Good afternoon lpaniagua!
-
Please confirm if your topology currently looks like the following one (a cable connected from ge-0/0/4 directly to ge-0/0/5) or if you have modified it:
.2 192.168.2/24 .1
VR1-(ge-0/0/4)----------------------(ge-0/0/5)-VR2
VR1Zone VR2Zone
Answer: Yes, I have a cable connected from port ge-0/0/4 to port ge-0/0/5
2. Please also share:
root@NewJuniper> show route
inet.0: 3 destinations, 3 routes (3 active, 0 holddown, 0 hidden)
+ = Active Route, - = Last Active, * = Both
192.168.1.1/32 *[Local/0] 00:04:45
Reject
192.168.4.1/32 *[Local/0] 00:04:45
Reject
192.168.7.1/32 *[Local/0] 00:04:16
Reject
VRBOXExample.inet.0: 2 destinations, 2 routes (2 active, 0 holddown, 0 hidden)
+ = Active Route, - = Last Active, * = Both
192.168.2.0/24 *[Direct/0] 00:04:10
> via ge-0/0/4.0
192.168.2.2/32 *[Local/0] 00:04:16
Local via ge-0/0/4.0
VRPrincipal.inet.0: 2 destinations, 2 routes (2 active, 0 holddown, 0 hidden)
+ = Active Route, - = Last Active, * = Both
192.168.2.0/24 *[Direct/0] 00:04:10
> via ge-0/0/5.0
192.168.2.1/32 *[Local/0] 00:04:16
Local via ge-0/0/5.0
root@NewJuniper# show security zones security zones security-zone VR1Zone | display set
set security zones security-zone VRPrincipalZone interfaces ge-0/0/5.0
[edit]
root@NewJuniper# show security zones security-zone VR2Zone | display set
set security zones security-zone VRBOXExampleZone interfaces ge-0/0/4.0
[edit]
3. Please also apply the following counters on both interfaces to confirm if the ping packets are being received/sent.
Answer: I put the commands you wrote.
4. After commiting the above configuraiton try the following ping:
root@NewJuniper# run ping 192.168.2.1 routing-instance VR1 count 5
PING 192.168.2.1 (192.168.2.1): 56 data bytes
64 bytes from 192.168.2.1: icmp_seq=0 ttl=64 time=0.328 ms
64 bytes from 192.168.2.1: icmp_seq=1 ttl=64 time=0.106 ms
64 bytes from 192.168.2.1: icmp_seq=2 ttl=64 time=0.239 ms
64 bytes from 192.168.2.1: icmp_seq=3 ttl=64 time=0.094 ms
64 bytes from 192.168.2.1: icmp_seq=4 ttl=64 time=0.113 ms
--- 192.168.2.1 ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max/stddev = 0.094/0.176/0.328/0.092 ms
[edit]
5. And after that, gather the following command:
root@NewJuniper# show firewall
filter GE4-COUNTER {
term GE4-OUT {
from {
source-address {
192.168.2.2/32;
}
destination-address {
192.168.2.1/32;
}
protocol icmp;
}
then {
count GE4-OUT;
accept;
}
}
term GE4-IN {
from {
source-address {
192.168.2.1/32;
}
destination-address {
192.168.2.2/32;
}
protocol icmp;
}
then {
count GE4-IN;
accept;
}
}
term ALLOW-ELSE {
then accept;
}
}
filter GE5-COUNTER {
term GE5-OUT {
from {
source-address {
192.168.2.1/32;
}
destination-address {
192.168.2.2/32;
}
protocol icmp;
}
then {
count GE5-OUT;
accept;
}
}
term GE5-IN {
from {
source-address {
192.168.2.2/32;
}
destination-address {
192.168.2.1/32;
}
protocol icmp;
}
then {
count GE5-IN;
accept;
}
}
term ALLOW-ELSE {
then accept;
}
}
[edit]
Thank you very much for your involvement helping other people, the truth that is nice to see that there are still people like this in this world, thank you again and if you need anything else, do not hesitate to ask me, greetings.