Switching

last person joined: 23 hours ago 

Ask questions and share experiences about EX and QFX portfolios and all switching solutions across your data center, campus, and branch locations.
  • 1.  SRX240 ROS trunked to Cisco 6500

    Posted 11-30-2012 12:55

    All, 

     

    I am trying to set up a ROS scenario between a SRX240 and a Cisco 6500 switch.  I have created logical interfaces on ge0/0/1 interface.  I have set the Cisco port to trunk.  Not sure what I am missing.  I am new to Juniper and a have a little experience in the LAN realm.  I am hoping someone can point me in the right direction or point out something that I missed. 

     

    Configs are below:

     

    SRX240 - [12.1R4.7]
    newbie@SRX240-RTR-1# show interfaces ge-0/0/1 | display set
    set interfaces ge-0/0/1 vlan-tagging
    set interfaces ge-0/0/1 unit 1 description Mgmnt-LAN
    set interfaces ge-0/0/1 unit 1 vlan-id 1
    set interfaces ge-0/0/1 unit 1 family inet address 10.1.1.2/24 vrrp-group 1 virtual-address 10.1.1.1
    set interfaces ge-0/0/1 unit 1 family inet address 10.1.1.2/24 vrrp-group 1 priority 150
    set interfaces ge-0/0/1 unit 1 family inet address 10.1.1.2/24 vrrp-group 1 preempt
    set interfaces ge-0/0/1 unit 1 family inet address 10.1.1.2/24 vrrp-group 1 accept-data
    set interfaces ge-0/0/1 unit 1 family inet address 10.1.1.2/24 vrrp-group 1 track interface lsq-0/0/0:0.0 priority-cost 20
    set interfaces ge-0/0/1 unit 100 description Admin-LAN
    set interfaces ge-0/0/1 unit 100 vlan-id 100
    set interfaces ge-0/0/1 unit 100 family inet address 10.1.100.2/24 vrrp-group 100 virtual-address 10.1.100.1
    set interfaces ge-0/0/1 unit 100 family inet address 10.1.100.2/24 vrrp-group 100 priority 150
    set interfaces ge-0/0/1 unit 100 family inet address 10.1.100.2/24 vrrp-group 100 preempt
    set interfaces ge-0/0/1 unit 100 family inet address 10.1.100.2/24 vrrp-group 100 accept-data
    set interfaces ge-0/0/1 unit 100 family inet address 10.1.100.2/24 vrrp-group 100 track interface lsq-0/0/0:0.0 priority-cost 20
    set interfaces ge-0/0/1 unit 313 description Wireless-LAN
    set interfaces ge-0/0/1 unit 313 vlan-id 313
    set interfaces ge-0/0/1 unit 313 family inet address 10.1.13.2/24 vrrp-group 13 virtual-address 10.1.13.1
    set interfaces ge-0/0/1 unit 313 family inet address 10.1.13.2/24 vrrp-group 13 priority 150
    set interfaces ge-0/0/1 unit 313 family inet address 10.1.13.2/24 vrrp-group 13 preempt
    set interfaces ge-0/0/1 unit 313 family inet address 10.1.13.2/24 vrrp-group 13 accept-data
    set interfaces ge-0/0/1 unit 313 family inet address 10.1.13.2/24 vrrp-group 13 track interface lsq-0/0/0:0.0 priority-cost 20
    set interfaces ge-0/0/1 unit 314 description PASS-LAN
    set interfaces ge-0/0/1 unit 314 vlan-id 314
    set interfaces ge-0/0/1 unit 314 family inet address 10.1.14.2/24 vrrp-group 14 virtual-address 10.1.14.1
    set interfaces ge-0/0/1 unit 314 family inet address 10.1.14.2/24 vrrp-group 14 priority 150
    set interfaces ge-0/0/1 unit 314 family inet address 10.1.14.2/24 vrrp-group 14 preempt
    set interfaces ge-0/0/1 unit 314 family inet address 10.1.14.2/24 vrrp-group 14 accept-data
    set interfaces ge-0/0/1 unit 314 family inet address 10.1.14.2/24 vrrp-group 14 track interface lsq-0/0/0:0.0 priority-cost 20

