SRX Next-Gen Firewalls

 View Only
last person joined: 19 hours ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.

Welcome!

If you have a question or a use case, likely there are others who are experiencing or worked through the same thing. Don't hesitate to jump in and ask or share your knowledge!

Need additional guidance?  Check out these Juniper Resources.

Juniper Threat LabsSRX Upgrade Guide Security Advisories Technical Bulletins

Latest Discussion Posts

  • Thanks Nikolay. I'll do some further testing as soon as both my nodes are up and running. Currently one of them is in transit to another location, so I'm not able do test at the moment. And... no worries about not answering the question. Any feedback ...

  • This reminds me of the ScreenOS HA feature of yesteryear. Sure, you could route to the virtual IP address, but it took years of development before other features could use it. For a while you couldn't run OSPF on it, for example. I haven't used MNHA ...

  • I meant check the IP config on the PC to double-check my suspicion. On Windows, for example, you can open command prompt and say ipconfig /all to check what address, gateway, and DNS the computer has configured. ------------------------------ Nikolay ...

  • Hi Nikolay, Thank you for the assistance. After the IP of name-server is added, the PC is able to access internet. However, I would like to confirm what do you mean for You can verify this by examining the active IP configuration on the endpoint? ...

  • Hi all. This question is regarding Multinode High Availability (MNHA) setup of two Juniper SRX nodes in a hybrid deployment: It seems that you always need to have 3 IP addresses for each VLAN; one unique for each node and one virtual IP. For ...

  • Have you tried resetting to factory, then connecting via the console port, then in the cli switch to root access commands. There is a document which covers this on the web. I know it's still there and it's for srx300. I'd look for it but I forgot the ...

  • Your internal client machine at 10.10.10.2 is not getting any DNS server information. You can verify this by examining the active IP configuration on the endpoint. Because ge-0/0/0.0 has a static IP address, it has no settings it can propagate downstream ...

Unanswered Posts

Top Contributors in the Community