185.77.199.1
MXR-2#

WLC local-switching

image_pdfimage_print

 

show ap config


 

MXR-2# show ap config
5 APs configured
AP   AP Name          Model      Mode     Radio 1 profile  Radio 2 profile
---- ---------------- ---------- -------- ---------------- ----------------
auto                             enabled  default          default
   1 KX0212509705     WLA522-WW           default          default
   2 AP3207           WLA522-WW           default          default
   3 AP_3209_0        WLA522-WW           default          default
   5 AP-071           MP-82               default          default

 

show ap connection


 

MXR-2# show  ap connection
Total number of entries: 4
AP   Serial Id   AP IP Address   Switch IP Address
---- ----------- --------------- -----------------
1    kx0212509705 192.168.10.241  192.168.10.30
2    kx0212422852 192.168.10.242  192.168.10.30
3    kx0212511571 192.168.10.243  192.168.10.30
5    09e3700966  192.168.10.244  192.168.10.30

 

Show ap vlan


 

MXR-2# show ap vlan
AP 1:
VLAN Name             Mode    Port             Tag
---- ---------------- ----    ---------------- ----
4095 LABVLAN          local
                                          eth1 none

AP 2:
VLAN Name             Mode    Port             Tag
---- ---------------- ----    ---------------- ----
4095 LABVLAN          local
                                          eth1 none

AP 3:
VLAN Name             Mode    Port             Tag
---- ---------------- ----    ---------------- ----
200  PRODVLAN         local
                                          eth1  200
                                       radio_2    8
1    default          tunnel
                                         mxtun    1
                                       radio_1    1
                                       radio_2    2
4095 LABVLAN          local
                                          eth1 none

AP 5:
VLAN Name             Mode    Port             Tag
---- ---------------- ----    ---------------- ----
4095 LABVLAN          local
                                          eth1 none

 

show ap fdb


 

MXR-2# show ap fdb
AP 1:
# = system, $ = authenticated
VLAN TAG  Destination MAC    [CoS] Bucket Destination Ports
---- ---- ------------------ ----- ------ -----------------
4095    0 9c:d3:5b:de:4b:ed            56         eth0
4095    0 40:b4:f0:a6:e0:c0            b2         eth0
4095    0 04:18:d6:26:5d:cf            ef         eth0
4095    0 fc:83:99:a5:c4:01           115         eth0
4095    0 00:50:43:6a:20:2b           18c         eth0
4095    0 00:08:da:51:23:04           248         eth0
4095    0 00:0b:0e:5b:f0:ec           35b         eth0
4095 4095 40:b4:f0:a5:fb:80      #    373          CPU
4095    0 30:07:4d:bd:80:7d           399         eth0
4095    0 80:d2:1d:25:2e:5e           3ff         eth0
Total Matching AP FDB Entries Displayed = 10
dynamic= 9, static= 0, system= 1, authenticated= 0

AP 2:
# = system, $ = authenticated
VLAN TAG  Destination MAC    [CoS] Bucket Destination Ports
---- ---- ------------------ ----- ------ -----------------
4095    0 9c:d3:5b:de:4b:ed            56         eth0
4095    0 40:b4:f0:a6:e0:c0            b2         eth0
4095    0 04:18:d6:26:5d:cf            ef         eth0
4095    0 fc:83:99:a5:c4:01           115         eth0
4095    0 00:50:43:6a:20:2b           18c         eth0
4095 4095 40:b4:f0:15:1b:40      #    230          CPU
4095    0 00:08:da:51:23:04           248         eth0
4095    0 00:0b:0e:5b:f0:ec           35b         eth0
4095    0 30:07:4d:bd:80:7d           399         eth0
4095    0 80:d2:1d:25:2e:5e           3ff         eth0
Total Matching AP FDB Entries Displayed = 10
dynamic= 9, static= 0, system= 1, authenticated= 0

AP 3:
# = system, $ = authenticated
VLAN TAG  Destination MAC    [CoS] Bucket Destination Ports
---- ---- ------------------ ----- ------ -----------------
4095    0 00:1a:70:a1:93:c6            11         eth0
4095    0 9c:d3:5b:de:4b:ed            56         eth0
   1    2 30:07:4d:bd:80:7d      $     81      radio_2
 200  200 40:b4:f0:a6:e0:c0      #     b1          CPU
4095 4095 40:b4:f0:a6:e0:c0      #     b2          CPU
4095    0 fc:83:99:a5:c4:40            d5         eth0
   1    1 80:d2:1d:25:2e:5e      $     e7      radio_1
4095    0 04:18:d6:26:5d:cf            ef         eth0
 200  200 00:23:9c:3f:9e:0b           100         eth0
4095    0 fc:83:99:a5:c4:01           115         eth0
 200  200 fc:83:99:a5:c4:41           161         eth0
4095    0 00:50:43:6a:20:2b           18c         eth0
4095    0 00:08:da:51:23:04           248         eth0
   1    1 d0:87:e2:96:0e:b9      $    269      radio_1
   1    1 24:0d:c2:1c:69:2f      $    297      radio_1
 200  200 00:0f:66:7e:f9:df           2e9         eth0
   1    1 9c:d3:5b:de:4b:ed      $    34e      radio_1
 200    8 f4:5c:89:92:f8:61      $    355      radio_2
 200  200 00:0b:0e:5b:f0:ec           358         eth0
4095    0 00:0b:0e:5b:f0:ec           35b         eth0
4095    0 30:07:4d:bd:80:7d           399         eth0
   1    1 40:b4:f0:a6:e0:c0      #    3aa          CPU
4095    0 80:d2:1d:25:2e:5e           3ff         eth0
Total Matching AP FDB Entries Displayed = 23
dynamic= 14, static= 0, system= 3, authenticated= 6

AP 5:
# = system, $ = authenticated
VLAN TAG  Destination MAC    [CoS] Bucket Destination Ports
---- ---- ------------------ ----- ------ -----------------
4095    0 9c:d3:5b:de:4b:ed            56         eth0
4095    0 40:b4:f0:a6:e0:c0            b2         eth0
4095    0 04:18:d6:26:5d:cf            ef         eth0
4095    0 fc:83:99:a5:c4:01           115         eth0
4095    0 00:50:43:6a:20:2b           18c         eth0
4095 4095 00:26:3e:23:80:c0      #    23a          CPU
4095    0 00:08:da:51:23:04           248         eth0
4095    0 00:0b:0e:5b:f0:ec           35b         eth0
4095    0 30:07:4d:bd:80:7d           399         eth0
4095    0 80:d2:1d:25:2e:5e           3ff         eth0
Total Matching AP FDB Entries Displayed = 10
dynamic= 9, static= 0, system= 1, authenticated= 0

 

show ap arp


 

MXR-2# show  ap arp
AP 1:
Host                           HW Address        VLAN  State    Type
------------------------------ ----------------- ----- -------- -------
192.168.10.2                   00:1a:70:a1:93:c6  4095 RESOLVED DYNAMIC
192.168.10.7                   fc:83:99:a5:c4:40  4095 RESOLVED DYNAMIC
192.168.10.30                  00:0b:0e:5b:f0:ec  4095 RESOLVED DYNAMIC
192.168.10.1                   00:08:da:51:23:04  4095 RESOLVED DYNAMIC

