Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  NSRP query

    Posted 08-21-2009 13:55

    folks

     

    i know this is a silly question but here goes

     

    i have an ISG with 12 interfaces, trust, untrust, dmzs but i'm only monitoring the trust & untrust interfaces in nsrp

     

    now the silly question

     

    for true failover do i need to monitor all the live interfaces?

     

    thanks to anyone taking the time to reply or read this

     

    gratefully appreciated

     

     



  • 2.  RE: NSRP query
    Best Answer

    Posted 08-21-2009 14:39

     

    No .

     

    In an NSRP Active/Passive configuration, device failover can be triggered by monitoring at least one of three objects--interface, track-ip address, and zone. 
    For example , if firewall is set to monitor an interface , once FW hit to the threshold for that particular interface , it will failover.
    So failover can be done with the help of any single object or with the combination of the object. It all depends upon your network requirement.
     For the purpose of troubleshooting, this KB article describes how to trigger a failover of an NSRP device when monitoring each object.

     

    http://kb.juniper.net/KB11192

     

     

    Thanks

    Atif

    If this worked for you please flag my post as an "Accepted Solution" so others can benefit. A kudo would be cool if you think I earned it.

     



  • 3.  RE: NSRP query

    Posted 08-21-2009 17:20

    many thanks for your reply my friend

     

    i've added kudos!