Interface configuration:
set protocols l2-learning global-mode transparent-bridge
set interfaces ge-0/0/4 unit 0 family ethernet-switching interface-mode trunk
set interfaces ge-0/0/4 unit 0 family ethernet-switching vlan members vlan10
set interfaces ge-0/0/15 flexible-vlan-tagging
set interfaces ge-0/0/15 unit 0 family ethernet-switching interface-mode trunk
set interfaces ge-0/0/15 unit 0 family ethernet-switching vlan members vlan10
set interfaces ge-0/0/15 unit 99 family ethernet-switching interface-mode trunk
set interfaces ge-0/0/15 unit 99 family ethernet-switching vlan members vlan99
set vlans vlan10 vlan-id 10
set vlans vlan99 vlan-id 99
set vlans vlan99 l3-interface irb.10
set interfaces irb unit 10 family inet address 10.10.99.2/30
set security zones security-zone trust host-inbound-traffic system-services all
set security zones security-zone trust host-inbound-traffic protocols all
set security zones security-zone trust interfaces ge-0/0/4.0
set security zones security-zone trust interfaces ge-0/0/15.99
set security policies from-zone trust to-zone trust policy trust-to-trust match source-address any
set security policies from-zone trust to-zone trust policy trust-to-trust match destination-address any
set security policies from-zone trust to-zone trust policy trust-to-trust match application any
set security policies from-zone trust to-zone trust policy trust-to-trust then permit
If I try and set the IRB interface to the trust zone I get the following error:
[edit security zones security-zone trust]
'interfaces irb.10'
Interface irb is not allowed in mix mode
If I create a new zone and assign irb.10 to it I get (I don't have the config), but something like:
Can't assign policy to Layer 2 and Layer 3 zones
The layer 2 works perfectly from end-to-end .... just stuck on this last point and not sure if it is possible on this device.