vSRX 기본 구성 이해
IBM Cloud® Juniper vSRX 디바이스는 다음 기본 구성으로 제공됩니다.
- SSH 및 Ping은 vSRX 공용 및 사설 게이트웨이 IP 주소에 허용됩니다.
- Juniper Web Management(J-Web) UI 액세스는 공용 및 사설 게이트웨이 IP 주소의 HTTPS 포트 8443에 허용됩니다.
- 주소 세트
SERVICE는 IBM 서비스 네트워크에 대해 사전 정의됩니다. SL-PRIVATE및SL-PUBLIC의 두 보안 구역이 사전 정의됩니다.SL-PRIVATE구역에서 모든 서비스까지의 액세스가 IBM에서 제공되고 주소 세트SERVICE가 허용됩니다.- 기타 모든 네트워크 액세스가 거부됩니다.
두 개의 중복성 그룹이 구성됩니다. 다음 표에서는 이 중복성 그룹에 대해 설명합니다.
| 중복성 그룹 | 중복성 그룹 기능 |
|---|---|
| redundancy-group 0 | 제어 플레인을 위한 중복성 그룹 |
| redundancy-group 1 | 데이터 플레인을 위한 중복성 그룹 |
중복성 그룹의 우선순위는 활성 상태인 vSRX 노드를 결정합니다. 기본적으로 노드 0은 제어 플레인 및 데이터 플레인 모두에 대해 활성 상태입니다.
샘플 1G 독립형 SR-IOV 공용 및 사설 vSRX Gateway의 기본 구성
다음 코드 샘플은 최신 코드 릴리스에서 제공되는 예입니다.
## Last commit: 2020-04-28 00:32:27 UTC by root
version 18.4R1-S1.3;
system {
login {
class security {
permissions [ security-control view-configuration ];
}
user admin {
uid 2000;
class super-user;
authentication {
encrypted-password "$6$5gPuIk9u$JPzyjh5zVz0tf4P3.POWv4UWGDfowbzirGmnpiBUW0tDWLf1ZfvP.YwN88Mc8.cyOIvgDMrksbCYsmZxf4f3p."; ## SECRET-DATA
}
}
}
root-authentication {
encrypted-password "$6$q9tQzuqT$/TFQLkHK.woO.Qv9YcZ1nnJqZqhLBqXeg7L3xkUWXVmq8fn4N7mClTpckoCKhombXucxU6StRKOiHTDUeTdd91"; ## SECRET-DATA
}
services {
ssh {
root-login allow;
}
netconf {
ssh {
port 830;
}
}
web-management {
http {
interface fxp0.0;
}
https {
port 8443;
system-generated-certificate;
interface [ fxp0.0 ae0.0 ae1.0 ge-0/0/0.0 ge-0/0/1.0 ];
}
session {
session-limit 100;
}
}
}
host-name asloma-swap-18-1g-sa0-vsrx-vSRX;
name-server {
10.0.80.11;
10.0.80.12;
}
syslog {
user * {
any emergency;
}
file messages {
any any;
authorization info;
}
file interactive-commands {
interactive-commands any;
}
}
ntp {
server 10.0.77.54;
}
}
chassis {
aggregated-devices {
ethernet {
device-count 10;
}
}
}
security {
log {
mode stream;
report;
}
address-book {
global {
address SL8 10.1.192.0/20;
address SL9 10.1.160.0/20;
address SL4 10.2.128.0/20;
address SL5 10.1.176.0/20;
address SL6 10.1.64.0/19;
address SL7 10.1.96.0/19;
address SL1 10.0.64.0/19;
address SL2 10.1.128.0/19;
address SL3 10.0.86.0/24;
address SL20 10.3.80.0/20;
address SL18 10.2.176.0/20;
address SL19 10.3.64.0/20;
address SL16 10.2.144.0/20;
address SL17 10.2.48.0/20;
address SL14 10.1.208.0/20;
address SL15 10.2.80.0/20;
address SL12 10.2.112.0/20;
address SL13 10.2.160.0/20;
address SL10 10.2.32.0/20;
address SL11 10.2.64.0/20;
address SL_PRIV_MGMT 10.188.111.70/32;
address SL_PUB_MGMT 169.60.101.121/32;
address-set SERVICE {
address SL8;
address SL9;
address SL4;
address SL5;
address SL6;
address SL7;
address SL1;
address SL2;
address SL3;
address SL20;
address SL18;
address SL19;
address SL16;
address SL17;
address SL14;
address SL15;
address SL12;
address SL13;
address SL10;
address SL11;
}
}
}
screen {
ids-option untrust-screen {
icmp {
ping-death;
}
ip {
source-route-option;
tear-drop;
}
tcp {
syn-flood {
