Security

last person joined: 8 days ago 

Ask questions and share experiences with Juniper Connected Security. Discuss Advanced Threat Protection, SecIntel, Secure Analytics, Secure Connect, Security Director, and all things related to Juniper security technologies.
  • 1.  Unable to change VLAN member on ex3200

    Posted 08-05-2016 10:06
      |   view attached

    2 Vlans set up, default and a manually created.  While both GUI and CLI do not give any errors when changing ID (ore trying to remove associated ports) and seemingly commit without fault, nothing actually changes.  I'm stumped here.  Basically just want to remove Horizons VLAN and add all associated ports back to default.  Any advice is greatly appreciated.

     

     



  • 2.  RE: Unable to change VLAN member on ex3200

    Posted 08-05-2016 11:14

    how does your configuration looks like?

     

    basically I would expect that you should do the following for all relevant interfaces (in configuration mode):

    delete interfaces ge-0/0/33.0 family ethernet-switching vlan member horizon
    set interfaces ge-0/0/33.0 family ethernet-switching vlan member default
    commit

    Please try this and revert with the result (and your config if it still doesn't work)

     



  • 3.  RE: Unable to change VLAN member on ex3200

    Posted 08-05-2016 11:34
      |   view attached

    Thanks so much for your response.

     

    When i try the first command to delete, i get a warning: element not found (error attached)

     

    Config:

    root@fsd-cl-sw1> show configuration | except SECRET-DATA

    ## Last commit: 2014-12-26 18:55:09 UTC by root
    version 11.3R2.4;
    system {
    host-name fsd-cl-sw1;
    root-authentication {
    }
    services {
    ssh {
    root-login allow;
    protocol-version v2;
    }
    web-management {
    http;
    }
    }
    syslog {
    user * {
    any emergency;
    }
    host 10.2.4.156 {
    any warning;
    }
    file messages {
    any notice;
    authorization info;
    }
    file interactive-commands {
    interactive-commands any;
    }
    }
    ntp {
    server 10.2.4.70;
    server 10.1.4.70;
    }
    }
    chassis {
    alarm {
    management-ethernet {
    link-down ignore;
    }
    }
    }
    interfaces {
    interface-range CL {
    member-range ge-0/0/0 to ge-0/0/31;
    unit 0 {
    family ethernet-switching {
    vlan {
    members default;
    }
    }
    }
    }
    interface-range Horizon {
    member-range ge-0/0/32 to ge-0/0/47;
    unit 0 {
    family ethernet-switching {
    vlan {
    members Horizon;
    }
    }
    }
    }
    ge-0/0/0 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/1 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/2 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/3 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/4 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/5 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/6 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/7 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/8 {
    ether-options {
    auto-negotiation;
    flow-control;
    link-mode automatic;
    speed {
    10m;
    }
    }
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/9 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/10 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/11 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/12 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/13 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/14 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/15 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/16 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/17 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/18 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/19 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/20 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/21 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/22 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/23 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/24 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/25 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/26 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/27 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/28 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/29 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/30 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/31 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/0/32 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/33 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/34 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/35 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/36 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/37 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/38 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/39 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/40 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/41 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/42 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/43 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/44 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/45 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/46 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/0/47 {
    unit 0 {
    family ethernet-switching {
    port-mode access;
    }
    }
    }
    ge-0/1/0 {
    unit 0 {
    family ethernet-switching;
    }
    }
    xe-0/1/0 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/1/1 {
    unit 0 {
    family ethernet-switching;
    }
    }
    xe-0/1/1 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/1/2 {
    unit 0 {
    family ethernet-switching;
    }
    }
    ge-0/1/3 {
    unit 0 {
    family ethernet-switching;
    }
    }
    me0 {
    unit 0 {
    family inet;
    }
    }
    vlan {
    unit 0 {
    family inet {
    address 10.2.42.2/24;
    }
    }
    }
    }
    snmp {
    community chenega0ps {
    authorization read-only;
    }
    community Test {
    authorization read-only;
    }
    }
    routing-options {
    static {
    route 0.0.0.0/0 {
    next-hop 10.2.42.1;
    retain;
    }
    route 10.3.0.0/16 next-hop 10.2.4.204;
    }
    }
    protocols {
    igmp-snooping {
    vlan all;
    }
    rstp;
    lldp {
    interface all;
    }
    lldp-med {
    interface all;
    }
    }
    ethernet-switching-options {
    voip;
    storm-control {
    interface all;
    }
    }
    vlans {
    Horizon;
    default {
    l3-interface vlan.0;
    }
    }
    poe {
    interface all;
    }



  • 4.  RE: Unable to change VLAN member on ex3200
    Best Answer

    Posted 08-05-2016 11:45

    It's due to your interface ranges:

     

    interface-range CL {
    member-range ge-0/0/0 to ge-0/0/31;
    unit 0 {
    family ethernet-switching {
    vlan {
    members default;
    }
    }
    }
    }
    interface-range Horizon {
    member-range ge-0/0/32 to ge-0/0/47;
    unit 0 {
    family ethernet-switching {
    vlan {
    members Horizon;
    }
    }
    }
    }

    Either change you 'Horizon' range to vlan members default or delete the entire interface-range horizon and add the range to interface-range CL.



  • 5.  RE: Unable to change VLAN member on ex3200

    Posted 08-05-2016 12:37

    I thank you sincerely good sir, that did the trick!!