Ethernet Switching
Reply
Recognized Expert
Loup2
Posts: 301
Registered: ‎04-22-2008
0

Re: Default route for vme/me management ports?

OK , I understand your problem !

 

So that should be easy to leave the VME interface in the main routing table and the real "transient" interfaces in a VR type routing-instance !

 

I am also surprised that you're not able to have some supernet for your management network !

 

I understand that you'd like to have Logical-router (logical-system now) on EX switches, so would I, but i am not sure we will have this since a long time.

 

Alain

 

 

 

Trusted Contributor
BuckWeet
Posts: 159
Registered: ‎08-29-2008
0

Re: Default route for vme/me management ports?

You could put all other interfaces into a vrf, but that is an idiotic way to do it in my opinion.. If I were to have an 8216 fully poppulated with modules, it would mean i have to put hundreds of interfaces into it. Let alone that JUNOS has a hack implementation of interface-ranges with 10.x, it's just cumbersome..

 

I asked my SE to put in a feature request to allow VME/FXP interfaces into a VRF.

 

BuckWeet

Recognized Expert
Loup2
Posts: 301
Registered: ‎04-22-2008
0

Re: Default route for vme/me management ports?

Hi BuckWeet

 

That's a nice request.

I'm not sure you will see it going out quickly !

 

Still doesn't understand why you're locked with this static "default" route.

Or your OOB network is completely unstructured !

 

I was just trying to help but it seems that can't be done

 

Kind regards

The Idiot guy who wanted to help you!

Contributor
MM2503
Posts: 12
Registered: ‎04-30-2009

Re: Default route for vme/me management ports?

I to have had many times when a dedicated OOB-RI with it's own Default would have saved me plenty of pain.

 

On some sites it is a legislated requirement to seperate the managment plane traffic from the rest.

 

I had this issue with 9.4 and as of my testing on 10.1 there still seems to be a lack of urgency from Juniper about this need.

 

I would imagine this would not be to hard to add in.

 

On Extreme XOS devices they have VR-Default and VR-MGMT.  You can cretate your own as you require but the OOBMI are all in the MGMT VLAN which is in the VR-MGMT.

 

It takes about 3 minutes to set this aspect of the product up.

 

Juniper should start to take this request on board as a OOBM Network should be standard practice for all networks with more than a half dozen switches.

 

For me the work around was to go inband and to ensure all managment interfaces are access-limited and encrypted.

 

Regards

 

Marc

    

Regular Visitor
bohara
Posts: 10
Registered: ‎03-31-2010
0

Re: Default route for vme/me management ports?

+1

 

I need my management routing separate to my main routing table.  On a managed customer fw, there's no way the customer equipment should ever see my management network regardless of any fw rules blocking them from management.

Regular Visitor
simon.bingham@splc.co.uk
Posts: 7
Registered: ‎04-10-2012
0

Re: Default route for vme/me management ports?

I was just about to add exactly that point about Extreme. 

With extreme the MGMT port is predefined with a separate VR instance. 

 

Separate routing table for both in fact its not possible to route between the 2 which is exactly what you want. 

I still find it hard to belive JUNOS does not support this, the whole point of the MGMT port is it is a separate interface to the management much like the serial port, only IP.

This is an example config to configure the MGMT on an extreme, job done. 

 

configure vlan Mgmt ipaddress 172.27.233.43 255.255.255.0
configure iproute add 10.0.0.0 255.255.255.0 172.27.233.254 vr VR-Mgmt

 

Simon

Visitor
Stephen D
Posts: 1
Registered: ‎04-23-2012
0

Re: Default route for vme/me management ports?

Please don't say this is still a restriction ?? I've just spent the last half an hour trying to do this (yeah, yeah. I'm a cisco head, that's why it took so long :smileywink:)

 

How would I go about looking to see if it's been scheduled as an enhancement request ?

Distinguished Expert
muttbarker
Posts: 2,363
Registered: ‎01-29-2008
0

Re: Default route for vme/me management ports?

Stephen - the Juniper party line is that you need to talk to your Juniper Sales Team and get them to submit an enhancement request for you. I don't think you will get any feedback as to where it is in the priority list, or if it is even on the list (unless you have a lot of clout) but the more requests the more Juniper will listen and do the obvious fix.

Kevin Barker
JNCIP-SEC
JNCIS-ENT, FWV, SSL, WLAN
JNCIA-ER, EX, IDP, UAC, WX
Juniper Networks Certified Instructor
Juniper Networks Ambassador

Juniper Elite Reseller
J-Partner Service Specialist - Implementation

If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.