hello all,
i've just got my hands on a brand new shiny SRX340. all it's good for at the moment is a foot rest though, because i can't seem to be able to put basic configuration on it.
i have a load of 240s, which i use for VPN access from remote sites. one port is routed for internet access and the rest are switchports, which uses a vlan interface for routing.
i tried copying the config from a 240 to a 340 and the first thing i get in my vlan config is:
error: l3-interface: 'vlan.123': Only IRB interface is supported, e.g. irb.10
fine, i'll use an IRB interface:
# set security zones security-zone TRUST interfaces irb.123
error: interface-unit: 'irb.123': This interface cannot be configured in a zone
error: statement creation failed: irb.123
fine, i'll create a new zone with all the physical switchports defined and permit the new zone outbound.
'policy TRUST-UNTRUST'
from-zone (TRUST) and to-zone (UNTRUST) must be both L2 or L3 zones.
error: configuration check-out failed
i'm not a firewall admin by any means, so maybe i'm missing something very obvious, but it doesn't look as these things want to be gateway devices anymore?!