Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




871 posts

Ultimate Geek

Trusted

Topic # 69647 12-Oct-2010 16:34 Send private message

Hi all

We are looking at getting a Juniper SRX240 firewall but I can't find any information to answer some questions.

I need to know if the ports are physically separate or if they are just VLANed apart. (After switching has been disabled)

We need to have 1 interface connected to Citylink that can handle multiple IP addresses, and a backup ADSL / VDSL card.

Different servers will have different IP addresses / ports associated with them, but for compliance purposes we need to be able to prove that Server A on port ge-0/0/5 (which has IP XXX.XXX.XXX.XXX externally) can't talk directly to Server B on port ge-0/0/6 (which has IP XXX.XXX.XXX.YYY externally)

Can anyone help me answer the above question?

Cheers
James

Create new topic
1324 posts

Uber Geek
+1 received by user: 153

Trusted

  Reply # 391020 12-Oct-2010 16:44 Send private message

I don't quite understand what you're asking, sorry :)

The ports don't act like a hub though, if that's what you mean? You have to say "this port's in this VLAN"

Tim




Checkout the EPIC5 script I work on, LiCe. Makes console based IRC fun and easy to use, just like the old days!
Android user? Checkout MightyText - text messaging from your browser.



871 posts

Ultimate Geek

Trusted

  Reply # 391024 12-Oct-2010 16:48 Send private message

muppet: I don't quite understand what you're asking, sorry :)

The ports don't act like a hub though, if that's what you mean? You have to say "this port's in this VLAN"

Tim


I'm finding it quite hard to explain.

Really, we need one ethernet port for internet (I'm ignoring the ADSL / VDSL card) and then have the other Ethernet ports as separate zones, such as "Web Servers", "Mail Servers", "File Servers" etc

Does that explain it better? I'm told we need to do better than just VLANs

The Game.
2947 posts

Uber Geek
+1 received by user: 502

Trusted
Think Concepts
Subscriber

  Reply # 391042 12-Oct-2010 17:34 Send private message

The best thing would be to put the likes of certain ports on certain vlans, for example:

If you had Port ge-0/0/1 connected to Citylink with multiple IP addresses it might be worth asking if they can do BGP with this, that way using BGP they can route you different IP addresses and all you need to do is to update the router config to make these changes.

From here, you can allocate different computers / devices to different IP's - you can also get the Juniper to do natting for all computers on the "LAN" and give external IP's to the servers as needed.

If you didn't want the network on Port ge-0/0/2 accessing anything on port ge-0/0/1 the normal step would be to separate them with use of Vlans, you can also add certain devices to different vlans depending on your needs.

It's pretty hard to explain, but the best step would be for you to head over to these articles:

http://www.juniper.net/techpubs/software/erx/erx51x/swconfig-routing-vol2/html/bgp-config.html (This is for setting up BGP) 

http://www.juniper.net/techpubs/software/management/nmc-rx/nmc-rx73x/swconfig-nmc-rx-vol2/html/vlan-config.html (Setting up Vlans)

http://www.juniper.net/techpubs/software/erx/junose71/swconfig-routing-services/html/nat-config.html (Nat Config)

With these routers don't get sucked into using the web interface, it's best to leave this disabled and use the CLI - you will get your head around things easier that way. The cool thing with these routers is if you are doing the config through the CLI and break something (and had a working config beforehand) then the router will revert to that working config after a reboot unless if you commit it.

Good luck! Good on you for supporting Juniper! They are awesome pieces of equipment! 




Michael Murphy
[Twitter] [Last.fm] [IPv6 Sage]

Everything I say here is my own opinion and not that of my employer.

Create new topic




Twitter »
Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:




News »

Trending now »
Hot discussions in our forums right now:

Moment of Truth?
Created by BarTender, last reply by KiwiNZ on 18-Sep-2014 21:10 (360 replies)
Pages... 22 23 24


IOS8 - Network Load
Created by FireEngine, last reply by joker97 on 18-Sep-2014 19:43 (36 replies)
Pages... 2 3


10 Iphone 128gb 6+ iphones this weekend at auckland airport
Created by frysie, last reply by TimA on 17-Sep-2014 22:02 (36 replies)
Pages... 2 3


Mr. Key to extradite Kim Dotcom?
Created by TimA, last reply by SaltyNZ on 18-Sep-2014 09:20 (126 replies)
Pages... 7 8 9


Spark DNS Issues - Amazing - Broadband Service Alert
Created by PeteS, last reply by Demeter on 15-Sep-2014 14:13 (307 replies)
Pages... 19 20 21


New On Account mobile plans - Red+
Created by NikT, last reply by paulspain on 18-Sep-2014 21:39 (18 replies)
Pages... 2


Bizarre Policy on plan change
Created by toejam316, last reply by FireEngine on 18-Sep-2014 20:22 (17 replies)
Pages... 2


2014 Holden SS (V8) or Ford XR6-T (in-line 6 turbo)
Created by joker97, last reply by ilovemusic on 16-Sep-2014 14:34 (71 replies)
Pages... 3 4 5



Geekzone Live »
Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.

Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.