AP 2:
Host                           HW Address        VLAN  State    Type
------------------------------ ----------------- ----- -------- -------
192.168.10.2                   00:1a:70:a1:93:c6  4095 RESOLVED DYNAMIC
192.168.10.7                   fc:83:99:a5:c4:40  4095 RESOLVED DYNAMIC
192.168.10.30                  00:0b:0e:5b:f0:ec  4095 RESOLVED DYNAMIC
192.168.10.1                   00:08:da:51:23:04  4095 RESOLVED DYNAMIC

AP 3:
Host                           HW Address        VLAN  State    Type
------------------------------ ----------------- ----- -------- -------
192.168.10.2                   00:1a:70:a1:93:c6  4095 RESOLVED DYNAMIC
192.168.10.7                   fc:83:99:a5:c4:40  4095 RESOLVED DYNAMIC
192.168.10.30                  00:0b:0e:5b:f0:ec  4095 RESOLVED DYNAMIC
192.168.10.1                   00:08:da:51:23:04  4095 RESOLVED DYNAMIC

AP 5:
Host                           HW Address        VLAN  State    Type
------------------------------ ----------------- ----- -------- -------
192.168.10.2                   00:1a:70:a1:93:c6  4095 RESOLVED DYNAMIC
192.168.10.7                   fc:83:99:a5:c4:40  4095 RESOLVED DYNAMIC
192.168.10.30                  00:0b:0e:5b:f0:ec  4095 RESOLVED DYNAMIC
192.168.10.1                   00:08:da:51:23:04  4095 RESOLVED DYNAMIC

MXR-2#

show sessions network ap

MXR-2> show sessions network ap

6 sessions total

AP 2 (AP3207)
User Name                Sess   Address              VLAN              Radio Band
-----------------------  -----  -------------------- ----------------  ----- -----
LR-YouAreSecure LAB WL~   2053* 192.168.10.40,V6     default             1   11g

AP 3 (AP_FLOOR_0) Ground Floor
User Name                Sess   Address              VLAN              Radio Band
-----------------------  -----  -------------------- ----------------  ----- -----
LR-YouAreSecure LAB WL~   2009* 192.168.10.52,V6     default             1   11g
LR-YouAreSecure LAB WL~   2048* 192.168.10.247,V6    default             1   11g
LR-YouAreSecure LAB WL~   2047* 192.168.10.50,V6     default             2   11a
LR-YouAreSecure PROD W~   2052* 192.168.12.233,V6    PRODVLAN        L   2   11a
LR-YouAreSecure LAB WL~   2013* 192.168.10.142,V6    default             1   11g

aaa

MXR-2> show sessions

6 sessions total

User Name             SessID  Type  Address              VLAN              AP/Rdo
--------------------- ------  ----- -------------------- --------------    -------
LR-YouAreSecure LAB ~   2053* open  192.168.10.40,V6     default             2/1
LR-YouAreSecure PROD~   2052* open  192.168.12.233,V6    PRODVLAN        L   3/2
LR-YouAreSecure LAB ~   2047* open  192.168.10.50,V6     default             3/2
LR-YouAreSecure LAB ~   2013* open  192.168.10.142,V6    default             3/1
LR-YouAreSecure LAB ~   2009* open  192.168.10.52,V6     default             3/1
LR-YouAreSecure LAB ~   2048* open  192.168.10.247,V6    default             3/1

show version details ap 1

MXR-2> show version details ap 1

        Mobility System Software, Version: 9.6.0.2 REL
        Copyright (c) 2002 - 2013 Juniper Networks, Inc. All rights reserved.

Build Information: (build#0) REL_9_6_0_branch 2016-03-16 13:07:00
Label:             REL_9.6.0.2.0_031616
Build Suffix:      -d-O1
Model:             MXR-2
Hardware
   Mainboard:      version 0 ; revision M
   CPU Model:      405EP (Revision 9.80)
Serial number      0722200023
Flash:             1.0.0 - 0
Kernel:            6.3.0
BootLoader:        7.1 /

AP    AP Model     Serial #       Versions
----- ------------ -------------- ------------------------
 1    WLA522-WW    KX0212509705   H/W  : A09
                         F/W1 : 128.2
                         F/W2 : 128.2
                         S/W  : REL_9.6.0.2.0_031616
                    BOOT S/W  : REL_9.6.0.2.0_031616
                  fingerprint : 4d:f8:b8:ed:eb:1e:3d:8c:7c:1d:c3:de:76:70:9a:84

Disable Leds

MXR-2# set ap 3 led-mode off

 

configuration


 

