Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: SRX firewall routing configuration

$
0
0
could you help me to understand the different functionality of the 2 definitions
1- set routing-instances Main-VR routing-options static route
2- routing-options static route

When you create a routing instance this creates an independent routing table within the device.  

 

1 - adds a static route to the Main-VR routing instance route table

2- adds a static route to the root routing instance route table

 

Use the operation command will show both route tables.  This is an example of an SRX with 2 routing instances configured Trust-vr and Untrust-vr and inet.0 is the root routing instance.

 

root@none> show route 

inet.0: 3 destinations, 4 routes (3 active, 0 holddown, 0 hidden)
+ = Active Route, - = Last Active, * = Both

0.0.0.0/0          *[Static/5] 16w5d 14:04:33
                    > to 192.168.0.1 via fe-0/0/7.0
                    [Access-internal/12] 18w6d 20:44:27> to 192.168.128.1 via fe-0/0/0.0
192.168.0.0/24     *[Direct/0] 24w5d 17:49:39> via fe-0/0/7.0
192.168.0.20/32    *[Local/0] 24w5d 18:02:06
                      Local via fe-0/0/7.0

Trust-vr.inet.0: 2 destinations, 2 routes (2 active, 0 holddown, 0 hidden)
+ = Active Route, - = Last Active, * = Both

192.168.27.64/28   *[Direct/0] 17w5d 17:29:41
                    > via fe-0/0/1.0
192.168.27.65/32   *[Local/0] 18w6d 20:46:02
                      Local via fe-0/0/1.0

Untrust-vr.inet.0: 3 destinations, 3 routes (3 active, 0 holddown, 0 hidden)
+ = Active Route, - = Last Active, * = Both

192.168.27.64/28   *[Direct/0] 16w5d 14:04:33
                    > via fe-0/0/1.0
192.168.128.0/24   *[Direct/0] 18w6d 20:44:27> via fe-0/0/0.0
192.168.128.14/32  *[Local/0] 18w6d 20:44:27
                      Local via fe-0/0/0.0

 

 

“All those traffic that will arrive to srx interface other then reth0.0 use global defination.”
Where to find this global definition

Your original configuration shows that reth0.0 is assigned to the Main-VR.  Thus any traffic that arrives on this sub interface will be processed by the Main-VR routing table.  Traffic that arrives on any other interface will be procesed by the root routing instance.


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>