Hi All,
Could someone please help me with this issue. I have 2 SRX340 to cluster, however I have setup a lab on EVE to configure and test before configuring the SRX340.
I'm unable to ping from the PC on my Trusted zone to the Router on the Untrusted zone. I'm not sure if I'm missing something. Any help will be appreciated
JUNOS 17.3R1.10
I have attached the topology
To confirm all chasis interfaces are up and I have run all the necessary command to make sure the cluster is fine.
PC - 10.10.10.5/24 - Trusted Zone
Router - 10.10.10.1/24 - Untrusted Zone.
Below is the config :
set groups node0 system host-name srx-a
set groups node0 interfaces fxp0 unit 0 family ethernet-switching interface-mode access
set groups node0 interfaces fxp0 unit 0 family ethernet-switching vlan members vlan-254
set groups node0 interfaces irb unit 0 family inet address 192.168.254.53/24
set groups node1 system host-name srx-b
set groups node1 interfaces fxp0 unit 0 family ethernet-switching interface-mode access
set groups node1 interfaces fxp0 unit 0 family ethernet-switching vlan members vlan-254
set groups node1 interfaces irb unit 0 family inet address 192.168.254.54/24
set apply-groups "${node}"
set chassis cluster reth-count 2
set chassis cluster redundancy-group 0 node 0 priority 200
set chassis cluster redundancy-group 0 node 1 priority 100
set chassis cluster redundancy-group 1 node 0 priority 200
set chassis cluster redundancy-group 1 node 1 priority 100
set interfaces fab0 fabric-options member-interfaces ge-0/0/1
set interfaces fab1 fabric-options member-interfaces ge-7/0/1
set interfaces ge-0/0/3 gigether-options redundant-parent reth0
set interfaces ge-7/0/3 gigether-options redundant-parent reth0
set interfaces ge-0/0/2 gigether-options redundant-parent reth1
set interfaces ge-7/0/2 gigether-options redundant-parent reth1
set interfaces reth0 redundant-ether-options redundancy-group 1
set interfaces reth0 unit 0 family ethernet-switching interface-mode access
set interfaces reth0 unit 0 family ethernet-switching vlan members vlan-10
set interfaces reth1 redundant-ether-options redundancy-group 1
set interfaces reth1 unit 0 family ethernet-switching interface-mode access
set interfaces reth1 unit 0 family ethernet-switching vlan members vlan-10
set security zones security-zone Trusted
set security zones security-zone Untrusted
set security zones security-zone Trusted host-inbound-traffic system-services all
set security policies from-zone Trusted to-zone Untrusted policy trust-untrust match source-address any
set security policies from-zone Trusted to-zone Untrusted policy trust-untrust match destination-address any
set security policies from-zone Trusted to-zone Untrusted policy trust-untrust match application any
set security policies from-zone Trusted to-zone Untrusted policy trust-untrust then permit
set vlans vlan-10 vlan-id 10
set vlans vlan-254 vlan-id 254
set vlans vlan-254 l3-interface irb.254
set routing-options static route 0.0.0.0/0 next-hop 192.168.254.254
===================================================
SW3- config : Just layer 2
!
interface Ethernet0/0
switchport access vlan 10
switchport mode access
!
interface Ethernet0/1
switchport access vlan 10
switchport mode access
!
interface Ethernet0/2
switchport access vlan 10
switchport mode access
!
interface Ethernet0/3
!
===================
SW3- config : Just layer 2
!
interface Ethernet0/0
switchport access vlan 10
switchport mode access
!
interface Ethernet0/1
switchport access vlan 10
switchport mode access
!
interface Ethernet0/2
switchport access vlan 10
switchport mode access