# Configuration nvgen'd at 2017-9-29 22:30:26
# Image 9.6.0.2.0
# Model MXR-2
# Last change occurred at 2017-9-29 22:28:04
set ip route default 192.168.10.1 1
set ip dns domain lab.youaresecure.be
set ip dns enable
set ip dns server 192.168.10.2 PRIMARY
set log console enable severity info
set log session enable severity info
set log server 10.128.100.102 severity debug
set web-portal ssl-mode none
set system name MXR-2
set system ip-address 192.168.10.30
set system countrycode BE
set timezone CET 1 00
set service-profile 00TESTwirelessNetwork ssid-name "YouAreSecure TEST WLAN"
set service-profile 00TESTwirelessNetwork auth-fallthru last-resort
set service-profile 00TESTwirelessNetwork psk-encrypted 0509
set service-profile 00TESTwirelessNetwork multicast-conversion enable
set service-profile 00TESTwirelessNetwork wpa-ie cipher-tkip enable
set service-profile 00TESTwirelessNetwork wpa-ie auth-psk enable
set service-profile 00TESTwirelessNetwork wpa-ie auth-dot1x disable
set service-profile 00TESTwirelessNetwork rsn-ie cipher-tkip enable
set service-profile 00TESTwirelessNetwork rsn-ie auth-psk enable
set service-profile 00TESTwirelessNetwork rsn-ie auth-dot1x disable
set service-profile 00TESTwirelessNetwork rsn-ie enable
set service-profile 00TESTwirelessNetwork attr vlan-name TESTVLAN
set service-profile 01PRODwirelessNetwork ssid-name "YouAreSecure PROD WLAN"
set service-profile 01PRODwirelessNetwork auth-fallthru last-resort
set service-profile 01PRODwirelessNetwork psk-encrypted 094
set service-profile 01PRODwirelessNetwork wpa-ie cipher-ccmp enable
set service-profile 01PRODwirelessNetwork wpa-ie auth-psk enable
set service-profile 01PRODwirelessNetwork wpa-ie auth-dot1x disable
set service-profile 01PRODwirelessNetwork rsn-ie cipher-tkip enable
set service-profile 01PRODwirelessNetwork rsn-ie auth-psk enable
set service-profile 01PRODwirelessNetwork rsn-ie auth-dot1x disable
set service-profile 01PRODwirelessNetwork rsn-ie enable
set service-profile 01PRODwirelessNetwork attr vlan-name PRODVLAN
set service-profile 02LABwirelessNetwork ssid-name "YouAreSecure LAB WLAN"
set service-profile 02LABwirelessNetwork auth-fallthru last-resort
set service-profile 02LABwirelessNetwork psk-encrypted 050e570e781c1
set service-profile 02LABwirelessNetwork multicast-conversion enable
set service-profile 02LABwirelessNetwork wpa-ie auth-psk enable
set service-profile 02LABwirelessNetwork wpa-ie auth-dot1x disable
set service-profile 02LABwirelessNetwork rsn-ie cipher-tkip enable
set service-profile 02LABwirelessNetwork rsn-ie auth-psk enable
set service-profile 02LABwirelessNetwork rsn-ie auth-dot1x disable
set service-profile 02LABwirelessNetwork rsn-ie enable
set service-profile 02LABwirelessNetwork attr vlan-name default
set service-profile ProfileYouAreSecure ssid-name "YouAreSecure Guest WLAN"
set service-profile ProfileYouAreSecure ssid-type clear
set service-profile ProfileYouAreSecure auth-fallthru web-portal
set service-profile ProfileYouAreSecure web-portal-acl portalacl
set service-profile ProfileYouAreSecure wpa-ie auth-dot1x disable
set service-profile ProfileYouAreSecure rsn-ie auth-dot1x disable
set service-profile ProfileYouAreSecure attr vlan-name default
set vlan-profile PROFILE-VLANS vlan PRODVLAN tag 200
set vlan-profile PROFILE-VLANS vlan TESTVLAN tag 300
set vlan-profile PROFILE-VLANS vlan LABVLAN
set enablepass password 
set authentication web ssid "YouAreSecure Guest WLAN" ** local
set usergroup GuestNet attr vlan-name default
set user admin password encrypted 010
set user admin group usersrsrsrsr
set user guest1 password encrypted 12
set user guest1 group GuestNet
set user guest1 attr ssid YouAreSecure Guest WLAN
set user guest1 attr vlan-name default
set radio-profile default power-policy max-coverage
set radio-profile default service-profile 02LABwirelessNetwork
set radio-profile default service-profile 01PRODwirelessNetwork
set radio-profile default service-profile 00TESTwirelessNetwork
set radio-profile default service-profile ProfileYouAreSecure
set ap auto mode enable
set ap auto force-image-download enable
set ap 1 serial-id kx0212509705 model WLA522-WW
set ap 1 name KX0212509705
set ap 1 radio 1 channel 1 mode enable
set ap 1 radio 2 mode enable
set ap 1 local-switching mode enable vlan-profile PROFILE-VLANS
set ap 2 serial-id KX0212422852 model WLA522-WW
set ap 2 name AP3207
set ap 2 radio 1 mode enable
set ap 2 radio 2 mode enable
set ap 2 local-switching mode enable vlan-profile PROFILE-VLANS
set ap 3 serial-id KX0212511571 model WLA522-WW
set ap 3 name AP_3209_0
set ap 3 radio 1 mode enable
set ap 3 radio 2 mode enable
set ap 3 local-switching mode enable vlan-profile PROFILE-VLANS
set ap 5 serial-id 09E3700966 model MP-82
set ap 5 name AP-071
set ap 5 radio 1 mode enable
set ap 5 radio 2 mode enable
set ap 5 local-switching mode enable vlan-profile PROFILE-VLANS
set ip snmp server enable
set ip telnet server enable
set snmp protocol v2c enable
set snmp protocol usm enable
set vlan 1 port 1
set vlan 200 name PRODVLAN
set vlan 200 port 1 tag 200
set vlan 300 name TESTVLAN
set vlan 300 port 1 tag 300
set vlan 300 port 2 tag 300
set vlan 500 name DMZGUESTVLAN
set vlan 500 port 1 tag 500
set vlan 500 port 2 tag 500
set interface 1 ip 192.168.10.30 255.255.255.0
set interface 200 ip 192.168.12.30 255.255.255.0
set interface 300 ip 10.128.10.30 255.255.255.0
set snmp community name public access read-only
set security acl name portalacl permit udp 0.0.0.0 255.255.255.255 eq 68 0.0.0.0 255.255.255.255 eq 67
set security acl name portalacl deny 0.0.0.0 255.255.255.255 capture
commit security acl portalacl
set ntp enable
set ntp update-interval 1024
set ntp server 46.254.216.12
set ntp server 91.121.160.173
set ntp server 185.77.199.1

References


Avaya local-switching

[final] SRX 220 ex2200 routing instance + dhcp server + IPSEC + redundant aggregated interfaces ethernet-switching port-mode trunk, Source NAT and redundat tagged + probes

image_pdfimage_print

Is never final, but, up to date.

EX2200 STOCKELA-SW-EX01


Show hardware


run show chassis hardware
Hardware inventory:
Item             Version  Part number  Serial number     Description
Chassis                                CV0212151670      EX2200-24P-4G
Routing Engine 0 REV 18   750-026464   CV0212151670      EX2200-24P-4G, POE
FPC 0            REV 18   750-026464   CV0212151670      EX2200-24P-4G, POE
  CPU                     BUILTIN      BUILTIN           FPC CPU
  PIC 0                   BUILTIN      BUILTIN           24x 10/100/1000 Base-T
  PIC 1          REV 18   750-026464   CV0212151670      4x GE SFP
Power Supply 0                                           PS 550W AC
Fan Tray                                                 Fan Tray

 

set version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set chassis aggregated-devices ethernet device-count 2
set interfaces ge-0/0/1 unit 0 family ethernet-switching
set interfaces ge-0/0/5 unit 0 family ethernet-switching
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v11
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "           ==== ae0  TRUNK to SRX node 0 ==== "
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members all
set interfaces ae1 description "           ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 aggregated-ether-options lacp active
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members all
set interfaces me0 description "           ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "  ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "  ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set routing-instances LAN description "   ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set vlans v11 description "               ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "               ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12

 

EX2200 Updated configuration 1/Nov/2017


snmp configured
Interfaces description improved.
Vlans 100,200,300,500 for replacing avaya.

