JuniperForum.com
September 07, 2010, 07:45:40 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: Two Wan links  (Read 3651 times)
GDSA
Newbie
*
Posts: 3


View Profile
« on: April 18, 2008, 12:43:16 PM »

Hi,

Currently I had Two links coming on a single Ethernet cable , One for Internet traffic and Second is MPLS vpn Network for branch offices. Both had separate gateways and Subnets…..

At present it is configured on Cisco 2800 router and two Vlans are configured on Single Wan Interface to separate the traffic of both the network and static routs are configured for the flow of  traffic as required.

But now I am removing the Cisco Router and replacing it with SSG 20 Appliance. But I am getting confused with its options on its Untreated Interfaces and Vlans. I tried to Separate the Traffic by configuring Sub-Interfaces on Wan Port , But it did not worked….

Can any one suggest Best method to Configure SSG 20 and the configuration steps to separate the Wan traffic on a single Interface as done on Cisco Router….

Logged
wpj
Full Member
***
Posts: 170


View Profile
« Reply #1 on: April 20, 2008, 10:54:58 AM »

I would use VLAN tags and subinterfaces..
Logged

JNCIS-FWV, JNCIS-ER, JNCIA-FWV, JNCIA-SSL, JNCIA-AC, JNCIA-ER
JNSS-S, JNSS-R, JNSS-AC, JNSS-EN, JNSA-S, JNSA-EN, JNSA-AC, JNSA-DX
screenie.
Hero Member
*****
Posts: 1236


View Profile
« Reply #2 on: April 20, 2008, 11:11:39 AM »

So would I! But: don' t forget to set the subinterface as outgoing interface for routes, including default route. Otherwise the traffic won't be tagged.
Logged

Regards, Screenie
------------------------
JNSS, JNCIA, JNCIS, JNCI
GDSA
Newbie
*
Posts: 3


View Profile
« Reply #3 on: April 20, 2008, 12:08:31 PM »

Thnx for the reply...

i had tried to create the sub interfaces and assign the Routs accordingly. Buy the sub interfaces didnt allowed to send the data outside. Does Sub-Interfaces require some separate licenses to work...Huh?
Logged
screenie.
Hero Member
*****
Posts: 1236


View Profile
« Reply #4 on: April 20, 2008, 02:09:53 PM »

No, no additinonal license needed. Did you make sure you created them in the untrust zone? If I recall well trust is the default.
Logged

Regards, Screenie
------------------------
JNSS, JNCIA, JNCIS, JNCI
GDSA
Newbie
*
Posts: 3


View Profile
« Reply #5 on: April 21, 2008, 01:02:07 AM »

can u please upload the complete procedure to configure VLANs and Sub interfaces
Logged
Packet7
Jr. Member
**
Posts: 82


View Profile
« Reply #6 on: April 25, 2008, 01:42:04 PM »

Hi,

What version of ScreenOS are you running?  I don't think subinterfaces in the untrust zone is support in 5.x.  However, the C&E for 6.x mentions any zone.

Rgds,

John
Logged
wpj
Full Member
***
Posts: 170


View Profile
« Reply #7 on: April 25, 2008, 07:59:11 PM »

I have been able to use subinterfaces in 4.0 code so they have been there
Logged

JNCIS-FWV, JNCIS-ER, JNCIA-FWV, JNCIA-SSL, JNCIA-AC, JNCIA-ER
JNSS-S, JNSS-R, JNSS-AC, JNSS-EN, JNSA-S, JNSA-EN, JNSA-AC, JNSA-DX
thebull
Newbie
*
Posts: 5


View Profile
« Reply #8 on: May 06, 2008, 03:16:34 PM »

Bro,

I would suggest to create Zone for two Internet connections, which will help you to define the rules and routing.

I will send the link later for configuring zones on interfaces.
Logged
screenie.
Hero Member
*****
Posts: 1236


View Profile
« Reply #9 on: October 12, 2008, 10:41:29 AM »

The procedure for a sub int:

set int e1.1 tag 10 zone (un)trust
set int e1.1 ip ..../..

Nothing fancy about it!!

In 5.3 you where allready free to chose any zone for the subint.
Logged

Regards, Screenie
------------------------
JNSS, JNCIA, JNCIS, JNCI
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
  • Total Members: 22514
  • Latest: Deepy
Stats
  • Total Posts: 40575
  • Total Topics: 11249
  • Online Today: 77
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 3
Guests: 57
Total: 60
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.215 seconds with 38 queries.