Hardware: Five EX4200 in Virtual Chassis Configuration
Software: Junos 10.4R5.5
In the past, I've used FBF on an SRX-100 to balance some traffic over various commodity Internet connections. Since I did this fairly easily after learning the process, I didn't figure this to be much of an issue.
I couldn't have been more wrong.
The problem is simple. We're moving from one ISP to another, and wish to do this gradually. Thankfully our network is set up as such that I can move a building at a time based on the IP subnets in the buildings. Currently, I'm just trying to get my laptop in my office to work as proof of concept, then move the building, then move everyone else. In my original config, the traffic wasn't even being shipped to the new routing instance. Now, it seems to be dropped altogether. Below is my relevant config:
interfaces{
ae0 {
aggregated-ether-options {
lacp {
active;
}
}
unit 0 {
family inet {
filter {
input InternetTraffic;
}
address 192.168.88.1/24;
}
}
}
}
routing-options {
interface-routes {
rib-group inet NewISP;
}
static {
route 0.0.0.0/0 next-hop 192.168.128.1;
route 172.24.88.0/22 next-hop 192.168.88.254;
route 172.25.88.0/22 next-hop 192.168.88.254;
route 172.26.88.0/22 next-hop 192.168.88.254;
route 172.27.88.0/22 next-hop 192.168.88.254;
route 172.22.88.0/22 next-hop 172.24.128.13;
route 172.23.88.0/22 next-hop 172.24.128.13;
route 172.28.88.0/22 next-hop 192.168.88.254;
}
rib-groups {
NewISP {
import-rib [ inet.0 NewISP.inet.0 ];
}
}
}
policy-options {
prefix-list NewISPRoutes {
172.26.89.131/32;
}
}
firewall {
family inet {
filter InternetTraffic {
term NewISP {
from {
source-prefix-list {
NewISPRoutes;
}
}
then {
routing-instance NewISP;
}
}
term default {
then accept;
}
}
}
}
routing-instances {
NewISP {
instance-type forwarding;
routing-options {
static {
route 0.0.0.0/0 next-hop 172.24.128.2;
route 172.24.88.0/22 next-hop 192.168.88.254;
route 172.25.88.0/22 next-hop 192.168.88.254;
route 172.26.88.0/22 next-hop 192.168.88.254;
route 172.27.88.0/22 next-hop 192.168.88.254;
route 172.28.88.0/22 next-hop 192.168.88.254;
route 172.22.88.0/22 next-hop 172.24.128.13;
route 172.23.88.0/22 next-hop 172.24.128.13;
}
}
}
}
I'm pretty much at my wits end. I've been struggling with this for over a week and have yet to find why my traffic isn't passing. Traceroutes die at this router every time. If I add a different IP to the prefix list and remove mine, everything routes as normal for me again while killing the other IP's traffic, so I know the rule is being observed. The biggest issue hurting me is that I have no visibility. On SRX, I could run a "show security flow session" and see how traffic was being routed. That command doesn't exist outside the "security" version of Junos that I can see. Even dropping to shell and running tcpdump on the ae0 interface turns up very little traffic, and none of the traffic I'm trying to find. This may be the biggest help, to at least be able to see where things are going. Any help would be immensely appreciated.