et version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set chassis aggregated-devices ethernet device-count 2
set interfaces ge-0/0/0 description "                           ==== RESERVED FOR LAB  === "
set interfaces ge-0/0/0 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/1 description "                           ==== RESERVED FOR PROD  === "
set interfaces ge-0/0/1 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/2 description "                           ==== RESERVED FOR TEST  === "
set interfaces ge-0/0/2 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/2 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/3 description "                           ==== RESERVED FOR DMZ  === "
set interfaces ge-0/0/3 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/3 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/4 description "                           ==== RESERVED FOR OFFICE  === "
set interfaces ge-0/0/4 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/4 unit 0 family ethernet-switching native-vlan-id 200
set interfaces ge-0/0/5 description "                           ==== RESERVED FOR NUC  === "
set interfaces ge-0/0/5 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/5 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/6 description "                           ==== RESERVED FOR SHEEVA MAIN to LAB  === "
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/7 description "                           ==== RESERVED FOR v12  === "
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/11 description "                          ==== RESERVED FOR WLC  === "
set interfaces ge-0/0/11 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/11 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/12 description "                          ==== RESERVED FOR AP 1 === "
set interfaces ge-0/0/12 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/12 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/13 description "                          ==== RESERVED FOR AP 2 === "
set interfaces ge-0/0/13 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/13 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/14 description "                          ==== RESERVED FOR AP 3 === "
set interfaces ge-0/0/14 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/14 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/15 description "                          ==== RESERVED FOR AP 4 === "
set interfaces ge-0/0/15 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/15 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/16 description "                          ==== ge-0/0/16 V700 member === "
set interfaces ge-0/0/16 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/16 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/17 description "                          ==== ge-0/0/17 V700 member === "
set interfaces ge-0/0/17 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/17 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/18 description "                          ==== ge-0/0/18 V700 member === "
set interfaces ge-0/0/18 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/18 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/19 description "                          ==== ge-0/0/19 V700 member === "
set interfaces ge-0/0/19 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/19 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/20 description "                          ==== ge-0/0/20 ae0 member === "
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 description "                          ==== ge-0/0/21 ae0 member === "
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 description "                          ==== ge-0/0/22 ae1 member === "
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 description "                          ==== ge-0/0/23 ae1 member === "
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "                                ==== ae0  TRUNK to SRX node 0 ==== "
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members v11
set interfaces ae0 unit 0 family ethernet-switching vlan members v12
set interfaces ae1 description "                                ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 aggregated-ether-options lacp active
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members v11
set interfaces ae1 unit 0 family ethernet-switching vlan members v12
set interfaces me0 description "                                ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "                       ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "                       ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set interfaces vlan unit 100 description "                       ==== VLAN unit 100 INTERFACE ==== "
set interfaces vlan unit 100 family inet address 192.168.10.7/24
set interfaces vlan unit 200 description "                       ==== VLAN unit 200 INTERFACE ==== "
set interfaces vlan unit 200 family inet address 192.168.12.7/24
set interfaces vlan unit 300 description "                       ==== VLAN unit 300 INTERFACE ==== "
set interfaces vlan unit 300 family inet address 10.128.10.7/24
set interfaces vlan unit 500 description "                       ==== VLAN unit 500 INTERFACE ==== "
set interfaces vlan unit 500 family inet address 10.128.20.7/24
set snmp name "snmp STOCKEL A SW EX01"
set snmp description "community public for networks 192.168.10.0 192.168.12.0"
set snmp location "Rack A"
set snmp contact "Rafael.Torrales@gmail.com"
set snmp client-list list0 192.168.12.0/24
set snmp community public authorization read-only
set snmp community public client-list-name list0
set snmp trap-group STOCKEL-TRAPS destination-port 514
set snmp trap-group STOCKEL-TRAPS targets 192.168.12.185
set routing-instances LAN description "                         ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set routing-instances OLDNET description "                         ==== OLDNET ROUTING INSTANCE ==== "
set routing-instances OLDNET instance-type virtual-router
set routing-instances OLDNET interface vlan.100
set routing-instances OLDNET interface vlan.200
set routing-instances OLDNET interface vlan.300
set routing-instances OLDNET interface vlan.500
set vlans v100 description "                                    ==== VLAN 100  LAB        ==== "
set vlans v100 vlan-id 100
set vlans v100 l3-interface vlan.100
set vlans v11 description "                                     ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "                                     ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12
set vlans v200 description "                                    ==== VLAN 200  PROD       ==== "
set vlans v200 vlan-id 200
set vlans v200 l3-interface vlan.200
set vlans v300 description "                                    ==== VLAN 300  TEST       ==== "
set vlans v300 vlan-id 300
set vlans v300 l3-interface vlan.300
set vlans v500 description "                                    ==== VLAN 500  DMZ        ==== "
set vlans v500 vlan-id 500
set vlans v500 l3-interface vlan.500
set vlans v700 description "                                    ==== VLAN 700  INTERNET   ==== "
set vlans v700 vlan-id 700
set poe interface all

 

EX2200 Update November 12th.


Added DNS server.
Added NTP server.

Added rpm probe.

Improved interfaces’s descriptions.

Add static route for me0 interface.

 

 

set version 12.3R12.4
set system host-name STOCKELA-SW-EX01
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system name-server 192.168.12.10
set system services ssh
set system syslog host 10.128.100.102 any any
set system syslog file messages any info
set system syslog file default-log-messages any any
set system ntp server 193.104.37.238
set system ntp server 213.189.188.3
set chassis aggregated-devices ethernet device-count 2
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW probe-type icmp-ping-timestamp
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW target address 192.168.10.1
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW probe-count 10
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW probe-interval 20
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW test-interval 4
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW routing-instance OLDNET
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW history-size 20
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW moving-average-size 10
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW thresholds ingress-time 1000000
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW traps ingress-time-exceeded
set services rpm probe PROBE1_OLDNET test TEST1_ICMP_LAB_GW hardware-timestamp
set interfaces ge-0/0/0 description "                           ==== ge-0/0/0 FOR LAB  LAN === "
set interfaces ge-0/0/0 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/1 description "                           ==== ge-0/0/1 RESERVED FOR PROD LAN === "
set interfaces ge-0/0/1 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/2 description "                           ==== ge-0/0/2 FOR TEST LAN  === "
