Hello all. I am trying get a simple 2 device topology in EVE-NG up and running with 2 x VSRXs (evaluation version). I am new to Junos and new to EVE.
For some reason once I go into the CLI I don't see the ge interfaces (e.g. ge-0/0/1) until sometime after. Why is this? Should these not show up immediately once the devices are booted up? I have attached a pic showing the toplogy.
Eventually they do show and I am able to confirm this with show interfaces terse. I have configured IP addresses in unit 0 inet family on the relevant interfaces on both devices, but now I am unable to ping between devices. Are there any security settings I need to disable? I've included my config below. For conventince I have shown only info from one vSRX as both devices are configured the same, aside from IP addresses.
root> show version Model: vSRX Junos: 19.2R1.8
root> show chassis hardware Hardware inventory: Item Version Part number Serial number Description Chassis f0def23d5270 VSRX Midplane System IO Routing Engine VSRX-S FPC 0 FPC PIC 0 VSRX DPDK GE Power Supply 0
I have very limited knowledge about EVE-NG, but I think I can pinpoint your issue 🙂
Regarding the experience where your vSRX is booted but the ge- interfaces are missing until a bit later... that is per design with the seperate control plane and forwarding plane. The control-plane (routing engine) is booted first and then the forwarding plane is the initiated on your vSRX. This creates the delay.
To allow ping between your devices you should ensure that 'host-inbound-services system-services ping' is allowed in your security zone. Right now nothing is allowed inbound to your vSRX. For a lab you could go with 'all' instead' of 'ping' to allow all services.
Thanks for pointing me in the right direction. I've managed to get my lab going. For info this is the config I used.
cli-admin@my-junos> ...n security zones security-zone trust | display set set security zones security-zone trust tcp-rst set security zones security-zone trust host-inbound-traffic system-services all set security zones security-zone trust host-inbound-traffic protocols all set security zones security-zone trust interfaces ge-0/0/1.0 host-inbound-traffic system-services all set security zones security-zone trust interfaces ge-0/0/1.0 host-inbound-traffic protocols all