SRX

last person joined: 2 days ago 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  SRX 220h2 Chassis Cluster issue

    Posted 10-12-2015 22:06
      |   view attached

    Hi,

     

    I've setup two SRX 220H2 devices as per KB21312.

     

    I'm getting intermittent connection issues to interface reth1. It only seems to occur after connecting to services (SSH) via either of the fpx0 interfaces on Node0 or Node1.

     

    For example, after powering on both SSG devices I can ping all interfaces, from PC with IP 10.50.84.100, ok. That is, I can ping fxp0 interfaces on both Nodes (10.50.84.63 & 10.50.84.64) & the reth1 interface (10.50.84.20). But if I access the SSH service via fxp0 interface on Node0 (10.50.84.63) I can no longer ping reth1 (10.50.84.20) from the PC.

     

    Additionally. SSH sessions drop-out intermittently. That is, I'm able to connect to the SSH service, via Reth1, using Putty but the connection disconnects after 10 or so seconds.

     

    I have a feeling it is related to asymmetrical routing but unsure how to fix. The only work around is to restart the devices and NOT access SSH via the fxp0 interfaces.

     

    Physical setup:
    Interfaces ge-0/0/0 & ge-3/0/0 (Reth0) are connected to a Cisco (internet designated) switch, VLAN ID 1
    Interfaces ge-0/0/1, ge-3/0/1 (Reth1) & ge-0/0/6, ge-3/0/6 (fxp0) are all connected to the same HP (internal designated) switch, VLAN ID 2.
    Interfaces ge-0/0/5, ge-3/0/5 connected with straight thru cable
    Interfaces ge-0/0/7, ge-3/0/7 connected with straight thru cable
    STP is not enabled on the network.

     

    I've attached configuration.

     

    Any assistance very much appreciated.

     

    Regards,

    Andrew

    Attachment(s)

    txt
    Cluster_Config.txt   6 KB 1 version


  • 2.  RE: SRX 220h2 Chassis Cluster issue
    Best Answer

    Posted 10-13-2015 01:19

    Hi,

     

    Your FXP subnet (10.50.84.0/24) containing IPs 10.50.84.63/24 and 10.50.84.64/24) is in the same subnet as your reth1 interface 10.50.84.20/24.

    These interfaces are designed to be Out of Band and not mixed with the production network. I think they way they operate is not truely Out of Band as they are visible in the inet.0 routing instance. 

     

    Anyway, I would move these FXP interfaces to another subnet and keep them away from the production network.  A method I use is to create a second routing instance for production traffic, keeping inet.0 only for OOB management.



  • 3.  RE: SRX 220h2 Chassis Cluster issue

    Posted 10-13-2015 15:26

    Thanks for the assiatnce Martin.

     

    As suggested, I'll move the fxp assigned interfaces to another subnet.

     

    Regards,

    Andrew