set interfaces ge-0/0/2 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/2 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/3 description "                           ==== ge-0/0/3 FOR TEST DMZ  === "
set interfaces ge-0/0/3 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/3 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/4 description "                           ==== ge-0/0/4 RESERVED FOR OFFICE  === "
set interfaces ge-0/0/4 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/4 unit 0 family ethernet-switching native-vlan-id 200
set interfaces ge-0/0/5 description "                           ==== ge-0/0/5 RESERVED FOR NUC  === "
set interfaces ge-0/0/5 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/5 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/5 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/6 description "                           ==== ge-0/0/6 FOR SHEEVA MAIN to LAB  === "
set interfaces ge-0/0/6 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/6 unit 0 family ethernet-switching vlan members v100
set interfaces ge-0/0/7 description "                           ==== ge-0/0/7 FOR v12 NUC USB === "
set interfaces ge-0/0/7 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/7 unit 0 family ethernet-switching vlan members v12
set interfaces ge-0/0/8 description "                           ==== ge-0/0/8  member to SRX node 0 reth0 ge-0/0/0 === "
set interfaces ge-0/0/8 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/8 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/8 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/8 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/8 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/9 description "                           ==== ge-0/0/9  member to SRX node 1 reth0 ge-3/0/0 === "
set interfaces ge-0/0/9 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/9 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/9 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/9 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/9 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/10 description "                          ==== ge-0/0/10 NOT IN USE  === "
set interfaces ge-0/0/11 description "                          ==== ge-0/0/11 FOR WLC  === "
set interfaces ge-0/0/11 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/11 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/11 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/12 description "                          ==== ge-0/0/12 FOR AP 1 GROUND === "
set interfaces ge-0/0/12 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/12 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/12 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/13 description "                          ==== ge-0/0/13 FOR AP 2 1st FLOOR === "
set interfaces ge-0/0/13 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/13 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/13 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/14 description "                          ==== ge-0/0/14 FOR AP 3 2nd FLOOR OFFICE === "
set interfaces ge-0/0/14 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/14 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/14 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/15 description "                          ==== ge-0/0/15 FOR AP 4 UNDERGROUND === "
set interfaces ge-0/0/15 unit 0 family ethernet-switching port-mode trunk
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v200
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v300
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members v500
set interfaces ge-0/0/15 unit 0 family ethernet-switching native-vlan-id 100
set interfaces ge-0/0/16 description "                          ==== ge-0/0/16 V700 member SWITCH INET=== "
set interfaces ge-0/0/16 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/16 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/17 description "                          ==== ge-0/0/17 V700 member === "
set interfaces ge-0/0/17 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/17 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/18 description "                          ==== ge-0/0/18 V700 member LAB INET === "
set interfaces ge-0/0/18 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/18 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/19 description "                          ==== ge-0/0/19 V700 member PROD INET === "
set interfaces ge-0/0/19 unit 0 family ethernet-switching port-mode access
set interfaces ge-0/0/19 unit 0 family ethernet-switching vlan members v700
set interfaces ge-0/0/20 description "                          ==== ge-0/0/20 ae0 member srxC-1 ge-0/0/3 === "
set interfaces ge-0/0/20 ether-options 802.3ad ae0
set interfaces ge-0/0/21 description "                          ==== ge-0/0/21 ae0 member srxC-1 ge-0/0/4 === "
set interfaces ge-0/0/21 ether-options 802.3ad ae0
set interfaces ge-0/0/22 description "                          ==== ge-0/0/22 ae1 member srxC-2 ge-0/0/3 === "
set interfaces ge-0/0/22 ether-options 802.3ad ae1
set interfaces ge-0/0/23 description "                          ==== ge-0/0/23 ae1 member srxC-2 ge-0/0/4 === "
set interfaces ge-0/0/23 ether-options 802.3ad ae1
set interfaces ae0 description "                                ==== ae0 (ge-0/0/20 ge-0/0/20) TRUNK to SRX node 0 (ge-0/0/3 ge-0/0/4 )==== "
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members v11
set interfaces ae0 unit 0 family ethernet-switching vlan members v12
set interfaces ae1 description "                                ==== ae1  TRUNK to SRX node 1 ==== "
set interfaces ae1 unit 0 family ethernet-switching port-mode trunk
set interfaces ae1 unit 0 family ethernet-switching vlan members v11
set interfaces ae1 unit 0 family ethernet-switching vlan members v12
set interfaces me0 description "                                ==== me0 MANAGEMENT INTERFACE ==== "
set interfaces me0 unit 0 family inet address 192.168.12.21/24
set interfaces me0 unit 0 family inet address 10.128.10.249/24
set interfaces vlan unit 11 description "                       ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.1/24
set interfaces vlan unit 12 description "                       ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.1/24
set interfaces vlan unit 100 description "                       ==== VLAN unit 100 INTERFACE ==== "
set interfaces vlan unit 100 family inet address 192.168.10.7/24
set interfaces vlan unit 200 description "                       ==== VLAN unit 200 INTERFACE ==== "
set interfaces vlan unit 200 family inet address 192.168.12.7/24
set interfaces vlan unit 300 description "                       ==== VLAN unit 300 INTERFACE ==== "
set interfaces vlan unit 300 family inet address 10.128.10.7/24
set interfaces vlan unit 500 description "                       ==== VLAN unit 500 INTERFACE ==== "
set interfaces vlan unit 500 family inet address 10.128.20.7/24
set snmp name "snmp STOCKEL A SW EX01"
set snmp description " ===                                SNMP COMMUNITY PUBLIC for 192.168.10.0 192.168.12.0 === "
set snmp location "Rack A"
set snmp contact "Rafael.Torrales@gmail.com"
set snmp client-list list0 192.168.12.0/24
set snmp community public authorization read-only
set snmp community public client-list-name list0
set snmp trap-group STOCKEL-TRAPS destination-port 514
set snmp trap-group STOCKEL-TRAPS targets 192.168.12.185
set routing-options static route 0.0.0.0/0 next-hop 192.168.12.1
set routing-instances LAN description "                         ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 0.0.0.0/0 next-hop 172.23.11.10
set routing-instances OLDNET description "                         ==== OLDNET ROUTING INSTANCE ==== "
set routing-instances OLDNET instance-type virtual-router
set routing-instances OLDNET interface vlan.100
set routing-instances OLDNET interface vlan.200
set routing-instances OLDNET interface vlan.300
set routing-instances OLDNET interface vlan.500
set vlans v100 description "                                    ==== VLAN 100  LAB        ==== "
set vlans v100 vlan-id 100
set vlans v100 l3-interface vlan.100
set vlans v11 description "                                     ==== VLAN 11              ==== "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description "                                     ==== VLAN 12              ==== "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12
set vlans v200 description "                                    ==== VLAN 200  PROD       ==== "
set vlans v200 vlan-id 200
set vlans v200 l3-interface vlan.200
set vlans v300 description "                                    ==== VLAN 300  TEST       ==== "
set vlans v300 vlan-id 300
set vlans v300 l3-interface vlan.300
set vlans v500 description "                                    ==== VLAN 500  DMZ        ==== "
set vlans v500 vlan-id 500
set vlans v500 l3-interface vlan.500
set vlans v700 description "                                    ==== VLAN 700  INTERNET   ==== "
set vlans v700 vlan-id 700
set poe interface all

