Descrizione della configurazione predefinita vSRX

I dispositivi IBM Cloud® Juniper vSRX vengono forniti con la seguente configurazione predefinita:

  • SSH e Ping sono consentiti su entrambi gli indirizzi IP gateway privato e pubblico vSRX
  • L'accesso all'IU di gestione web Juniper (J-Web) è consentito sulla porta HTTPS 8443 per entrambi gli indirizzi IP gateway privato e pubblico
  • Un indirizzo-set SERVICE è predefinito per le reti di servizi IBM
  • Vengono predefinite due zone di sicurezza: SL-PRIVATE e SL-PUBLIC.
  • L'accesso da parte dell' SL-PRIVATE e di zona a tutti i servizi è fornito da IBM e l'indirizzo impostato SERVICE è consentito
  • Tutti gli altri accessi alla rete vengono negati

Sono configurati due gruppi di ridondanza. La seguente tabella illustra questi gruppi di ridondanza:

Gruppi di ridondanza
Gruppo di ridondanza Funzione gruppo di ridondanza
redundancy-group 0 Gruppo di ridondanza per il piano di controllo
redundancy-group 1 Gruppo di ridondanza per il piano di dati

La priorità nel gruppo di ridondanza decide quale nodo vSRX è attivo. Per impostazione predefinita, il nodo 0 è attivo sia per il piano di controllo che di dati.

Configurazione predefinita di un gateway 1G SR - IOV pubblico e privato vSRX di esempio

I seguenti esempi di codice sono degli esempi dalla release di codice più recente.

