On 05/01/2015 04:50 PM, ML wrote: > I'm exploring the possibility of using the MS-MIC in an MX104 to > terminate route based VPNs. I'd be interested in hearing about > success/failure stories from people that have done this before I go to > the trouble of getting a demo unit.
So far it's working good, but I really miss documentation on the Juniper Website. It was more or less guesswork to get it going. And I'm missing most of the traceoptions I have available on SRX1-3k. > The plan is to terminate route based VPNs, placing the st0.X interfaces > in a VRF for use as a CE interface in our MPLS network. I plan to keep > traffic symmetric but I can't guarantee it will be as each end site > (Branch SRX) may have an IPsec VPN to up to 3 POPs. Will asymmetric > paths be a problem with MX + MS-MIC? Will the MS-MIC terminated IPsec > VPNs play nice in this scenario? You probably need to place the inside service-interface into the routing-instance or somethings alike. I don't see st0.x interfaces on my MX like I do on the SRX. Did you implement your scenario in the end? -dominik _______________________________________________ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp