Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


JAMMAN2110

871 posts

Ultimate Geek

Trusted

#69647 12-Oct-2010 16:34
Send private message

Hi all

We are looking at getting a Juniper SRX240 firewall but I can't find any information to answer some questions.

I need to know if the ports are physically separate or if they are just VLANed apart. (After switching has been disabled)

We need to have 1 interface connected to Citylink that can handle multiple IP addresses, and a backup ADSL / VDSL card.

Different servers will have different IP addresses / ports associated with them, but for compliance purposes we need to be able to prove that Server A on port ge-0/0/5 (which has IP XXX.XXX.XXX.XXX externally) can't talk directly to Server B on port ge-0/0/6 (which has IP XXX.XXX.XXX.YYY externally)

Can anyone help me answer the above question?

Cheers
James

Create new topic
muppet
2572 posts

Uber Geek

Trusted

  #391020 12-Oct-2010 16:44
Send private message

I don't quite understand what you're asking, sorry :)

The ports don't act like a hub though, if that's what you mean? You have to say "this port's in this VLAN"

Tim




Audiophiles are such twits! They buy such pointless stuff: Gold plated cables, $2000 power cords. Idiots.

 

OOOHHHH HYPERFIBRE!




JAMMAN2110

871 posts

Ultimate Geek

Trusted

  #391024 12-Oct-2010 16:48
Send private message

muppet: I don't quite understand what you're asking, sorry :)

The ports don't act like a hub though, if that's what you mean? You have to say "this port's in this VLAN"

Tim


I'm finding it quite hard to explain.

Really, we need one ethernet port for internet (I'm ignoring the ADSL / VDSL card) and then have the other Ethernet ports as separate zones, such as "Web Servers", "Mail Servers", "File Servers" etc

Does that explain it better? I'm told we need to do better than just VLANs

michaelmurfy
meow
13275 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #391042 12-Oct-2010 17:34
Send private message

The best thing would be to put the likes of certain ports on certain vlans, for example:

If you had Port ge-0/0/1 connected to Citylink with multiple IP addresses it might be worth asking if they can do BGP with this, that way using BGP they can route you different IP addresses and all you need to do is to update the router config to make these changes.

From here, you can allocate different computers / devices to different IP's - you can also get the Juniper to do natting for all computers on the "LAN" and give external IP's to the servers as needed.

If you didn't want the network on Port ge-0/0/2 accessing anything on port ge-0/0/1 the normal step would be to separate them with use of Vlans, you can also add certain devices to different vlans depending on your needs.

It's pretty hard to explain, but the best step would be for you to head over to these articles:

http://www.juniper.net/techpubs/software/erx/erx51x/swconfig-routing-vol2/html/bgp-config.html (This is for setting up BGP) 

http://www.juniper.net/techpubs/software/management/nmc-rx/nmc-rx73x/swconfig-nmc-rx-vol2/html/vlan-config.html (Setting up Vlans)

http://www.juniper.net/techpubs/software/erx/junose71/swconfig-routing-services/html/nat-config.html (Nat Config)

With these routers don't get sucked into using the web interface, it's best to leave this disabled and use the CLI - you will get your head around things easier that way. The cool thing with these routers is if you are doing the config through the CLI and break something (and had a working config beforehand) then the router will revert to that working config after a reboot unless if you commit it.

Good luck! Good on you for supporting Juniper! They are awesome pieces of equipment! 




Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


Create new topic





News and reviews »

Gen Threat Report Reveals Rise in Crypto, Sextortion and Tech Support Scams
Posted 7-Aug-2025 13:09


Logitech G and McLaren Racing Sign New, Expanded Multi-Year Partnership
Posted 7-Aug-2025 13:00


A Third of New Zealanders Fall for Online Scams Says Trend Micro
Posted 7-Aug-2025 12:43


OPPO Releases Its Most Stylish and Compact Smartwatch Yet, the Watch X2 Mini.
Posted 7-Aug-2025 12:37


Epson Launches New High-End EH-LS9000B Home Theatre Laser Projector
Posted 7-Aug-2025 12:34


Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.