Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.



871 posts

Ultimate Geek

Trusted

Topic # 69647 12-Oct-2010 16:34 Send private message

Hi all

We are looking at getting a Juniper SRX240 firewall but I can't find any information to answer some questions.

I need to know if the ports are physically separate or if they are just VLANed apart. (After switching has been disabled)

We need to have 1 interface connected to Citylink that can handle multiple IP addresses, and a backup ADSL / VDSL card.

Different servers will have different IP addresses / ports associated with them, but for compliance purposes we need to be able to prove that Server A on port ge-0/0/5 (which has IP XXX.XXX.XXX.XXX externally) can't talk directly to Server B on port ge-0/0/6 (which has IP XXX.XXX.XXX.YYY externally)

Can anyone help me answer the above question?

Cheers
James

Create new topic
1397 posts

Uber Geek
+1 received by user: 224

Trusted

  Reply # 391020 12-Oct-2010 16:44 Send private message

I don't quite understand what you're asking, sorry :)

The ports don't act like a hub though, if that's what you mean? You have to say "this port's in this VLAN"

Tim




Checkout the EPIC5 script I work on, LiCe. Makes console based IRC fun and easy to use, just like the old days!
Android user? Checkout MightyText - text messaging from your browser.



871 posts

Ultimate Geek

Trusted

  Reply # 391024 12-Oct-2010 16:48 Send private message

muppet: I don't quite understand what you're asking, sorry :)

The ports don't act like a hub though, if that's what you mean? You have to say "this port's in this VLAN"

Tim


I'm finding it quite hard to explain.

Really, we need one ethernet port for internet (I'm ignoring the ADSL / VDSL card) and then have the other Ethernet ports as separate zones, such as "Web Servers", "Mail Servers", "File Servers" etc

Does that explain it better? I'm told we need to do better than just VLANs

170Mb/s faster than TimA
3336 posts

Uber Geek
+1 received by user: 757

Trusted
Think Concepts
Subscriber

  Reply # 391042 12-Oct-2010 17:34 Send private message

The best thing would be to put the likes of certain ports on certain vlans, for example:

If you had Port ge-0/0/1 connected to Citylink with multiple IP addresses it might be worth asking if they can do BGP with this, that way using BGP they can route you different IP addresses and all you need to do is to update the router config to make these changes.

From here, you can allocate different computers / devices to different IP's - you can also get the Juniper to do natting for all computers on the "LAN" and give external IP's to the servers as needed.

If you didn't want the network on Port ge-0/0/2 accessing anything on port ge-0/0/1 the normal step would be to separate them with use of Vlans, you can also add certain devices to different vlans depending on your needs.

It's pretty hard to explain, but the best step would be for you to head over to these articles:

http://www.juniper.net/techpubs/software/erx/erx51x/swconfig-routing-vol2/html/bgp-config.html (This is for setting up BGP) 

http://www.juniper.net/techpubs/software/management/nmc-rx/nmc-rx73x/swconfig-nmc-rx-vol2/html/vlan-config.html (Setting up Vlans)

http://www.juniper.net/techpubs/software/erx/junose71/swconfig-routing-services/html/nat-config.html (Nat Config)

With these routers don't get sucked into using the web interface, it's best to leave this disabled and use the CLI - you will get your head around things easier that way. The cool thing with these routers is if you are doing the config through the CLI and break something (and had a working config beforehand) then the router will revert to that working config after a reboot unless if you commit it.

Good luck! Good on you for supporting Juniper! They are awesome pieces of equipment! 




Michael Murphy
[Twitter] [Last.fm] [IPv6 Sage]

Everything I say here is my own opinion and not that of my employer.

Create new topic




Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





Trending now »

Hot discussions in our forums right now:

Smoke billows from Auckland mall after "explosion" - Westfield West City
Created by freitasm, last reply by hio77 on 27-Feb-2015 19:33 (41 replies)
Pages... 2 3


Why does Lightbox have a suicide wish?
Created by dafman, last reply by tdgeek on 2-Mar-2015 12:21 (68 replies)
Pages... 3 4 5


Leonard Nimoy, Mr Spock dies at 83
Created by freitasm, last reply by freitasm on 28-Feb-2015 22:20 (20 replies)
Pages... 2


Galaxy s6 announcement and owners thread
Created by Shoes2468, last reply by old3eyes on 2-Mar-2015 12:29 (38 replies)
Pages... 2 3


Has my desktop got Wi-Fi?
Created by beenz, last reply by dclegg on 26-Feb-2015 15:43 (19 replies)
Pages... 2


Uber Taxi Rides - $10 off first ride.
Created by kiwijunglist, last reply by gzt on 1-Mar-2015 23:38 (18 replies)
Pages... 2


The Evil that is ISIS
Created by networkn, last reply by joker97 on 28-Feb-2015 22:47 (201 replies)
Pages... 12 13 14


Spark Open Term Plan Changes? (27/2)
Created by taneb1, last reply by funnyfela on 28-Feb-2015 15:03 (37 replies)
Pages... 2 3



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.