JuniperForum.com
September 09, 2010, 02:14:56 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: NSRP + BGP  (Read 1409 times)
10us
Jr. Member
**
Posts: 65


View Profile
« on: September 05, 2007, 09:13:48 AM »

Hi,

I try to find out if we can support redundant fiber (ethernet) access with two SSG-140's and without any routers in front of it. Preferable active/passive. I guess BGP should determine on the outside which node to use, but the inside should be full-mesh for the internal hosts to have a gateway. Somebody understand what I mean?  wink

Somebody any experience?

Cheers,

Martijn
Logged
MaxPipeline
Hero Member
*****
Posts: 702


View Profile
« Reply #1 on: September 10, 2007, 12:01:52 PM »

Yes, this is all possible.  Refer to Concept and Examples (C&E)guides at www.juniper.net/techpubs/software/screenos/.  In particular review the High Availability guide.

Logged

Help us help you.

Have you looked at the documentation?
http://www.juniper.net/techpubs/

Have you checked the Juniper Knowledgebase?
http://kb.juniper.net
greg1c
Full Member
***
Posts: 190


View Profile
« Reply #2 on: September 14, 2007, 04:25:50 PM »

The SSG 140 running 5.4 code can do active/passive Failover, and with 6.0 you can do Active/Active.  The number of BGP routes is only 2,048 so you more than likely or only taking a default route.  So I would configure one SSG 140 how I wanted it and then add the HA to it.  The Active/Passive means the interfaces on the passive firewall are inactive until the firewall fails or an interface or tracked ip fails.

Greg
Logged
screenie.
Hero Member
*****
Posts: 1236


View Profile
« Reply #3 on: December 15, 2007, 11:14:38 AM »

Be carefull to use version 6. In 5.4 bgp (or ospf) is * * not * * synchronised by NSRP.

Then (just thinking about it, never tried it) place two fibre int in both devices. (just install a multiple fibre card in both)

Of course you need a public range of IP adress.

Configure BGP peers for both ISP's, only one works ofcoure, but in failover the otherone will work.
import only 0.0.0.0 export your public IP's, should work.

Becouse of changing outgoing interface sessions will die in failover, so configure a big preempt holddowntime! Also allow I acspect a minute or so for things to work again afterfailover. Just t5est it!

Bye.
Logged

Regards, Screenie
------------------------
JNSS, JNCIA, JNCIS, JNCI
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
Stats
  • Total Posts: 40719
  • Total Topics: 11389
  • Online Today: 82
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 1
Guests: 48
Total: 49
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.211 seconds with 37 queries.