Hi,
On production firewall we need to add a vlan on a LAN-interface, add it to new security zone and security policy.
In other words we need to add en extra lab-network and tagg it to the destination on existing LAN.
there are no l3 interfaces configured, the IPs are configured directly on the interface like this:
set interfaces fe-0/0/6 unit 0 family inet address 10.10.10.1/24
I've tried to add another l3 interface but cannot seem to get this to work!
This shouldn't be any problems to achieve but somehow this is a difficult topic in SRX.
I've tried the following:
set interfaces fe-0/0/6 vlan-tagging
set interfaces fe-0/0/6 unit 200 vlan-id 200
set interfaces fe-0/0/6 unit 200 family inet address 10.0.200.1/24
but when commiting it complains about not having vlan-id on unit 0
adding "set interfaces fe-0/0/6 unit 0 vlan-id 0" brakes the LAN-connectivity!!!
What to do?
Many thanks in advance,
regards, DB.