## Last commit: 2020-04-28 00:32:27 UTC by root
version 18.4R1-S1.3;
system {
    login {
        class security {
            permissions [ security-control view-configuration ];
        }
        user admin {
            uid 2000;
            class super-user;
            authentication {
                encrypted-password "$6$5gPuIk9u$JPzyjh5zVz0tf4P3.POWv4UWGDfowbzirGmnpiBUW0tDWLf1ZfvP.YwN88Mc8.cyOIvgDMrksbCYsmZxf4f3p."; ## SECRET-DATA
            }
        }
    }
    root-authentication {
        encrypted-password "$6$q9tQzuqT$/TFQLkHK.woO.Qv9YcZ1nnJqZqhLBqXeg7L3xkUWXVmq8fn4N7mClTpckoCKhombXucxU6StRKOiHTDUeTdd91"; ## SECRET-DATA
    }
    services {
        ssh {
            root-login allow;
        }
        netconf {
            ssh {
                port 830;
            }
        }
        web-management {
            http {
                interface fxp0.0;
            }
            https {
                port 8443;
                system-generated-certificate;
                interface [ fxp0.0 ae0.0 ae1.0 ge-0/0/0.0 ge-0/0/1.0 ];
            }
            session {
                session-limit 100;
            }
        }
    }
    host-name asloma-swap-18-1g-sa0-vsrx-vSRX;
    name-server {
        10.0.80.11;
        10.0.80.12;
    }
    syslog {
        user * {
            any emergency;
        }
        file messages {
            any any;
            authorization info;
        }
        file interactive-commands {
            interactive-commands any;
        }
    }
    ntp {
        server 10.0.77.54;
    }
}
chassis {
    aggregated-devices {
        ethernet {
            device-count 10;
        }
    }
}
security {
    log {
        mode stream;
        report;
    }
    address-book {
        global {
            address SL8 10.1.192.0/20;
            address SL9 10.1.160.0/20;
            address SL4 10.2.128.0/20;
            address SL5 10.1.176.0/20;
            address SL6 10.1.64.0/19;
            address SL7 10.1.96.0/19;
            address SL1 10.0.64.0/19;
            address SL2 10.1.128.0/19;
            address SL3 10.0.86.0/24;
            address SL20 10.3.80.0/20;
            address SL18 10.2.176.0/20;
            address SL19 10.3.64.0/20;
            address SL16 10.2.144.0/20;
            address SL17 10.2.48.0/20;
            address SL14 10.1.208.0/20;
            address SL15 10.2.80.0/20;
            address SL12 10.2.112.0/20;
            address SL13 10.2.160.0/20;
            address SL10 10.2.32.0/20;
            address SL11 10.2.64.0/20;
            address SL_PRIV_MGMT 10.188.111.70/32;
            address SL_PUB_MGMT 169.60.101.121/32;
            address-set SERVICE {
                address SL8;
                address SL9;
                address SL4;
                address SL5;
                address SL6;
                address SL7;
                address SL1;
                address SL2;
                address SL3;
                address SL20;
                address SL18;
                address SL19;
                address SL16;
                address SL17;
                address SL14;
                address SL15;
                address SL12;
                address SL13;
                address SL10;
                address SL11;
            }
        }
    }
    screen {
        ids-option untrust-screen {
            icmp {
                ping-death;
            }
            ip {
                source-route-option;
                tear-drop;
            }
            tcp {
                syn-flood {
                    alarm-threshold 1024;
                    attack-threshold 200;
                    source-threshold 1024;
                    destination-threshold 2048;
                    queue-size 2000; ## Warning: 'queue-size' is deprecated
                    timeout 20;
                }
                land;
            }
        }
    }
    policies {
        from-zone SL-PRIVATE to-zone SL-PRIVATE {
            policy Allow_Management {
                match {
                    source-address any;
                    destination-address [ SL_PRIV_MGMT SERVICE ];
                    application any;
                }
                then {
                    permit;
                }
            }
        }
        from-zone SL-PUBLIC to-zone SL-PUBLIC {
            policy Allow_Management {
                match {
                    source-address any;
                    destination-address SL_PUB_MGMT;
                    application [ junos-ssh junos-https junos-http junos-icmp-ping ];
                }
                then {
                    permit;
                }
            }
        }
    }
    zones {
        security-zone SL-PRIVATE {
            interfaces {
                ae0.0 {
                    host-inbound-traffic {
                        system-services {
                            all;
                        }
                    }
                }
            }
        }
        security-zone SL-PUBLIC {
            interfaces {
                ae1.0 {
                    host-inbound-traffic {
                        system-services {
                            all;
                        }
                    }
                }
            }
        }
    }
}
interfaces {
    ge-0/0/0 {
        ether-options {
            802.3ad ae0;
        }
    }
    ge-0/0/1 {
        ether-options {
            802.3ad ae1;
        }
    }
    ge-0/0/2 {
        ether-options {
            802.3ad ae0;
        }
    }
    ge-0/0/3 {
        ether-options {
            802.3ad ae1;
        }
    }
    ae0 {
        description PRIVATE_VLANs;
        flexible-vlan-tagging;
        native-vlan-id 925;
        unit 0 {
            vlan-id 925;
            family inet {
                address 10.188.111.70/26;
            }
        }
    }
    ae1 {
        description PUBLIC_VLAN;
        flexible-vlan-tagging;
        native-vlan-id 985;
        unit 0 {
            vlan-id 985;
            family inet {
                address 169.60.101.121/28;
            }
            family inet6 {
                address 2607:f0d0:3901:0063:0000:0000:0000:000f/64;
            }
        }
    }
    fxp0 {
        unit 0;
    }
    lo0 {
        unit 0 {
            family inet {
                filter {
                    input PROTECT-IN;
                }
                address 127.0.0.1/32;
            }
        }
    }
}
firewall {
    filter PROTECT-IN {
        term PING {
            from {
                destination-address {
                    169.60.101.121/32;
                    10.188.111.70/32;
                }
                protocol icmp;
            }
            then accept;
        }
        term SSH {
            from {
                destination-address {
                    169.60.101.121/32;
                    10.188.111.70/32;
                }
                protocol tcp;
                destination-port ssh;
            }
            then accept;
        }
        term WEB {
            from {
                destination-address {
                    169.60.101.121/32;
                    10.188.111.70/32;
                }
                protocol tcp;
                port 8443;
            }
            then accept;
        }
        term DNS {
            from {
                protocol udp;
                source-port 53;
            }
            then accept;
        }
    }
}
routing-options {
    static {
        route 166.9.0.0/16 next-hop 10.188.111.65;
        route 0.0.0.0/0 next-hop 169.60.101.113;
        route 161.26.0.0/16 next-hop 10.188.111.65;
        route 10.0.0.0/8 next-hop 10.188.111.65;
    }
}

La seguente tabella illustra le definizioni dell'interfaccia di rete per la configurazione precedente:

Definizioni dell'interfaccia di rete
Nome interfaccia Funzione interfaccia
ge-0/0/0 Interfaccia Gbe (GigaBit ethernet) per la VLAN di transito SL-PRIVATE
ge-0/0/1 Interfaccia Gbe (GigaBit ethernet) per la VLAN di transito SL-PUBLIC
ge-0/0/2 Interfaccia Gbe (GigaBit ethernet) per la VLAN di transito SL-PRIVATE
ge-0/0/3 Interfaccia Gbe (GigaBit ethernet) per la VLAN di transito SL-PUBLIC
ae0.0 Interfaccia Ethernet aggregata
ae1.0 Interfaccia Ethernet aggregata
fxp0 Interfaccia di gestione
lo0 interfaccia loopback

Configurazione predefinita di un gateway 10G HA SR - IOV pubblico e privato vSRX di esempio

## Last commit: 2020-04-21 17:22:34 UTC by root
version 18.4R1-S1.3;
groups {
    node0 {
        system {
            host-name asloma-tc1b-18-10g-pubpriv-dual-ha1-vsrx-vSRX-Node0;
        }
    }
    node1 {
        system {
            host-name asloma-tc1b-18-10g-pubpriv-dual-ha1-vsrx-vSRX-Node1;
        }
    }
}
apply-groups "${node}";
system {
    login {
        class security {
            permissions [ security-control view-configuration ];
        }
        user admin {
            uid 2000;
            class super-user;
            authentication {
                encrypted-password "xxx"; ## SECRET-DATA
            }
        }
    }
    root-authentication {
        encrypted-password "xxx”;## SECRET-DATA
    }
    services {
        ssh {
            root-login allow;
        }
        netconf {
            ssh {
                port 830;
            }
        }
        web-management {
            http {
                interface fxp0.0;
            }
            https {
                port 8443;
                system-generated-certificate;
                interface [ fxp0.0 reth1.0 reth0.0 ];
            }
            session {
                session-limit 100;
            }
        }
    }
    name-server {
        10.0.80.11;
        10.0.80.12;
    }
    syslog {
        user * {
            any emergency;
        }
        file messages {
            any any;
            authorization info;
        }
        file interactive-commands {
            interactive-commands any;
        }
    }
    ntp {
        server 10.0.77.54;
    }
}
chassis {
    cluster {
        control-link-recovery;
        reth-count 4;
        heartbeat-interval 2000;
        heartbeat-threshold 8;
        redundancy-group 0 {
            node 0 priority 100;
            node 1 priority 1;
        }
        redundancy-group 1 {
            node 0 priority 100;
            node 1 priority 1;
            inactive: preempt;
            interface-monitor {
                ge-0/0/3 weight 130;
                ge-0/0/4 weight 130;
                ge-7/0/3 weight 130;
                ge-7/0/4 weight 130;
            }
        }
    }
}
security {
    log {
        mode stream;
        report;
    }
    address-book {
        global {
            address SL8 10.1.192.0/20;
            address SL9 10.1.160.0/20;
            address SL4 10.2.128.0/20;
            address SL5 10.1.176.0/20;
            address SL6 10.1.64.0/19;
            address SL7 10.1.96.0/19;
            address SL1 10.0.64.0/19;
            address SL2 10.1.128.0/19;
            address SL3 10.0.86.0/24;
            address SL20 10.3.80.0/20;
            address SL18 10.2.176.0/20;
            address SL19 10.3.64.0/20;
            address SL16 10.2.144.0/20;
            address SL17 10.2.48.0/20;
            address SL14 10.1.208.0/20;
            address SL15 10.2.80.0/20;
            address SL12 10.2.112.0/20;
            address SL13 10.2.160.0/20;
            address SL10 10.2.32.0/20;
            address SL11 10.2.64.0/20;
            address SL_PRIV_MGMT 10.87.40.36/32;
            address SL_PUB_MGMT 169.62.79.21/32;
            address-set SERVICE {
                address SL8;
                address SL9;
                address SL4;
                address SL5;
                address SL6;
                address SL7;
                address SL1;
                address SL2;
                address SL3;
                address SL20;
                address SL18;
                address SL19;
                address SL16;
                address SL17;
                address SL14;
                address SL15;
                address SL12;
                address SL13;
                address SL10;
                address SL11;
            }
        }
    }
    screen {
        ids-option untrust-screen {
            icmp {
                ping-death;
            }
            ip {
                source-route-option;
                tear-drop;
            }
            tcp {
                syn-flood {
                    alarm-threshold 1024;
                    attack-threshold 200;
                    source-threshold 1024;
                    destination-threshold 2048;
                    queue-size 2000; ## Warning: 'queue-size' is deprecated
                    timeout 20;
                }
                land;
            }
        }
    }
    policies {
        from-zone SL-PRIVATE to-zone SL-PRIVATE {
            policy Allow_Management {
                match {
                    source-address any;