SRX SRX-C (cluster).


 

set version 12.1X46-D65.4
set groups node0 system host-name srxC-1
set groups node0 interfaces fxp0 unit 0 family inet address 192.168.12.26/24
set groups node0 interfaces fxp0 unit 0 family inet address 192.168.12.28/24 master-only
set groups node1 system host-name srxC-2
set groups node1 interfaces fxp0 unit 0 family inet address 192.168.12.27/24
set groups node1 interfaces fxp0 unit 0 family inet address 192.168.12.28/24 master-only
set apply-groups "${node}"
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system name-server 192.168.12.10
set system name-server 192.168.10.2
set system services ssh
set system services xnm-clear-text
set chassis aggregated-devices ethernet device-count 1
set chassis cluster reth-count 3
set chassis cluster redundancy-group 0 node 0 priority 254
set chassis cluster redundancy-group 0 node 1 priority 2
set chassis cluster redundancy-group 3 node 0 priority 254
set chassis cluster redundancy-group 3 node 1 priority 2
set chassis cluster redundancy-group 3 preempt
set chassis cluster redundancy-group 2 node 0 priority 254
set chassis cluster redundancy-group 2 node 1 priority 2
set chassis cluster redundancy-group 2 preempt
set chassis cluster redundancy-group 1 node 0 priority 254
set chassis cluster redundancy-group 1 node 1 priority 2
set chassis cluster redundancy-group 1 preempt
set interfaces ge-0/0/0 gigether-options redundant-parent reth0
set interfaces ge-0/0/1 gigether-options redundant-parent reth2
set interfaces ge-0/0/3 gigether-options redundant-parent reth1
set interfaces ge-0/0/4 gigether-options redundant-parent reth1
set interfaces ge-3/0/0 gigether-options redundant-parent reth0
set interfaces ge-3/0/1 gigether-options redundant-parent reth2
set interfaces ge-3/0/3 gigether-options redundant-parent reth1
set interfaces ge-3/0/4 gigether-options redundant-parent reth1
set interfaces fab0 fabric-options member-interfaces ge-0/0/5
set interfaces fab1 fabric-options member-interfaces ge-3/0/5
set interfaces reth0 description "          ==== reth0  to OLDNET ==== "
set interfaces reth0 vlan-tagging
set interfaces reth0 redundant-ether-options redundancy-group 1
set interfaces reth0 unit 200 description " ==== VLAN unit 200 PROD reth0.200 INTERFACE ==== "
set interfaces reth0 unit 200 vlan-id 200
set interfaces reth0 unit 200 family inet address 192.168.12.3/24
set interfaces reth0 unit 300 description " ==== VLAN unit 300 TEST reth0.300 INTERFACE ==== "
set interfaces reth0 unit 300 vlan-id 300
set interfaces reth0 unit 300 family inet address 10.128.10.3/24
set interfaces reth1 redundant-ether-options redundancy-group 2
set interfaces reth1 redundant-ether-options lacp passive
set interfaces reth1 redundant-ether-options lacp periodic slow
set interfaces reth1 unit 0 description " ==== reth1.0 TRUNK to SWITCH ==== "
set interfaces reth1 unit 0 family ethernet-switching port-mode trunk
set interfaces reth1 unit 0 family ethernet-switching vlan members all
set interfaces reth2 redundant-ether-options redundancy-group 3
set interfaces reth2 unit 0 description " ==== reth2.0 INTERNET INTERFACE ==== "
set interfaces reth2 unit 0 family inet sampling input
set interfaces reth2 unit 0 family inet sampling output
set interfaces reth2 unit 0 family inet dhcp-client retransmission-attempt 6
set interfaces reth2 unit 0 family inet dhcp-client retransmission-interval 5
set interfaces reth2 unit 0 family inet dhcp-client update-server
set interfaces st0 unit 2 description " ==== ASKAREL IPSEC TUNNEL  INTERFACE ==== "
set interfaces st0 unit 2 family inet sampling input
set interfaces st0 unit 2 family inet sampling output
set interfaces swfab0 fabric-options member-interfaces ge-0/0/2
set interfaces swfab1 fabric-options member-interfaces ge-3/0/2
set interfaces vlan unit 11 description " ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.10/24
set interfaces vlan unit 12 description " ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.10/24
set security ike proposal phase1-ASKAREL description " ==== PHASE 1 ASKAREL PROPOSAL ==== "
set security ike proposal phase1-ASKAREL authentication-method pre-shared-keys
set security ike proposal phase1-ASKAREL dh-group group2
set security ike proposal phase1-ASKAREL authentication-algorithm sha-256
set security ike proposal phase1-ASKAREL encryption-algorithm aes-256-cbc
set security ike proposal phase1-ASKAREL lifetime-seconds 86400
set security ike policy phase1-pol-ASKAREL mode aggressive
set security ike policy phase1-pol-ASKAREL description " ==== PHASE 1 ASKAREL POLICY ==== "
set security ike policy phase1-pol-ASKAREL proposals phase1-ASKAREL
set security ike policy phase1-pol-ASKAREL pre-shared-key ascii-text "$9$"
set security ike gateway gw-ASKAREL ike-policy phase1-pol-ASKAREL
set security ike gateway gw-ASKAREL dynamic inet 172.23.90.64
set security ike gateway gw-ASKAREL dead-peer-detection interval 30
set security ike gateway gw-ASKAREL dead-peer-detection threshold 5
set security ike gateway gw-ASKAREL local-identity inet 172.23.90.0
set security ike gateway gw-ASKAREL external-interface reth2.0
set security ike gateway gw-ASKAREL version v1-only
set security ipsec traceoptions flag all
set security ipsec traceoptions flag security-associations
set security ipsec traceoptions flag packet-drops
set security ipsec traceoptions flag packet-processing
deactivate security ipsec traceoptions
set security ipsec proposal phase2-ASKAREL description " ==== PHASE 2 ASKAREL PROPOSAL ==== "
set security ipsec proposal phase2-ASKAREL protocol esp
set security ipsec proposal phase2-ASKAREL authentication-algorithm hmac-sha-256-128
set security ipsec proposal phase2-ASKAREL encryption-algorithm aes-256-cbc
set security ipsec proposal phase2-ASKAREL lifetime-seconds 3600
set security ipsec policy phase2-pol-ASKAREL description " ==== PHASE 2 ASKAREL POLICY ==== "
set security ipsec policy phase2-pol-ASKAREL perfect-forward-secrecy keys group2
set security ipsec policy phase2-pol-ASKAREL proposals phase2-ASKAREL
set security ipsec vpn to-ASKAREL bind-interface st0.2
set security ipsec vpn to-ASKAREL ike gateway gw-ASKAREL
set security ipsec vpn to-ASKAREL ike ipsec-policy phase2-pol-ASKAREL
set security ipsec vpn to-ASKAREL establish-tunnels immediately
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST description " === RULESET SOURCE NAT TO UNTRUST === "
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST from zone TRUST
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST to zone UNTRUST
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST rule RULE1-SOURCENAT-TO-UNTRUST description " === RULE 1 RULESET SOURCENAT TO UNTRUST === "
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST rule RULE1-SOURCENAT-TO-UNTRUST match source-address 0.0.0.0/0
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST rule RULE1-SOURCENAT-TO-UNTRUST match destination-address 0.0.0.0/0
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST rule RULE1-SOURCENAT-TO-UNTRUST then source-nat interface
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN description " === SECURITY POLICY from ASKAREL to TRUST allow ICMP === "
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN match source-address any
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN match destination-address any
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN match application junos-icmp-ping
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN then permit
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL description " === SECURITY POLICY from TRUST to ASKAREL allow ICMP === "
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL match source-address any
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL match destination-address any
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL match application junos-icmp-ping
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL then permit
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET description " === SECURITY POLICY from TRUST to OLDNET allow ICMP === "
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET match source-address any
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET match destination-address any
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET match application junos-icmp-ping
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET then permit
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST description " === SECURITY POLICY from OLDNET to TRUST allow ICMP === "
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST match source-address any
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST match destination-address any
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST match application junos-icmp-ping
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST then permit
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST description " === SECURITY POLICY from OLDNET to TRUST allow SSH === "
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST match source-address any
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST match destination-address any
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST match application junos-ssh
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST then permit
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST description " === SECURITY POLICY from TRUST to UNTRUST allow ANY === "
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST match source-address any
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST match destination-address any
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST match application any
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST then permit
set security zones security-zone TRUST description " ==== TRUST inside networks vlan 11 and vlan 12 ==== "
set security zones security-zone TRUST interfaces vlan.11 host-inbound-traffic system-services dhcp
set security zones security-zone TRUST interfaces vlan.11 host-inbound-traffic system-services ping
set security zones security-zone TRUST interfaces vlan.12 host-inbound-traffic system-services dhcp
set security zones security-zone TRUST interfaces vlan.12 host-inbound-traffic system-services ping
set security zones security-zone UNTRUST description " ==== UNTRUST towards Inet ==== "
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services dhcp
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services ike
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services https
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services ping
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services traceroute
set security zones security-zone ASKAREL description " ==== ASKAREL IPSEC  ==== "
set security zones security-zone ASKAREL host-inbound-traffic system-services ping
set security zones security-zone ASKAREL host-inbound-traffic system-services traceroute
set security zones security-zone ASKAREL interfaces st0.2
set security zones security-zone OLDNET description " ==== SECURITY ZONE: OLDNET ==== "
set security zones security-zone OLDNET interfaces reth0.200 host-inbound-traffic system-services ping
set security zones security-zone OLDNET interfaces reth0.300 host-inbound-traffic system-services ping
set routing-instances LAN description " ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN system services dhcp-local-server group DHCP_POOL_VLAN11 interface vlan.11
set routing-instances LAN system services dhcp-local-server group DHCP_POOL_VLAN12 interface vlan.12
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet network 172.23.11.0/24
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet range DHCP_RANGE_VLAN11 low 172.23.11.100
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet range DHCP_RANGE_VLAN11 high 172.23.11.200
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet dhcp-attributes maximum-lease-time 2419200
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet dhcp-attributes name-server 8.8.8.8
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet dhcp-attributes router 172.23.11.1
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN12 family inet network 172.23.12.0/24
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN12 family inet range DHCP_RANGE_VLAN12 low 172.23.12.100
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN12 family inet range DHCP_RANGE_VLAN12 high 172.23.12.200
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN12 family inet dhcp-attributes router 172.23.12.1
set routing-instances LAN interface reth0.200
set routing-instances LAN interface reth0.300
set routing-instances LAN interface reth2.0
set routing-instances LAN interface st0.2
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 192.168.5.0/24 next-hop st0.2
set routing-instances LAN routing-options static route 10.128.10.0/24 next-hop 10.128.10.2
set routing-instances LAN routing-options static route 192.168.12.0/24 next-hop 192.168.12.1
set routing-instances LAN routing-options static route 172.23.11.0/24 next-hop 172.23.11.1
set routing-instances LAN routing-options static route 172.23.12.0/24 next-hop 172.23.12.1
set vlans v11 description " === VLAN 11 === "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description " === VLAN 12 === "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12

Update SRX nov 12th

Update SRX nov 12th


Improved interfaces description.

