Hello David,

yes, this is the objective. I would like to use a vSRX to act as a router/firewall to a physical lan. This is working to a LAN with no valid IP (because in this case we have SNAT) and the physical gateway knows how to forward the traffic.


Do you know what is feature in the CSO that allows me to achieve this? There is "enhanced" version of the vRouter in CSO ?


Regards,


Cleofas R. Schaden
WZTECH Networks
[email protected]

Em 05/03/2017 10:55, David bass escreveu:
Are you trying to use this vSRX as a router/firewall for a physical LAN?  Where 
the vSRX will be the gateway for devices other than the virtual servers on that 
physical host (assuming there are other virtual servers on the same physical 
host that the vSRX is on).

If you're trying to do that within Contrail, then you are right it won't work.  
Juniper has another product called CSO that is more designed to do what you're 
looking to do. It's not free or open source...


On Mar 2, 2017, at 1:04 PM, Cleofas R Schaden <[email protected]> wrote:

Hello,

in my scenario, the network is associated with a interface of vSRX and this 
interface have a valid IP address. In a normal environment I will use a routing 
protocol to advertise this CIDR to network,  this is what I'm trying to figure 
out.

My scenario: vSRX with 3 interface MGT (192.168.44.0/24) ge-0/0/0 
(189.39.11.1/24) ge-0/0/1 (189.39.12.1/24).


I'm not seeing a way to get this working with route aggregate, because the 
route aggregation will work only until the last router that did the route 
aggregation, this router will not have in this forwarding table a valid 
next-hop to IP address 189.39.12.2 for example.


Regards,



Cleofas R. Schaden
WZTECH Networks
[email protected]

Em 02/03/2017 11:56, David bass escreveu:
Why would you want to advertise the entire /24, and not the specific routes for 
instances that are actually on that physical hosts?

You would want to aggregate the route at a higher level.

On Mar 2, 2017, at 8:50 AM, Cleofas R Schaden <[email protected]> wrote:

Hello all,



There is a way to vRouter advertise the whole CIDR (/24 for example) to 
physical gatewat and not the specific /32 that is correlated to a instance?

Example: When I create a network the CIDR allocated is 192.168.100.0/24. But 
the addresses advertised to the physical gateway is only the addresses from 
instances that are running.

Regards,




--
Cleofas R. Schaden
WZTECH Networks
[email protected]


_______________________________________________
Dev mailing list
[email protected]
http://lists.opencontrail.org/mailman/listinfo/dev_lists.opencontrail.org


_______________________________________________
Dev mailing list
[email protected]
http://lists.opencontrail.org/mailman/listinfo/dev_lists.opencontrail.org

Reply via email to