                    destination-address [ SL_PRIV_MGMT SERVICE ];
                    application any;
                }
                then {
                    permit;
                }
            }
        }
        from-zone SL-PUBLIC to-zone SL-PUBLIC {
            policy Allow_Management {
                match {
                    source-address any;
                    destination-address SL_PUB_MGMT;
                    application [ junos-ssh junos-https junos-http junos-icmp-ping ];
                }
                then {
                    permit;
                }
            }
        }
    }
    zones {
        security-zone SL-PRIVATE {
            interfaces {
                reth0.0 {
                    host-inbound-traffic {
                        system-services {
                            all;
                        }
                    }
                }
            }
        }
        security-zone SL-PUBLIC {
            interfaces {
                reth1.0 {
                    host-inbound-traffic {
                        system-services {
                            all;
                        }
                    }
                }
            }
        }
    }
}
interfaces {
    ge-0/0/1 {
        gigether-options {
            redundant-parent reth0;
        }
    }
    ge-0/0/2 {
        gigether-options {
            redundant-parent reth0;
        }
    }
    ge-0/0/3 {
        gigether-options {
            redundant-parent reth1;
        }
    }
    ge-0/0/4 {
        gigether-options {
            redundant-parent reth1;
        }
    }
    ge-0/0/5 {
        gigether-options {
            redundant-parent reth2;
        }
    }
    ge-0/0/6 {
        gigether-options {
            redundant-parent reth2;
        }
    }
    ge-0/0/7 {
        gigether-options {
            redundant-parent reth3;
        }
    }
    ge-0/0/8 {
        gigether-options {
            redundant-parent reth3;
        }
    }
    ge-7/0/1 {
        gigether-options {
            redundant-parent reth0;
        }
    }
    ge-7/0/2 {
        gigether-options {
            redundant-parent reth0;
        }
    }
    ge-7/0/3 {
        gigether-options {
            redundant-parent reth1;
        }
    }
    ge-7/0/4 {
        gigether-options {
            redundant-parent reth1;
        }
    }
    ge-7/0/5 {
        gigether-options {
            redundant-parent reth2;
        }
    }
    ge-7/0/6 {
        gigether-options {
            redundant-parent reth2;
        }
    }
    ge-7/0/7 {
        gigether-options {
            redundant-parent reth3;
        }
    }
    ge-7/0/8 {
        gigether-options {
            redundant-parent reth3;
        }
    }
    fab0 {
        fabric-options {
            member-interfaces {
                ge-0/0/0;
                ge-0/0/9;
            }
        }
    }
    fab1 {
        fabric-options {
            member-interfaces {
                ge-7/0/0;
                ge-7/0/9;
            }
        }
    }
    lo0 {
        unit 0 {
            family inet {
                filter {
                    input PROTECT-IN;
                }
                address 127.0.0.1/32;
            }
        }
    }
    reth0 {
        redundant-ether-options {
            redundancy-group 1;
        }
        unit 0 {
            description "SL PRIVATE VLAN INTERFACE";
            family inet {
                address 10.87.40.36/26;
            }
        }
    }
    reth1 {
        redundant-ether-options {
            redundancy-group 1;
        }
        unit 0 {
            description "SL PUBLIC VLAN INTERFACE";
            family inet {
                address 169.62.79.21/29;
            }
            family inet6 {
                address 2607:f0d0:2901:002e:0000:0000:0000:0003/64;
            }
        }
    }
    reth2 {
        vlan-tagging;
        redundant-ether-options {
            redundancy-group 1;
        }
    }
    reth3 {
        vlan-tagging;
        redundant-ether-options {
            redundancy-group 1;
        }
    }
}
firewall {
    filter PROTECT-IN {
        term PING {
            from {
                destination-address {
                    169.62.79.21/32;
                    10.87.40.36/32;
                }
                protocol icmp;
            }
            then accept;
        }
        term SSH {
            from {
                destination-address {
                    169.62.79.21/32;
                    10.87.40.36/32;
                }
                protocol tcp;
                destination-port ssh;
            }
            then accept;
        }
        term WEB {
            from {
                destination-address {
                    169.62.79.21/32;
                    10.87.40.36/32;
                }
                protocol tcp;
                port 8443;
            }
            then accept;
        }
        term DNS {
            from {
                protocol udp;
                source-port 53;
            }
            then accept;
        }
    }
}
routing-options {
    static {
        route 166.9.0.0/16 next-hop 10.87.40.1;
        route 0.0.0.0/0 next-hop 169.62.79.17;
        route 161.26.0.0/16 next-hop 10.87.40.1;
        route 10.0.0.0/8 next-hop 10.87.40.1;
    }
}