Added snmp

added static route for fxp0

Placed reth0 interfaces on new routing instance called OLDNET

 

set version 12.1X46-D65.4
set groups node0 system host-name srxC-1
set groups node0 interfaces fxp0 unit 0 family inet address 192.168.12.26/24
set groups node0 interfaces fxp0 unit 0 family inet address 192.168.12.28/24 master-only
set groups node1 system host-name srxC-2
set groups node1 interfaces fxp0 unit 0 family inet address 192.168.12.27/24
set groups node1 interfaces fxp0 unit 0 family inet address 192.168.12.28/24 master-only
set apply-groups "${node}"
set system time-zone Europe/Brussels
set system root-authentication encrypted-password "$1$"
set system name-server 192.168.12.10
set system name-server 192.168.10.2
set system services ssh
set system services xnm-clear-text
set chassis aggregated-devices ethernet device-count 1
set chassis cluster reth-count 3
set chassis cluster redundancy-group 0 node 0 priority 254
set chassis cluster redundancy-group 0 node 1 priority 2
set chassis cluster redundancy-group 3 node 0 priority 254
set chassis cluster redundancy-group 3 node 1 priority 2
set chassis cluster redundancy-group 3 preempt
set chassis cluster redundancy-group 2 node 0 priority 254
set chassis cluster redundancy-group 2 node 1 priority 2
set chassis cluster redundancy-group 2 preempt
set chassis cluster redundancy-group 1 node 0 priority 254
set chassis cluster redundancy-group 1 node 1 priority 2
set chassis cluster redundancy-group 1 preempt
set interfaces ge-0/0/0 description "          ==== ge-0/0/0 member of reth0 ==== "
set interfaces ge-0/0/0 gigether-options redundant-parent reth0
set interfaces ge-0/0/1 description "          ==== ge-0/0/1 member of reth2 ==== "
set interfaces ge-0/0/1 gigether-options redundant-parent reth2
set interfaces ge-0/0/3 description "          ==== ge-0/0/3 member of reth1 ==== "
set interfaces ge-0/0/3 gigether-options redundant-parent reth1
set interfaces ge-0/0/4 description "          ==== ge-0/0/4 member of reth1 ==== "
set interfaces ge-0/0/4 gigether-options redundant-parent reth1
set interfaces ge-3/0/0 description "          ==== ge-3/0/0 member of reth0 ==== "
set interfaces ge-3/0/0 gigether-options redundant-parent reth0
set interfaces ge-3/0/1 description "          ==== ge-3/0/1 member of reth2 ==== "
set interfaces ge-3/0/1 gigether-options redundant-parent reth2
set interfaces ge-3/0/3 description "          ==== ge-3/0/3 member of reth1 ==== "
set interfaces ge-3/0/3 gigether-options redundant-parent reth1
set interfaces ge-3/0/4 description "          ==== ge-3/0/4 member of reth1 ==== "
set interfaces ge-3/0/4 gigether-options redundant-parent reth1
set interfaces fab0 description "              ==== fab0 ge-0/0/5 ==== "
set interfaces fab0 fabric-options member-interfaces ge-0/0/5
set interfaces fab1 description "              ==== fab1 ge-3/0/5 ==== "
set interfaces fab1 fabric-options member-interfaces ge-3/0/5
set interfaces reth0 description "             ==== reth0  to OLDNET ==== "
set interfaces reth0 vlan-tagging
set interfaces reth0 redundant-ether-options redundancy-group 1
set interfaces reth0 unit 200 description "          ==== VLAN unit 200 PROD reth0.200 INTERFACE ==== "
set interfaces reth0 unit 200 vlan-id 200
set interfaces reth0 unit 200 family inet address 192.168.12.3/24
set interfaces reth0 unit 300 description "          ==== VLAN unit 300 TEST reth0.300 INTERFACE ==== "
set interfaces reth0 unit 300 vlan-id 300
set interfaces reth0 unit 300 family inet address 10.128.10.3/24
set interfaces reth1 redundant-ether-options redundancy-group 2
set interfaces reth1 unit 0 description "            ==== reth1.0 TRUNK to SWITCH ==== "
set interfaces reth1 unit 0 family ethernet-switching port-mode trunk
set interfaces reth1 unit 0 family ethernet-switching vlan members all
set interfaces reth2 redundant-ether-options redundancy-group 3
set interfaces reth2 unit 0 description "            ==== reth2.0 INTERNET INTERFACE ==== "
set interfaces reth2 unit 0 family inet sampling input
set interfaces reth2 unit 0 family inet sampling output
set interfaces reth2 unit 0 family inet dhcp-client retransmission-attempt 6
set interfaces reth2 unit 0 family inet dhcp-client retransmission-interval 5
set interfaces reth2 unit 0 family inet dhcp-client update-server
set interfaces st0 unit 2 description "           ==== ASKAREL IPSEC TUNNEL  INTERFACE ==== "
set interfaces st0 unit 2 family inet sampling input
set interfaces st0 unit 2 family inet sampling output
set interfaces swfab0 description "               ==== swfab0 ge-0/0/2 ===== "
set interfaces swfab0 fabric-options member-interfaces ge-0/0/2
set interfaces swfab1 description "               ==== swfab1 ge-3/0/2 ===== "
set interfaces swfab1 fabric-options member-interfaces ge-3/0/2
set interfaces vlan unit 11 description "         ==== VLAN unit 11 INTERFACE ==== "
set interfaces vlan unit 11 family inet address 172.23.11.10/24
set interfaces vlan unit 12 description "         ==== VLAN unit 12 INTERFACE ==== "
set interfaces vlan unit 12 family inet address 172.23.12.10/24
set snmp name "snmp STOCKEL A Firewall SRX C"
set snmp description "Firewall snmp community public for networks 192.168.10.0 192.168.12.0"
set snmp location "Rack A"
set snmp contact "Rafael.Torrales@gmail.com"
set snmp client-list list0 192.168.12.0/24
set snmp community public authorization read-only
set snmp community public client-list-name list0
set snmp trap-group STOCKEL-TRAPS destination-port 514
set snmp trap-group STOCKEL-TRAPS targets 192.168.12.185
set routing-options static route 0.0.0.0/0 next-hop 192.168.12.1
set security ike proposal phase1-ASKAREL description " ==== PHASE 1 ASKAREL PROPOSAL ==== "
set security ike proposal phase1-ASKAREL authentication-method pre-shared-keys
set security ike proposal phase1-ASKAREL dh-group group2
set security ike proposal phase1-ASKAREL authentication-algorithm sha-256
set security ike proposal phase1-ASKAREL encryption-algorithm aes-256-cbc
set security ike proposal phase1-ASKAREL lifetime-seconds 86400
set security ike policy phase1-pol-ASKAREL mode aggressive
set security ike policy phase1-pol-ASKAREL description " ==== PHASE 1 ASKAREL POLICY ==== "
set security ike policy phase1-pol-ASKAREL proposals phase1-ASKAREL
set security ike policy phase1-pol-ASKAREL pre-shared-key ascii-text "$9$TQ39AtOBIcP59p01yraZGi.5Qz6/Cumf39p0IRrevWLNVb2oZUev2aJU.mOBIcevx7VwYoKM7Vw2GU0B1hSl7Nb"
set security ike gateway gw-ASKAREL ike-policy phase1-pol-ASKAREL
set security ike gateway gw-ASKAREL dynamic inet 172.23.90.64
set security ike gateway gw-ASKAREL dead-peer-detection interval 30
set security ike gateway gw-ASKAREL dead-peer-detection threshold 5
set security ike gateway gw-ASKAREL local-identity inet 172.23.90.0
set security ike gateway gw-ASKAREL external-interface reth2.0
set security ike gateway gw-ASKAREL version v1-only
set security ipsec traceoptions flag all
set security ipsec traceoptions flag security-associations
set security ipsec traceoptions flag packet-drops
set security ipsec traceoptions flag packet-processing
deactivate security ipsec traceoptions
set security ipsec proposal phase2-ASKAREL description " ==== PHASE 2 ASKAREL PROPOSAL ==== "
set security ipsec proposal phase2-ASKAREL protocol esp
set security ipsec proposal phase2-ASKAREL authentication-algorithm hmac-sha-256-128
set security ipsec proposal phase2-ASKAREL encryption-algorithm aes-256-cbc
set security ipsec proposal phase2-ASKAREL lifetime-seconds 3600
set security ipsec policy phase2-pol-ASKAREL description " ==== PHASE 2 ASKAREL POLICY ==== "
set security ipsec policy phase2-pol-ASKAREL perfect-forward-secrecy keys group2
