I am newbie to Juniper world. 🙂 I have a question about setting up a HA parir SRX cluster.
I have planning to do a setup like this. First thing I wanted to know is whether this is a valid design?
The reason why I am aiming for etherchannel between SRX and the switch is there a around 10 differnet zones that we need to setup in SRX. I could set each zone into a physical interface in SRX. What I wanted to check is if there is way to setup a trunk from switch to SRX and push differnet zone traffic to SRX. At the same time I need to setup differnet Reth interfaces for all zones for HA between the SRXs.
To recap the requirements are:
1) All 10 zones traffic sent to the SRX using a Etherchannel that carries different VLAN traffic to SRX
2) Have a proper HA cluster using Reth interfaces for 10 different redundancy groups.
Please let me know if you need more details.
You may refer following kb to connect SRX with Switch (running LACP/Etherchannel).
For the requirements you mentioned, i would like to break it in parts.
1) All 10 zones traffic sent to the SRX using a Etherchannel that carries different VLAN traffic to SRX. ---> You can configure vlan-tagging on reth interfaces which will carry different vlan traffic to respective subinterfaces. You may assigned each sub-interface to different zone as per your requirements.
2) Have a proper HA cluster using Reth interfaces for 10 different redundancy groups - This is a conflicting requirements to above. You can achieve a proper HA failover of 1 reth (with multiple sub-interfaces) using 1 redundancy group as you can not map a subinterfaces of reth to different redundancy groups. hence, following will be two possible solutions.
(a). - create a 1 reth and map it to 1 redundancy group. which will do the desired failover.
(b). if you want to create 10 redundancy group, then you need to create 10 reth with different IP addresses and different ports for each vlans. It will increase the cabling and managebility over head hence not recommended solution. But at the end of the it is customer's choice.
Kindly close the thread if it has resolved your issue please.
Here is a good example: