Routing
Reply
Trusted Contributor
acecanal
Posts: 149
Registered: ‎07-05-2011
0

Re: vrrp

For sure.

 

VRRP is not a routable protocol, and is not the IP protocol so a "ip any any" rule will not allow VRRP, this is the VRRP protocol and should be allowed.

 

Your fw should be configured in transparent mode, never in routing mode. Should even allow pass through STP traffic or any other Layer2 protocol, like ARP. If not VRRP will not pass through your FW, because VRRP packets cant be routed.

 

This is why you got both routers as master. Because the FW block any vrrp traffic.

 

 

 

Br
Alex

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

If you want to say thanks, the word is Kudos!!.

Thx.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

JNCIA-JUNOS, JNCIS-ENT, JNCIS-SP, JNCIP-SP.
CCNA, CCNP, Written CCIE.
Contributor
alex14
Posts: 12
Registered: ‎04-10-2012
0

Re: vrrp

it was in transparent mode.

 

after looking through the different options on the firewall, my guess was either our junipers arent configured 100% properly or the fortinet fortigate firewall just wasnt 100% compatible with the juniper m7i routers.

Trusted Contributor
acecanal
Posts: 149
Registered: ‎07-05-2011
0

Re: vrrp

 

The only compatiblity issue you may have, is that firewall didnt reconize some protocols, and could not configure this to be allowed by the fw. But vrrp is a standard protocol, could not have issues with this.

Anyway, try to configure a ip any any, arp any any, icmp any any, vrrp any any rules, then both router should work properly, you have to be able to telnet, ping from both routers to each other, and vrrp should work. If not, firewall is not transparent.

Br
Alex

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

If you want to say thanks, the word is Kudos!!.

Thx.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

JNCIA-JUNOS, JNCIS-ENT, JNCIS-SP, JNCIP-SP.
CCNA, CCNP, Written CCIE.
Contributor
alex14
Posts: 12
Registered: ‎04-10-2012
0

Re: vrrp

i did a all any to any so that should include everything.

 

i was able to ping from each.

 

i give up on the fortigates. we had it only for eval and their support was no help.

 

thanks for your help.

Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.