Thank you for your replies. I did test both setting, but the firewall still shows:
Control link 0 name: fxp1
Control link status: Down
As I said, using a ProCurve it worked with the following settings:
vlan 1
name "DEFAULT_VLAN"
untagged 1-48
no ip address
exit
vlan 4094
name "VLAN4094"
tagged 1-2
exit
Meaning, the two control links (Port 1 + 2) are untagged in vlan-id 1 and transport vlan-tagged packets in vlan-id 4094.
The trunk mode:
ether-options {
no-flow-control;
}
unit 0 {
family ethernet-switching {
port-mode trunk;
vlan {
members FWcontrollLine;
}
}
}
did not work, even with the nativ-vlan-switch:
ether-options {
no-flow-control;
}
unit 0 {
family ethernet-switching {
port-mode trunk;
vlan {
members FWcontrollLine;
}
native-vlan-id 1;
}
}
and
unit 0 {
family ethernet-switching {
vlan {
members FWcontrollLine;
}
}
}
did not work.
When I look at the common set up on SRX or my J6350 devices I have to use the following settings to have a interface transport tagged packets:
vlan-tagging;
unit 0 {
vlan-id 4094;
}
For me, it seems like, the EX2200 discards any packets on the interfaces, that contain tagged packets.
Just to make one thing clear, as the docu of Juniper states, the control link is using vlan-id 4094 tagged packets to communicate. As far as I know, I can't change this bad and stiff behaviour, so the switches have to support it somehow. 😞
- Do I use the wrong firmware?
- Do I need a different license?