SRX220H2 running 12.3X48-D75.4
This is my first foray into configuring MPLS on any Juniper device.
I'm trying to get the route target import and export working. When I apply the import policy, I get the error in the subject line.
Policies look like this:
[edit policy-options]
root@MIRf1c1# show
policy-statement EXPORT-RT-POLICY {
from {
family route-target;
rtf-prefix-list EXPORT-RT;
}
then accept;
}
policy-statement IMPORT-RT-POLICY {
from {
family route-target;
rtf-prefix-list IMPORT-RT;
}
then accept;
}
rtf-prefix-list EXPORT-RT {
65001:1200:12/96;
}
rtf-prefix-list IMPORT-RT {
65001:1200:12/96;
65001:1300:12/96;
65001:500:12/96;
65001:501:12/96;
65001:600:12/96;
65001:601:12/96;
}
My VRF MAIN routing instance looks like this:
[edit routing-instances MAIN]
root@MIRf1c1# show
instance-type vrf;
interface lo0.12;
route-distinguisher 1200:12;
vrf-import IMPORT-RT-POLICY;
vrf-export EXPORT-RT-POLICY;
vrf-target target:1200:12;
protocols {
pim {
rp {
static {
address 192.168.200.252;
}
}
}
}
When I try to set a target without using the 65001 AS, I get the following:
[edit policy-options rtf-prefix-list IMPORT-RT]
root@MIRf1c1# set target:1200:12/96
error: prefix: 'target:1200:12/96': Use format 'as:x:y/len' where 'as' is an AS number and 'x' is an AS number followed by an option
al 'L' (To indicate 4 byte AS), or an IP address and 'y' is a number. e.g. 123456L:100 and len is a prefix length from 32 to 96 or 0
error: statement creation failed: target:1200:12/96
And when I try to commit my config, I get:
root@MIRf1c1# commit
error: MAIN: vrf-import policy permits accept action only if matching conditions contain a target community
error: configuration check-out failed
I was looking at https://www.juniper.net/documentation/en_US/junos/topics/example/vpn-bgp-route-target-filtering.html as an example, but in the example, it references vpn3-import and vpn3-export, but gives no example definition of either of those.
I know the export policy is formatted correctly, because I can remove the vrf-import statement and it commits.
Ideas on how to get past this hurdle?
Thanks,
Matt