last person joined: 23 hours ago 

Ask questions and share experiences about the SRX Series.
  • 1.  SRX240 cluster control link

    Posted 11-02-2009 05:04


    I am running 2x 240's with 9.6r1 in a clustered scenario and everything seems to be working. Currently I have the control links and data links directly connected to eachother and HA seems to be operating


    However if I try and move the control link via a switch and reboot the cluster, the HA always fails. I noticed on another thread that currently the control link needs to be connected directly, I would just like to double check this statement





  • 2.  RE: SRX240 cluster control link

    Posted 11-02-2009 08:28

    It's true that you should connect the control link back to back.

    Control link traffic is tagged with the VLAN-ID 4094.


    If you want to connect it via a switch you need to configure your switch with this VLAN setting.


    best regards


    If this worked for you please flag my post as an "Accepted Solution" so others can benefit.
    A kudo would be cool if you think I earned it.



  • 3.  RE: SRX240 cluster control link

    Posted 11-02-2009 12:34

    Hi Thorsten

    Thanks for that, howver this is what i've got so far


    A [FW1]ctrl link------------------------------ctrl link[FW2] (HA ok)
    B [FW1]ctrl link----switched nw---------ctrl link[FW2] (HA fail)
    C [FW1]ctrl link---QinQ switched nw--ctrl link[FW2] (HA fail)


    If that traffic is tagged I can see scenario B failing, however I'm surprised C fails as this just passes on whatever it receives. Incidentally the QinQ network is based EX4200's, do you think somethin is being blocked at all between QinQ access port?


    I've opened this up with TAC but not got any response as its only been 5 days 🙂





  • 4.  RE: SRX240 cluster control link

    Posted 11-04-2009 03:21

    According to JTAC, its not supported

  • 5.  RE: SRX240 cluster control link
    Best Answer

    Posted 11-09-2009 07:38

    FYI, it is supported on the High-end SRX. Look for an application note named "SRX series services gateways cluster deployment across layer 2 networks" (google will find it - its somewhere on the juniper website).


    We did such a setup with 3400s a while back and it takes quite a bit of work to get this up and running:

    - if your switches perform IGMP snooping, try disabling it

    - if the switches are cisco, you need to disable the ip-header verification. They will verify the IP header even for switched traffic, and the packets sent by the SRXs aren't valid IP so they will get dropped without any logging


  • 6.  RE: SRX240 cluster control link

    Posted 12-08-2009 09:47

    I can't find this application note. Any idea where I can find it ?





  • 7.  RE: SRX240 cluster control link

    Posted 12-10-2009 15:15

    Hi Jerome,


    You can find the Application note here:



    Best regards,