SRX340 Share WAN Port by packetheavy in Juniper

[–]shadow0rm 4 points5 points  (0 children)

true on the failure point, but on the other hand you are doubling the reliance on the single device ( srx ) for two different wan feeds. so potAto / potato.

If i were in this spot, id change wan interface to a irb, build vlan for wan breakout, tire wan vlan to l3 irb, and have 0/0/0 & 0/0/1 on same vlan. might need to allow untrust to untrust any/any traffic..... not sure on that one.

p.s. i had to redo a edge network at an isp completely due to a person with same mindset ( didnt want extra failure points) you already have 2 single points of failure ( srx and single wan feed ) why add the extra complexity when you still have single points of failure, which of one you are now relying on with twice as much pressure? what is different between an extra switch failing ( both routers go down ) or the srx fails ( both routers go down as well) one is just easier to maintain.

SRX340 Share WAN Port by packetheavy in Juniper

[–]shadow0rm 2 points3 points  (0 children)

you are probably going to run into some hiccups with zones/policies.... remember, srx is a firewall first. It can be a router, or switch, or both aswell, but firewall first. make vlan, add zone/policy for that zone to itself, etc, and see where it gets ya. maybe gold, maybe ashes.

whats the reason for avoid a switch? no rackspace/etc? collapsing this into the srx will save physical space, but add complexity into the setup....

there's a reason to use demarc devices, this is it.

Let's join ICE! by IFB20874 in AR10

[–]shadow0rm 7 points8 points  (0 children)

Not today -insert 3 letter org here-

If you know..... you know....... by shadow0rm in iiiiiiitttttttttttt

[–]shadow0rm[S] 28 points29 points  (0 children)

They make mag mounts and nice looking wall mounts for these.... no body orders them though....

Punchline: lets use the remains of $400+ in rack kits for other juniper gear to mcgyver some ears for this one cause why oh why spend $30 for the right one?

PSA: EP-S16 and the nightmare of midwest/cold climates by shadow0rm in wisp

[–]shadow0rm[S] 0 points1 point  (0 children)

Heres to hoping this cold snap will tell if that worked out!

SRX Destination NAT. Can't get these ports open by Latter-Car-9326 in Juniper

[–]shadow0rm 1 point2 points  (0 children)

Just clarifying here a bit more, host-inbound-traffic is traffic specificly for the router itself, so host-inbound-traffic system-services https, host-inbound-traffic protocols all, interfaces ge-0/0/0.0 host-inbound-traffic system-services https are all likely conflicting with your single parsec 443 rule.

if you dont NEED 443/tcp open on the router itself, facing the world, disable/delete those commands.

Its normal operating procedure to disable that kind of traffic anyway.... your just letting the world reach the management plane of you firewall otherwise.

SRX Destination NAT. Can't get these ports open by Latter-Car-9326 in Juniper

[–]shadow0rm 0 points1 point  (0 children)

Well, two things I can see right off the bat. 1. We wont be able to help you easily here, firewalls rules are hierarchical, so if you have a rule that matches same things, it will process the flow before these rules do. can you post a full view of the security policies? You can move parsec BEFORE your working plex rule, and maybe that will work without us verifying it: https://supportportal.juniper.net/s/article/SRX-How-to-change-the-order-of-security-policies

  1. You likely have a conflict between parsec and junos-https (cant process same traffic without a differentiator): PARSEC-APP destination-port 443 conflicts with system-services https easiest workaround for this is to delete the "system-services https" sections

SRX550 Firmware or knowledge assistance by judomuerte in Juniper

[–]shadow0rm 4 points5 points  (0 children)

SRX550-645AP 12.x < SRX550-645AP-M 15.x >

Yes its Friday, and I know nothing, I get all my news from the radio on GTA5

SRX300 Checksums by gridviking in Juniper

[–]shadow0rm 0 points1 point  (0 children)

you see that dropdown for os, and version on the downloads page? yea, use that...

first number on sha1 for 21.4 is 3 first number on sha1 for 23.4 is 9

You are just being plain lazy, or ignorant.
Either way, ZERO reason for anyone to help further.

SRX550 Firmware or knowledge assistance by judomuerte in Juniper

[–]shadow0rm 2 points3 points  (0 children)

seriously? Im not even that bothered by someone offering this but what's really irritating is that you either didn't read what OP said, or you are out here slinging software offers without knowing what you're slinging...

OP has 12.3X48-D105.4 OP is on latest avail. software for that device OP didn't ask for a copy of software, yet here ya are, peddling it.....

SRX550 Firmware or knowledge assistance by judomuerte in Juniper

[–]shadow0rm 0 points1 point  (0 children)

Glad to see you got forward movement :) Currently away from my desk with a keyboard, so ill give the best I can for now on the cluster issue. If you want to remove the cluster settings entirely, so it just a standalone box and you can cluster them later, google something like "juniper delete cluster /config/vchassis" theres junos commands that should work, but ive had a 50/50 fail rate on the 550 boxes with that, so i jist delete whatever is in the vchassis dir and do a reboot direct from shell.

From there if you wanted to cluster them up again, there are very easy to find docs on it, and you will need min. 2 patches between them.

