JNCIE-SEC-11.a - C10 - Extended ImplementationConcepts - Pps
JNCIE-SEC-11.a - C10 - Extended ImplementationConcepts - Pps
Concepts
2014 Juniper Networks, Inc. All rights reserved. | www.juniper.net | Worldwide Education Services
Objectives
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 2
Agenda: Extended Implementation
Concepts
Transparent Mode
Filter-Based Forwarding
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 3
What Is Transparent Mode?
End User
Device
Internal Router to
Switch Outside
End User
Device
Possible locations for
the SRX to be
installed
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 4
What Are the Rules?
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 5
Preparing a Device
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 6
Configuration Steps Review
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 7
Configure Interfaces
ACCESS TRUNK
[edit interfaces] [edit interfaces]
ge-0/0/1 { ge-0/0/1 {
unit 0 { unit 0 {
family bridge { family bridge {
interface-mode access; interface-mode trunk;
vlan-id 20; vlan-id-list 20;
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 8
Rewriting VLAN-ids
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 9
Create IRB Interface for mgmt
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 10
Create a Bridge-domain
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 11
Associate Interfaces with Zones
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 12
Options in Transparent Mode
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 13
Transparent Mode Verification
Basic commands
To view all of the active bridge domains defined:
>show bridge domain
To view MAC addresses learned from MAC discovery:
>show bridge mac-table
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 14
Issues and Tips
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 15
Agenda: Extended Implementation
Concepts
Transparent Mode
Filter-Based Forwarding
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 16
What Is Filter-Based Forwarding?
End User
Device
MPLS
Router
Web traffic
Security
Device
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 17
What Is Required? (1 of 2)
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 18
What Is Required? (2 of 2)
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 19
Filter-Based Forwarding Config (1 of 2)
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 20
Filter-Based Forwarding Config (2 of 2)
Firewall filter Applying filter
[edit firewall family inet] [edit interfaces ge-0/0/1]
filter Forward_Web { unit 0 {
term 1 { family inet {
from { filter {
source-address { input Forward_Web;
10.200.101.11/32; }
} address 10.200.101.254/24;
destination-port [ 80 443 ]; }
} }
then {
routing-instance FW;
}
}
term 2 {
then accept;
}
}
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 21
Summary
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 22
Extended Implementations Lab
2014 Juniper Networks, Inc. All rights reserved. Worldwide Education Services www.juniper.net | 23
Worldwide Education Services