Security

 View Only
last person joined: 18 days ago 

Ask questions and share experiences with Juniper Connected Security. Discuss Advanced Threat Protection, SecIntel, Secure Analytics, Secure Connect, Security Director, and all things related to Juniper security technologies.
  • 1.  Make service NAT card as layer 2, transparent to layer 3&mpls

    Posted 02-23-2025 22:28

    Hi team,

    I have a topo as below:

    All routers are MX-series.

    R2 has an MS-MPC card.

    Can I make R2 as transparent, so R1 and R3 can peer IGP, MPLS directly.

    And traffic between R1 and R3 will pass through MS-MPC card in R2.

    Please give me some ideas.

    Thanks.



    ------------------------------
    Harry
    ------------------------------


  • 2.  RE: Make service NAT card as layer 2, transparent to layer 3&mpls

    Posted 02-24-2025 19:08

    You should be able to use Local Interface Switching for a Layer 2 Circuit to connect the two R2 subinterfaces.  Then configure the interfaces on R1 & R3 as layer 3 neighbors for your IGP peers.

    https://www.juniper.net/documentation/us/en/software/nce/nce-078-layer-2-circuits/topics/task/layer-two-circuits-local-interface-switching-solutions.html



    ------------------------------
    Steve Puluka BSEET - Juniper Ambassador
    IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP - Retired)
    http://puluka.com/home
    ------------------------------



  • 3.  RE: Make service NAT card as layer 2, transparent to layer 3&mpls

    Posted 02-24-2025 21:31

    Hi Steve,

    How can we sure this traffic pass through card NAT (MS-MPC) in R2.

    Can we use mams interface as l2-interface?



    ------------------------------
    Harry
    ------------------------------



  • 4.  RE: Make service NAT card as layer 2, transparent to layer 3&mpls

    Posted 02-25-2025 19:35

    Sorry, I don't understand what you mean by NAT MS-MPC card.  What is the function you or configuration sample you are referring to?



    ------------------------------
    Steve Puluka BSEET - Juniper Ambassador
    IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP - Retired)
    http://puluka.com/home
    ------------------------------



  • 5.  RE: Make service NAT card as layer 2, transparent to layer 3&mpls

    Posted 03-03-2025 11:12

    Hi Steve,

    I want to configure R2 as layer 3 transparent so that R1 and R3 can peer IGP and MPLS directly.

    But traffic between R1 and R3 has to pass through NAT card in R2. 

    Can we make NAT card as a part of L2 bridge in R2?



    ------------------------------
    Harry
    ------------------------------



  • 6.  RE: Make service NAT card as layer 2, transparent to layer 3&mpls
    Best Answer

    Posted 03-03-2025 19:15

    I don't have any experience with the CG NAT features, but looking a the overview blog and documentation, it seems that all that is needed is the configure the inside and and outside interfaces for the flow.  It would seem that could be the two interfaces on R2 that would be configured as the l2circuit in this scenario.  But a lab test would be a good idea.

    Blog overview:

    https://community.juniper.net/blogs/ricardo-dominguez/2023/08/03/centralized-deterministic-cgnat

    Documentation

    https://www.juniper.net/assets/us/en/local/pdf/implementation-guides/8010076-en.pdf



    ------------------------------
    Steve Puluka BSEET - Juniper Ambassador
    IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP - Retired)
    http://puluka.com/home
    ------------------------------



  • 7.  RE: Make service NAT card as layer 2, transparent to layer 3&mpls

    Posted 03-14-2025 00:55

    Thank spuluka for your info.



    ------------------------------
    Harry
    ------------------------------