    > show interfaces ge-0/0/1
    Physical interface: ge-0/0/1, Enabled, Physical link is Up
      Interface index: 135, SNMP ifIndex: 509
      Link-level type: Ethernet, MTU: 1518, Link-mode: Full-duplex, Speed: 100mbps,
      BPDU Error: None, MAC-REWRITE Error: None, Loopback: Disabled,
      Source filtering: Disabled, Flow control: Enabled, Auto-negotiation: Enabled,
      Remote fault: Online
      Device flags   : Present Running
      Interface flags: SNMP-Traps Internal: 0x0
      CoS queues     : 8 supported, 8 maximum usable queues
      Current address: b0:a8:6e:be:a2:81, Hardware address: b0:a8:6e:be:a2:81
      Last flapped   : 2012-12-01 04:12:08 GMT (00:20:50 ago)
      Input rate     : 0 bps (0 pps)
      Output rate    : 2152 bps (4 pps)
      Active alarms  : None
      Active defects : None
      Interface transmit statistics: Disabled

      Logical interface ge-0/0/1.1 (Index 70) (SNMP ifIndex 560)
        Description: Mgmnt-LAN
        Flags: SNMP-Traps 0x0 VLAN-Tag [ 0x8100.1 ]  Encapsulation: ENET2
        Input packets : 29
        Output packets: 87105
        Security: Zone: Trust
        Allowed host-inbound traffic : bootp bfd bgp dns dvmrp igmp ldp msdp nhrp
        ospf pgm pim rip router-discovery rsvp sap vrrp dhcp finger ftp tftp
        ident-reset http https ike netconf ping reverse-telnet reverse-ssh rlogin
        rpm rsh snmp snmp-trap ssh telnet traceroute xnm-clear-text xnm-ssl lsping
        ntp sip r2cp
        Protocol inet, MTU: 1500
          Flags: Sendbcast-pkt-to-re
            Destination: 10.1.1/24, Local: 10.1.1.1, Broadcast: 10.1.1.255
          Addresses, Flags: Is-Preferred Is-Primary
            Destination: 10.1.1/24, Local: 10.1.1.2, Broadcast: 10.1.1.255

      Logical interface ge-0/0/1.100 (Index 71) (SNMP ifIndex 561)
        Description: Admin-LAN
        Flags: SNMP-Traps 0x0 VLAN-Tag [ 0x8100.100 ]  Encapsulation: ENET2
        Input packets : 16
        Output packets: 87508
        Security: Zone: Trust
        Allowed host-inbound traffic : bootp bfd bgp dns dvmrp igmp ldp msdp nhrp
        ospf pgm pim rip router-discovery rsvp sap vrrp dhcp finger ftp tftp
        ident-reset http https ike netconf ping reverse-telnet reverse-ssh rlogin
        rpm rsh snmp snmp-trap ssh telnet traceroute xnm-clear-text xnm-ssl lsping
        ntp sip r2cp
        Protocol inet, MTU: 1500
          Flags: Sendbcast-pkt-to-re
            Destination: 10.1.100/24, Local: 10.1.100.1, Broadcast: 10.1.100.255
          Addresses, Flags: Is-Preferred Is-Primary
            Destination: 10.1.100/24, Local: 10.1.100.2, Broadcast: 10.1.100.255

      Logical interface ge-0/0/1.313 (Index 72) (SNMP ifIndex 562)
        Description: Wireless-LAN
        Flags: SNMP-Traps 0x0 VLAN-Tag [ 0x8100.313 ]  Encapsulation: ENET2
        Input packets : 16
        Output packets: 87022
        Security: Zone: Trust
        Allowed host-inbound traffic : bootp bfd bgp dns dvmrp igmp ldp msdp nhrp
        ospf pgm pim rip router-discovery rsvp sap vrrp dhcp finger ftp tftp
        ident-reset http https ike netconf ping reverse-telnet reverse-ssh rlogin
        rpm rsh snmp snmp-trap ssh telnet traceroute xnm-clear-text xnm-ssl lsping
        ntp sip r2cp
        Protocol inet, MTU: 1500
          Flags: Sendbcast-pkt-to-re
            Destination: 10.1.13/24, Local: 10.1.13.1, Broadcast: 10.1.13.255
          Addresses, Flags: Is-Preferred Is-Primary
            Destination: 10.1.13/24, Local: 10.1.13.2, Broadcast: 10.1.13.255

