SRX Services Gateway
Highlighted
SRX Services Gateway

Maximum IP address on SRX Interface?

‎05-13-2014 03:39 AM

Hi Bro.

 

I wonder how many IP addresses a interface on SRX can support.How many IP can we configure for a interface?

5 REPLIES 5
Highlighted
SRX Services Gateway

Re: Maximum IP address on SRX Interface?

‎05-13-2014 04:16 AM

Hi Hoand,

 

  I just checked in lab on 

 

Model: srx100h2
JUNOS Software Release [12.1X44-D15.5]

 

I've added upto 300 IP addresses on a physical interface as below

 

[edit interfaces fe-0/0/1 unit 0 family inet]
root@srx100h2# show
address 1.1.1.1/24; <<<<
address 2.1.1.1/24; <<<<
address 3.1.1.1/24; <<<<

<sinp>

 

[edit interfaces fe-0/0/1 unit 0 family inet]
root@srx100h2# show | count
Count: 300 lines   <<<<

 

And I'm able to commit it so I don't see any limit up to 300 Ip address However, there is a limit on number of VLANs supported. You can refer the below branch SRX datasheet page number 8

 

http://www.juniper.net/us/en/local/pdf/datasheets/1000281-en.pdf

 

I hope this helps you!

 

Thanks,

SHKM

 

 

 

 

Highlighted
SRX Services Gateway

Re: Maximum IP address on SRX Interface?

‎05-14-2014 09:33 PM

Thanks for your help. Actually, in SSG product, we have this parameter

"Maximum Number of IP Addresses in Trusted Interfaces Unrestricted", but from SRX datasheet, I cannot find any equal parameter. Do you know about that ?

Highlighted
SRX Services Gateway

Re: Maximum IP address on SRX Interface?

‎05-14-2014 10:03 PM

Hi Hoand,

 

    I don't see any such IP limitation on SRX, at least there is no document stating that; however from the lab test we can add 300 IPs to physical interface but if you create number of VLANs and assign IP to each VLAN will hit number of VLANs per model limit.

 

Thanks,

SHKM

 

   

Highlighted
SRX Services Gateway

Re: Maximum IP address on SRX Interface?

‎05-15-2014 06:15 PM
"Maximum Number of IP Addresses in Trusted Interfaces Unrestricted"

 This parameter was once a popular licensing limitation with firewalls many years ago.  They would limit the number of host ip addresses that would be able to cross a firewall from the protected network.  Typically a 10 or 25 host license.  They kept track of the number of active ip addresses and then prevented access across the firewall when the count was full.  These devices then sold at a reduced price for very small branch offices.

 

Netsceen marketed their firewalls as unlimited ip address in order to contrast with this old licensing model and the language has just carried over as the years march on and it no longer has any relevance.  I don't think anyone in the firewall business still cripples the devices with host ip limits.

 

So to answer your question, the SRX is the same as the SSG for this parameter.  There are no limits to the number of hosts you can place behind the firewall.

 

 

Steve Puluka BSEET - Juniper Ambassador
IP Architect - DQE Communications Pittsburgh, PA (Metro Ethernet & ISP)
http://puluka.com/home
Highlighted
SRX Services Gateway

Re: Maximum IP address on SRX Interface?

‎05-16-2014 10:47 PM

Hoand, is this your requirement for your project, or you just asking for your knowledge?

 

adding 300 sub interface on one physical interface doesn't make any sense from design perspective.

 

I just want to tell you that if you are adding more sub interfaces on srx, make sure that you are bundling 2 interfaces (like port channel), this will give surety to bear load of vlans.