Le informazioni nella tabella riportata di seguito rappresentano la configurazione precedente:

Informazioni di configurazione
Nome interfaccia Funzione interfaccia Interfaccia ridondante
ge-0/0/1 / ge-0/0/2 Interfaccia Ethernet Gigabit per SL - PRIVATE transit VLAN sul nodo 0 reth0
ge-0/0/3 / ge-0/0/4 Interfaccia Ethernet Gigabit per VLAN di transito SL - PUBLIC sul nodo 0 reth1
ge-0/0/5 / ge-0/0/6 Interfaccia Ethernet Gigabit per VLAN privata del cliente sul nodo 0 reth2
ge-0/0/7 / ge-0/0/8 Interfaccia Ethernet Gigabit per VLAN pubblica cliente sul nodo 0 reth3
ge-7/0/1 / ge-7/0/2 Interfaccia Ethernet Gigabit per SL - PRIVATE transit VLAN sul nodo 1 reth0
ge-7/0/3 / ge-7/0/4 Interfaccia Ethernet Gigabit per SL - PUBLIC transit VLAN sul nodo 1 reth1
ge-7/0/5 / ge-7/0/6 Interfaccia Ethernet Gigabit per le VLAN private del cliente sul nodo 1 reth2
ge-7/0/7 / ge-7/0/8 Interfaccia Ethernet Gigabit per VLAN pubbliche del cliente sul nodo 1 reth3
fab0 Il link fabric del cluster di chassis utilizza ge-0/0/0 e ge-0/0/9
fab1 Il link fabric del cluster di chassis utilizza ge-7/0/0 e ge-7/0/9
fxp0 Interfaccia di gestione
lo0 interfaccia loopback

Configurazioni dell'interfaccia

L'architettura legacy per queste configurazioni ha utilizzato il bridge Linux sull'hypervisor host Ubuntu. IBM è da allora passato a una nuova architettura per i suoi gateway che si avvalga di SR - IOV sull'host. Ciò ha causato la modifica dell'associazione dell'interfaccia della configurazione vSRX in molti casi. Le differenze nella configurazione dell'interfaccia sono influenzate anche dal fatto che vSRX sia:

  • 10G o 1G
  • Autonomo o HA (High Availability)
  • Pubblico e privato, o solo privato
  • La versione vSRX
    • Tutti i vSRX’s basati su 15.1 utilizzano l'architettura legacy
    • Anche alcuni vSRX’s basati su 18.4 utilizzano l'architettura legacy

Sia l'architettura legacy che quella corrente sono descritte nelle seguenti sezioni.

