Security

last person joined: yesterday 

Ask questions and share experiences with Juniper Connected Security. Discuss Advanced Threat Protection, SecIntel, Secure Analytics, Secure Connect, Security Director, and all things related to Juniper security technologies.
  • 1.  nsmXpress 2010.2 haSvr.cfg

    Posted 07-01-2011 22:38

    hi, i'm trying to set up simple HA between 2x nsmxpress. i've tried configuring via nsm web and cli but to no luck.  I noticed that the when i do a /usr/netscreen/HaSvr/utils/haStatus, this is what i get

     

    Local Server:
      10.10.10.6    running    network-up    db-repl:dirty

      Peer Server:
      ""    timed-out(error)    network-down    db-repl:dirty

     

    I get a blank peer server settings.  after tinkering with the haSvr.cfg, i found out that when i put an IP on the highAvail.heartbeatClientIp.1 , that is the only time an IP address appears as a Peer Server.  accdg to some KB, i dont have to put a value on highAvail.heartbeatClientIp.1 since i'm only using 1 heartbeat link.  what am i missing here?

     

    my haSvr.cfg file snip

     

    highAvail.isPrimaryServer                     y
    highAvail.primaryServerIp                     10.10.10.6
    highAvail.secondaryServerIp                   x.x.x.250
    highAvail.remoteHaReplicationIp               x.x.x.250
    highAvail.numOfHeartbeatLinks                 1
    highAvail.heartbeatServerIp.0                 20.20.20.6
    highAvail.heartbeatClientIp.0                 x.x.x.13
    highAvail.heartbeatServerIp.1                 ""
    highAvail.heartbeatClientIp.1                 ""
    highAvail.heartbeatPort                       7802
    highAvail.heartbeatInterval                   15
    highAvail.timeoutHeartbeats                   4
    highAvail.mountSource                         ""
    highAvail.mountOptions                        ""
    highAvail.sharedDiskFS                        ""
    highAvail.pathSharedDir                       ""
    highAvail.cmdFsck                             ""
    highAvail.pingableIp                          x.x.x.13

     

    note: the nsmexpress is connected to an SRX using static nat.  x.x.x.250 => 10.10.10.6   x.x.x.13 => 20.20.20.6



  • 2.  RE: nsmXpress 2010.2 haSvr.cfg
    Best Answer

    Posted 07-02-2011 00:40
    Ok i got it! The configs are correct. It was a policy in srx that was causing the the peering to fail. Once deactivated the peering went up.