set security ipsec policy phase2-pol-ASKAREL proposals phase2-ASKAREL
set security ipsec vpn to-ASKAREL bind-interface st0.2
set security ipsec vpn to-ASKAREL ike gateway gw-ASKAREL
set security ipsec vpn to-ASKAREL ike ipsec-policy phase2-pol-ASKAREL
set security ipsec vpn to-ASKAREL establish-tunnels immediately
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST description " === RULESET SOURCE NAT TO UNTRUST === "
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST from zone TRUST
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST to zone UNTRUST
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST rule RULE1-SOURCENAT-TO-UNTRUST description " === RULE 1 RULESET SOURCENAT TO UNTRUST === "
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST rule RULE1-SOURCENAT-TO-UNTRUST match source-address 0.0.0.0/0
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST rule RULE1-SOURCENAT-TO-UNTRUST match destination-address 0.0.0.0/0
set security nat source rule-set RULESET-SOURCENAT-TO-UNTRUST rule RULE1-SOURCENAT-TO-UNTRUST then source-nat interface
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN description " === SECURITY POLICY from ASKAREL to TRUST allow ICMP === "
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN match source-address any
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN match destination-address any
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN match application junos-icmp-ping
set security policies from-zone ASKAREL to-zone TRUST policy ICMP_ASKAREL_TRUST_IN then permit
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL description " === SECURITY POLICY from TRUST to ASKAREL allow ICMP === "
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL match source-address any
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL match destination-address any
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL match application junos-icmp-ping
set security policies from-zone TRUST to-zone ASKAREL policy ICMP_TRUST_ASKAREL then permit
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET description " === SECURITY POLICY from TRUST to OLDNET allow ICMP === "
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET match source-address any
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET match destination-address any
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET match application junos-icmp-ping
set security policies from-zone TRUST to-zone OLDNET policy ICMP_TRUST_TO_OLDNET then permit
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST description " === SECURITY POLICY from OLDNET to TRUST allow ICMP === "
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST match source-address any
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST match destination-address any
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST match application junos-icmp-ping
set security policies from-zone OLDNET to-zone TRUST policy ICMP_OLDNET_TO_TRUST then permit
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST description " === SECURITY POLICY from OLDNET to TRUST allow SSH === "
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST match source-address any
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST match destination-address any
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST match application junos-ssh
set security policies from-zone OLDNET to-zone TRUST policy SSH_OLDNET_TO_TRUST then permit
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST description " === SECURITY POLICY from TRUST to UNTRUST allow ANY === "
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST match source-address any
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST match destination-address any
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST match application any
set security policies from-zone TRUST to-zone UNTRUST policy ANY_TRUST_to_UNTRUST then permit
set security zones security-zone TRUST description " ==== TRUST inside networks vlan 11 and vlan 12 ==== "
set security zones security-zone TRUST interfaces vlan.11 host-inbound-traffic system-services dhcp
set security zones security-zone TRUST interfaces vlan.11 host-inbound-traffic system-services ping
set security zones security-zone TRUST interfaces vlan.12 host-inbound-traffic system-services dhcp
set security zones security-zone TRUST interfaces vlan.12 host-inbound-traffic system-services ping
set security zones security-zone UNTRUST description " ==== UNTRUST towards Inet ==== "
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services dhcp
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services ike
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services https
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services ping
set security zones security-zone UNTRUST interfaces reth2.0 host-inbound-traffic system-services traceroute
set security zones security-zone ASKAREL description " ==== ASKAREL IPSEC  ==== "
set security zones security-zone ASKAREL host-inbound-traffic system-services ping
set security zones security-zone ASKAREL host-inbound-traffic system-services traceroute
set security zones security-zone ASKAREL interfaces st0.2
set security zones security-zone OLDNET description " ==== SECURITY ZONE: OLDNET ==== "
set security zones security-zone OLDNET interfaces reth0.200 host-inbound-traffic system-services ping
set security zones security-zone OLDNET interfaces reth0.300 host-inbound-traffic system-services ping
set routing-instances LAN description " ==== LAN ROUTING INSTANCE ==== "
set routing-instances LAN instance-type virtual-router
set routing-instances LAN system services dhcp-local-server group DHCP_POOL_VLAN11 interface vlan.11
set routing-instances LAN system services dhcp-local-server group DHCP_POOL_VLAN12 interface vlan.12
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet network 172.23.11.0/24
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet range DHCP_RANGE_VLAN11 low 172.23.11.100
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet range DHCP_RANGE_VLAN11 high 172.23.11.200
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet dhcp-attributes maximum-lease-time 2419200
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet dhcp-attributes name-server 8.8.8.8
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN11 family inet dhcp-attributes router 172.23.11.1
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN12 family inet network 172.23.12.0/24
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN12 family inet range DHCP_RANGE_VLAN12 low 172.23.12.100
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN12 family inet range DHCP_RANGE_VLAN12 high 172.23.12.200
set routing-instances LAN access address-assignment pool DHCP_POOL_VLAN12 family inet dhcp-attributes router 172.23.12.1
set routing-instances LAN interface reth2.0
set routing-instances LAN interface st0.2
set routing-instances LAN interface vlan.11
set routing-instances LAN interface vlan.12
set routing-instances LAN routing-options static route 192.168.5.0/24 next-hop st0.2
set routing-instances LAN routing-options static route 172.23.11.0/24 next-hop 172.23.11.1
set routing-instances LAN routing-options static route 172.23.12.0/24 next-hop 172.23.12.1
set routing-instances OLDNET description "                         ==== OLDNET ROUTING INSTANCE ==== "
set routing-instances OLDNET instance-type virtual-router
set routing-instances OLDNET interface reth0.200
set routing-instances OLDNET interface reth0.300
set vlans v11 description " === VLAN 11 === "
set vlans v11 vlan-id 11
set vlans v11 l3-interface vlan.11
set vlans v12 description " === VLAN 12 === "
set vlans v12 vlan-id 12
set vlans v12 l3-interface vlan.12

TU ru ru ru rUUUUUUU