      Logical interface ge-0/0/1.314 (Index 73) (SNMP ifIndex 563)
        Description: PASS-LAN
        Flags: SNMP-Traps 0x0 VLAN-Tag [ 0x8100.314 ]  Encapsulation: ENET2
        Input packets : 15
        Output packets: 86974
        Security: Zone: Trust
        Allowed host-inbound traffic : bootp bfd bgp dns dvmrp igmp ldp msdp nhrp
        ospf pgm pim rip router-discovery rsvp sap vrrp dhcp finger ftp tftp
        ident-reset http https ike netconf ping reverse-telnet reverse-ssh rlogin
        rpm rsh snmp snmp-trap ssh telnet traceroute xnm-clear-text xnm-ssl lsping
        ntp sip r2cp
        Protocol inet, MTU: 1500
          Flags: Sendbcast-pkt-to-re
            Destination: 10.1.14/24, Local: 10.1.14.1, Broadcast: 10.1.14.255
          Addresses, Flags: Is-Preferred Is-Primary
            Destination: 10.1.14/24, Local: 10.1.14.2, Broadcast: 10.1.14.255

      Logical interface ge-0/0/1.32767 (Index 74) (SNMP ifIndex 564)
        Flags: SNMP-Traps 0x0 VLAN-Tag [ 0x0000.0 ]  Encapsulation: ENET2
        Input packets : 0
        Output packets: 0
        Security: Zone: Trust
        Allowed host-inbound traffic : bootp bfd bgp dns dvmrp igmp ldp msdp nhrp
        ospf pgm pim rip router-discovery rsvp sap vrrp dhcp finger ftp tftp
        ident-reset http https ike netconf ping reverse-telnet reverse-ssh rlogin
        rpm rsh snmp snmp-trap ssh telnet traceroute xnm-clear-text xnm-ssl lsping
        ntp sip r2cp

    mci@1479881-ENDCNY-VZB-RTR-1>
    ================================

    CISCO 6500 SupII - c6sup22-jk2sv-mz.121-22.E1.bin

    L3SW_6500#show run int fast 6/47
    Building configuration...

    Current configuration : 194 bytes
    !
    interface FastEthernet6/47
     description TRUNK to SRX-1 ge-0/0/1
     switchport
     switchport trunk encapsulation dot1q
     switchport trunk allowed vlan 1-9,11-4094
     spanning-tree portfast trunk
    end
    L2_L3_SW_6500#show vlan

    VLAN Name                             Status    Ports
    ---- -------------------------------- --------- -------------------------------
    1    default                          active    Fa6/29, Fa6/46, Fa6/47
    10   VLAN0010                         active    Fa6/1, Fa6/2
    100  VLAN0100                         active    Fa6/30
    313  VLAN0313                         active
    314  VLAN0314                         active
    1002 fddi-default                     act/unsup
    1003 token-ring-default               act/unsup
    1004 fddinet-default                  act/unsup
    1005 trnet-default                    act/unsup



  • 2.  RE: SRX240 ROS trunked to Cisco 6500
    Best Answer

    Posted 12-01-2012 00:38
    Hi,

    Check this out:

    interface FastEthernet6/47
    description TRUNK to SRX-1 ge-0/0/1
    switchport
    switchport trunk encapsulation dot1q
    switchport trunk allowed vlan 1-9,11-4094
    spanning-tree portfast trunk
    end
    L2_L3_SW_6500#show vlan
    VLAN Name Status Ports
    ---- -------------------------------- --------- -------------------------------
    1 default active Fa6/29, Fa6/46, Fa6/47
    10 VLAN0010 active Fa6/1, Fa6/2
    100 VLAN0100 active Fa6/30
    313 VLAN0313 active
    314 VLAN0314 active
    1002 fddi-default act/unsup
    1003 token-ring-default act/unsup
    1004 fddinet-default act/unsup
    1005 trnet-default act/unsup


    It seems 6/47 is still an access port and doesn't hence all the VLANs are not allowed on it. You can verify this using the 'show interface trunk' command.

    I think it'll work if you configure 'switchport mode trunk' on fe6/47.

    Cheers,
    Ankit


  • 3.  RE: SRX240 ROS trunked to Cisco 6500

    Posted 12-02-2012 22:09

    Hi,

     

    Agree with Ankit, the interface from Cisco side still access port. that's why it is showing in vlan 1

     

    1 default active Fa6/29, Fa6/46, Fa6/47

     

    No problem appears from Juniper SRX side

     

    Regards,

    Mohamed



  • 4.  RE: SRX240 ROS trunked to Cisco 6500

    Posted 12-03-2012 09:02

    Thank you both.  I had to add "switchport mode trunk" to the configuration to the interfaces of the 6500.  Thanks again for your quick response.