keithr,
I'll need your help with this.
The 'accepted solution' doesn't work for me. And I have got the exact same scenario as what's mentioned in this thread.
Except, i'm using the awesome added benefit's that 11.1R1.10 brings, with regards to the switching capabilites on a cluster. (No more reth's. I just have ae interfaces. It works great ! 🙂 )
Pretty simple....
I have a management subnet (10.12.5.x /24). And a bunch of prefixes switched to the firewall, originating downstream, from an EX4200 VC. The prefixes sent to the firewall are DMZ based prefixes that need FW policies applied. All other 'locally significant' prefixes switch and route on the VC and end there. The Management subnet is one of these.
I.e. A bunch of vlans (Management, Clients, Printers, etc) that switch across the VC and terminate via RVI's on the switch, and then a bunch of vlans (FW-Untrust, FW-DMZ-Corp, FW-DMZ-Public, FW-DMZ-Public-Int, etc) whose RVI's terminate, upstream, on the FW. ae0 and ae1 feeding LACP enabled trunks interconnect the VC and SRX cluster.
The Ge-0/0/0 (and Ge-9/0/0 (SRX650) on Node1) from each SRX member, physically, have cables that plug into ports on the VC, that are mapped to the management subnet, via Vlan 5. Now, I read that Ge-0/0/0 turns into FXP0 once a cluster is created between two members. Is that correct ?
Through your config, I created 10.12.5.2 & 10.12.5.3 on the FXP0 interfaces for each SRX node (Node 0 & Node 1), via the,
set groups node0 interfaces fxp0 unit 0 family inet address 10.12.5.2/24
set groups node1 interfaces fxp0 unit 0 family inet address 10.12.5.3/24
commands.
And the 'backup router' statements with the 'destination' parameters,
i.e.,
backup-router 10.12.5.1 (RVI address on VC) destination 10.12.12.1/24 (prefix of 'Clients' on VC)
----------------------------------------------------------------------------------------------------------------------------------------------------------------
To be clear, if you've understand the above methodology, the 'Management' prefix/vlan, DOES NOT transit (not included in the trunk list on ae0 and ae1 from VC to SRX cluster) the SRX cluster, so I'm hopefully satisfying the requirements of trying to use the FXP0 interfaces 'Out of Band'.
----------------------------------------------------------------------------------------------------------------------------------------------------------------
So, like, paulkil here, I can ping each IP address from a 'Clients' vlan (10.12.12.x /24), but can't SSH, HTTPS to it.
The provided config doesn't help, and, from my undestanding I should be able to manage the SRX cluster on 10.12.5.2 when Node0 is active, and on 10.12.5.3 when Node1 is active, in this way, utilising this 'Out of Band' method with the Ge-0/0/0/Ge-9/0/0/FXP0 interface.