Screen OS

last person joined: 7 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  Redundant statix Route

    Posted 04-07-2014 05:26

    Dear Folks

     

    We run two ssg140 in HA Mode in Hamburg  with 2 external links.

     

    Last week our Provider installed a new Router in the Trust Zone building a new connection to Frankfurt Office using MPLS.

     

    What i wanne do is once the MPLS Link goes down ( IP in FFM is not reachable) a Backuplink to Frankfurt usind an IPSEC Tunnel (usind the working Internetconnection)should come up automaticly . I saw the Track IP feature only on an interface Basis 

     

     

    How can I track  whether the IP in Frankfurt is reachable and then bring up the IPSec Backup ?

     

    thx for your support

     

     

     



  • 2.  RE: Redundant statix Route

    Posted 04-07-2014 12:00
    Try this forum, they should be quicker to find solution. If you get resolution, close this with resolved and the solution also.
    http://forums.juniper.net/t5/ScreenOS-Firewalls-NOT-SRX/bd-p/Firewalls


  • 3.  RE: Redundant statix Route

    Posted 04-08-2014 18:37

    I would setup the following:

     

    Create a static route at the normal 20 preference towards the MPLS router interface

     

    Use the track ip on the interface connecting to the MPLS router for the remote ip address. This will bring down this interface and the route will withdraw when this happens.

     

    Create a route based vpn as the backup and allow that tunnel to remain up.

     

    Create the second static route with the higher preference pointed towards this vpn interface.  This route will not be active unless the primary route withdraws.

     

    If you are using OSPF or BGP you can also setup this same type of arrangement using routing preference within the protocol.  Then the routes will withdraw without track-ip because the neighbors will go down as the link fails.



  • 4.  RE: Redundant statix Route
    Best Answer

    Posted 04-11-2014 08:28

    thx for your reply

     

    i will  check this solution during the weekend

     

     

     

    if the  Interface is in a BGroup . Does the trackip shutdown the bgroup or actual interface ?

     

     



  • 5.  RE: Redundant statix Route

    Posted 04-15-2014 08:13

    Thx for your support

     

     

    I works exacly the way you told me . The failover works even if some of the MPLS Routers between us and the final destination failes

     

     

    good work