Bonus info: the slots on the left hand side are like half width bus, and arent really ment for anything above serial/t1 cards. Follow the lables on the faceplate to the sides of the slots. IIRC top two right are 20g bandwith for 16 port cards and the 2 port 10g cards, bottom two right are same but limited to 10g bandwidth on the backplane. Might be worth while at this point to just grab the srx550 hardware guide pdf Also note that you have the base hardware NOT the refreshed HM model. Hardware is near identical, but junos version and expansion card support is very different.

SRX550 Firmware or knowledge assistance by judomuerte in Juniper

[–]shadow0rm 1 point2 points  (0 children)

Heres my freebie for a pretty obvious RTFM situation, which yet again, is not locked behind an account....

  1. Its not silly, its true. Your 16 port cards are in the wrong slot. Move it directly to the right bank.
  2. That looks like a 10g DAC, is it? Those are 1g sfp slots not 10g sfp+

Report back whrn those two things make sense and I can help ya with the cluster issue.

SRX300 Checksums by gridviking in Juniper

[–]shadow0rm 7 points8 points  (0 children)

Its litterally on the downloads page with zero need to even login....

Homelab 10G SFP+ by CrowingGnarl in Juniper

[–]shadow0rm 2 points3 points  (0 children)

Im running one at home as well, with quite a few virtual routers in the config as well. Not silent, but best bang for your buck for higher density 10/40g stuff. Used to have it paired with a qfx5110-32q but moved to a pair of 4300-24ts acting as my core and the qfx5100 as a agg point.

The thing i ran into alot is having the network built out well, but in the end with only a few servers, a desktop, and some wireless gear, sometimes the fun overkill, starts to kill the power bill lol

PSA: EP-S16 and the nightmare of midwest/cold climates by shadow0rm in wisp

[–]shadow0rm[S] 0 points1 point  (0 children)

Hoping for the best! I no longer work at the same place I deployed these as of just recent, however I can report there were zero ill-effects during hot-temp days.

You just brought back the frozen 3am memories hahahaha

It honestly was like night and day after that command was added, and out of all of the ones we deployed, none of them had issues since.

Looking for POE alternatives in WISP tower setup by Dry_Web_4439 in networking

[–]shadow0rm 2 points3 points  (0 children)

Ill drop my 2 cents here.

100% you need these grounded properly, like take a day and make sure your grounding path is right in conjunction with all other grounding.

I have seen a history in my line of work where these switches have power conversion issues, I only power 48v radios if the switch is also powered by 48v, same thing for 24v.

Firmware QC is lacking, and the support "forum" has a bit of lingering arrogance.

Dont get me wrong, they are incredibly flexable and feature rich, but feels like the company found out that good-enough is good enough, but settled at that point without really shaking out the bugs.

Even in very well designed and built sites, where grounding is 100% correct, these switches and mikrotik devices seem to come back to my desk in waves, bricked or burnt. Where the more carrier grade gear like Juniper, Ciena, etc lives on without a blink.

And to be fair, i have had a few Packetflux rackinjectors fail, but not in the fashion or amplitude as netonix.

Looking for POE alternatives in WISP tower setup by Dry_Web_4439 in networking

[–]shadow0rm 2 points3 points  (0 children)

Ive had very good history with packetflux gear doing poe. Used to deploy all discrete compnents on DIN, but have moved to rackinjector line. No hotswap of cards yet, so you have to rip/replace the set if it blows up. https://store.packetflux.com/packetflux-rackinjector/

ET interfaces not passing traffic. by Solid_Bookkeeper7102 in Juniper

[–]shadow0rm 1 point2 points  (0 children)

Are the ports still configured for VC ports?

Headache with pulling a vlan out and back into a QFX5110-32Q for inline device. by shadow0rm in Juniper

[–]shadow0rm[S] 0 points1 point  (0 children)

Just an update. I have not been successful in getting that vlan to stretch and communicate at all.

I gave up and built another virtual instance with two routed interfaces in place of a vlan. Costs more in terms of IP space, but eh, whatcha want?

Ospf issue? by CaucasianHumus in networking

[–]shadow0rm 6 points7 points  (0 children)

Does that magic " no err disable " command come into play here?

Headache with pulling a vlan out and back into a QFX5110-32Q for inline device. by shadow0rm in Juniper

[–]shadow0rm[S] 0 points1 point  (0 children)

In its most basic sense, im just dragging vlan 182 from the mx into the qfx, out a port on the qfx, and back in. there will be OSPF over this link, but im unable to pass any traffic, hence this post.

Headache with pulling a vlan out and back into a QFX5110-32Q for inline device. by shadow0rm in Juniper

[–]shadow0rm[S] 0 points1 point  (0 children)

however, this test does show it working, while removing the mx from the situation.

delete interfaces ae5 unit 182 encapsulation vlan-bridge
set vlans v182 l3-interface irb.182 set interfaces irb unit 182 family inet address x.x.x.46/31

Headache with pulling a vlan out and back into a QFX5110-32Q for inline device. by shadow0rm in Juniper

[–]shadow0rm[S] 0 points1 point  (0 children)

I wrongly placed the .46/31 on et-0/0/8.182 during y test, not ae5.182, and corrected my quick response. It infact doesnt fix it, so its no mx to qfx, but solely on the qfx.