Interfacce vSRX High Availability (architettura corrente)

vSRX Interfacce ad alta disponibilità (architettura attuale)
Interfaccia 10G Pub + Priv 10G Solo Priv 1G Pub + Priv 1G Solo Priv
ge-0/0/0 fab0 fab0 fab0 fab0
ge-0/0/1 reth0 reth0 reth0 reth0
ge-0/0/2 reth0 reth0 reth0 reth0
ge-0/0/3 reth1 reth2 reth1 reth2
ge-0/0/4 reth1 reth2 reth1 reth2
ge-0/0/5 reth2 fab0 reth2 fab0
ge-0/0/6 reth2 non esiste reth2 non esiste
ge-0/0/7 reth3 non esiste reth3 non esiste
ge-0/0/8 reth3 non esiste reth3 non esiste
ge-0/0/9 fab0 non esiste fab0 non esiste
ge-7/0/0 fab1 fab1 fab1 fab1
ge-7/0/1 reth0 reth0 reth0 reth0
ge-7/0/2 reth0 reth0 reth0 reth0
ge-7/0/3 reth1 reth2 reth1 reth2
ge-7/0/4 reth1 reth2 reth1 reth2
ge-7/0/5 reth2 fab1 reth2 fab1
ge-7/0/6 reth2 non esiste reth2 non esiste
ge-7/0/7 reth3 non esiste reth3 non esiste
ge-7/0/8 reth3 non esiste reth3 non esiste
ge-7/0/9 fab1 non esiste fab1 non esiste

Interfacce autonome vSRX (architettura corrente)

vSRX interfacce indipendenti (architettura attuale)
Interfaccia 10G Pub + Priv 10G Solo Priv 1G Pub + Priv 1G Solo Priv
ge-0/0/0 ae0 ae0 ae0 ae0
ge-0/0/1 ae1 ae0 ae1 ae0
ge-0/0/2 ae0 non esiste ae0 non esiste
ge-0/0/3 ae1 non esiste ae1 non esiste

Interfacce vSRX High Availability (architettura legacy)

vSRX Interfacce ad alta disponibilità (architettura legacy)
Interfaccia 10G Priv + Pub 10G Solo Priv 1G Priv + Pub 1G Solo Priv
ge-0/0/0 fab0 fab0 fab0 fab0
ge-0/0/1 reth0 reth0 reth0 reth0
ge-0/0/2 reth0 reth0 reth2 reth2
ge-0/0/3 reth1 reth2 reth1 Non utilizzato
ge-0/0/4 reth1 reth2 reth3 Non utilizzato
ge-0/0/5 reth2 Non utilizzato non esiste non esiste
ge-0/0/6 reth2 Non utilizzato non esiste non esiste
ge-0/0/7 reth3 Non utilizzato non esiste non esiste
ge-0/0/8 reth3 Non utilizzato non esiste non esiste
ge-7/0/0 fab1 fab1 fab1 fab1
ge-7/0/1 reth0 reth0 reth0 reth0
ge-7/0/2 reth0 reth0 reth2 reth2
ge-7/0/3 reth1 reth2 reth1 Non utilizzato
ge-7/0/4 reth1 reth2 reth3 Non utilizzato
ge-7/0/5 reth2 Non utilizzato non esiste non esiste
ge-7/0/6 reth2 Non utilizzato non esiste non esiste
ge-7/0/7 reth3 Non utilizzato non esiste non esiste
ge-7/0/8 reth3 Non utilizzato non esiste non esiste

Interfacce autonome vSRX (architettura legacy)

vSRX interfacce indipendenti (architettura legacy)
Interfaccia 10G Pub + Priv 10G Solo Priv 1G Pub + Priv 1G Solo Priv
ge-0/0/0 ae0 ae0 ge-0/0/0 ge-0/0/0
ge-0/0/1 ae1 ae0 ge-0/0/1 non esiste
ge-0/0/2 ae0 non esiste non esiste non esiste
ge-0/0/3 ae1 non esiste non esiste non esiste