01-08-2010 02:44 AM
What is the status of IPv6 support for SRX? Is is ready to do dual-stack or 6PE/VPE? Is it possible to use SRX as a gateway for DS-Lite environment with NAT? If so, what is the NAT performance for this device in your opinion.
Thanks for any suggestions,
01-20-2010 11:51 PM - edited 01-20-2010 11:51 PM
I was expecting 10.1 due to be released in february to have IPv6 for the larger SRX models - but it seems it wont :-(
I am feeling let down here, since test equipment like the SRX210H has this feature, only not flow based filtering - but it can forward IPv6 packets.
If you need IPv6 then don't buy the bigger SRX models, anything bigger than SRX210H, check with Juniper salespeople.
02-24-2010 11:03 PM
I have several srx-210's and I would not call the ipv6 support on those models complete or usable. I need to run dual stack on vlan interfaces. This is currently not supported, who cares if I can run ipv6 on a physical interface. I need to be able to run it on a vlan interface. This is a big issue!!
05-26-2010 02:16 PM
I agree, this is pretty sad to see Juniper pushing SRX to customers and partners, yet if you want IPV6 you're better off running the SSGs. At least there you can dual-stacked on a bgroup interface and it support security flow-based forwarding. Is it really asking too much to get the SRXs to have the same functionality as the SSGs?
05-28-2010 07:25 AM
IPv6 is packet-based only right now. It's a safe bet to say it won't stay that way, and will become flow-based.
To think of SRX as a one-to-one SSG replacement is an approach that will get you in hot water at this time. It's got some amazing strong points: Price/performance, JunOS, better CoS for VOIP applications, to name just a few. And just as many shortcomings: Dual ISP w/o dynamic routing, Dynamic VPN, interop VPNs w/ Cisco, the web UI, again to name just a few. All of which boils down to: Know which design you are placing SRX in, and whether it will be a good fit there. And really watch those quarterly JunOS releases, as features are being added all the time to bring SRX closer and closer to SSG feature parity.
05-30-2010 01:52 AM
In 10.2 flow-based IPv6 will be available. It will be released for the SRX devices < 650 around August. What I have seen and heard about 10.2 you also will be able to configure v4 and v6 on vlan interfaces.
06-01-2010 01:43 PM
I've tested 10.2R1.8 the non-public release for SRX branch on my SRX210H at home this weekend.
It works in flow mode too, I have several made several security policies.
Still can't get IPv6 to work in a dual stack vlan interface. If you put it on a physical interface, then change/commit the address to a vlan interface it works for a few minutes. When I sniff the network it seems the SRX is not answering to neighbor discovery even though I do allow that inbound on the interface (it's a new host-inbound-traffic protocol in 10.2).
Let's hope 10.2R2 is even better then we will get there finally.
06-17-2010 02:32 PM