alarm-threshold 1024;
attack-threshold 200;
source-threshold 1024;
destination-threshold 2048;
queue-size 2000; ## Warning: 'queue-size' is deprecated
timeout 20;
}
land;
}
}
}
policies {
from-zone SL-PRIVATE to-zone SL-PRIVATE {
policy Allow_Management {
match {
source-address any;
destination-address [ SL_PRIV_MGMT SERVICE ];
application any;
}
then {
permit;
}
}
}
from-zone SL-PUBLIC to-zone SL-PUBLIC {
policy Allow_Management {
match {
source-address any;
destination-address SL_PUB_MGMT;
application [ junos-ssh junos-https junos-http junos-icmp-ping ];
}
then {
permit;
}
}
}
}
zones {
security-zone SL-PRIVATE {
interfaces {
ae0.0 {
host-inbound-traffic {
system-services {
all;
}
}
}
}
}
security-zone SL-PUBLIC {
interfaces {
ae1.0 {
host-inbound-traffic {
system-services {
all;
}
}
}
}
}
}
}
interfaces {
ge-0/0/0 {
ether-options {
802.3ad ae0;
}
}
ge-0/0/1 {
ether-options {
802.3ad ae1;
}
}
ge-0/0/2 {
ether-options {
802.3ad ae0;
}
}
ge-0/0/3 {
ether-options {
802.3ad ae1;
}
}
ae0 {
description PRIVATE_VLANs;
flexible-vlan-tagging;
native-vlan-id 925;
unit 0 {
vlan-id 925;
family inet {
address 10.188.111.70/26;
}
}
}
ae1 {
description PUBLIC_VLAN;
flexible-vlan-tagging;
native-vlan-id 985;
unit 0 {
vlan-id 985;
family inet {
address 169.60.101.121/28;
}
family inet6 {
address 2607:f0d0:3901:0063:0000:0000:0000:000f/64;
}
}
}
fxp0 {
unit 0;
}
lo0 {
unit 0 {
family inet {
filter {
input PROTECT-IN;
}
address 127.0.0.1/32;
}
}
}
}
firewall {
filter PROTECT-IN {
term PING {
from {
destination-address {
169.60.101.121/32;
10.188.111.70/32;
}
protocol icmp;
}
then accept;
}
term SSH {
from {
destination-address {
169.60.101.121/32;
10.188.111.70/32;
}
protocol tcp;
destination-port ssh;
}
then accept;
}
term WEB {
from {
destination-address {
169.60.101.121/32;
10.188.111.70/32;
}
protocol tcp;
port 8443;
}
then accept;
}
term DNS {
from {
protocol udp;
source-port 53;
}
then accept;
}
}
}
routing-options {
static {
route 166.9.0.0/16 next-hop 10.188.111.65;
route 0.0.0.0/0 next-hop 169.60.101.113;
route 161.26.0.0/16 next-hop 10.188.111.65;
route 10.0.0.0/8 next-hop 10.188.111.65;
}
}
다음 표는 이전 구성에 대한 네트워크 인터페이스 정의에 대해 설명합니다.
| 인터페이스 이름 | 인터페이스 기능 |
|---|---|
| ge-0/0/0 | SL-PRIVATE 전송 VLAN을 위한 기가비트 이더넷 인터페이스 |
| ge-0/0/1 | SL-PUBLIC 전송 VLAN을 위한 기가비트 이더넷 인터페이스 |
| ge-0/0/2 | SL-PRIVATE 전송 VLAN을 위한 기가비트 이더넷 인터페이스 |
| ge-0/0/3 | SL-PUBLIC 전송 VLAN을 위한 기가비트 이더넷 인터페이스 |
| ae0.0 | 집계된 이더넷 인터페이스 |
| ae1.0 | 집계된 이더넷 인터페이스 |
| fxp0 | 관리 인터페이스 |
| lo0 | 루프백 인터페이스 |
샘플 10G HA SR-IOV 공용 및 사설 vSRX Gateway의 기본 구성
## Last commit: 2020-04-21 17:22:34 UTC by root
version 18.4R1-S1.3;
groups {
node0 {
system {
host-name asloma-tc1b-18-10g-pubpriv-dual-ha1-vsrx-vSRX-Node0;
}
}
node1 {
system {
host-name asloma-tc1b-18-10g-pubpriv-dual-ha1-vsrx-vSRX-Node1;
}
}
}
apply-groups "${node}";
system {
login {
class security {
permissions [ security-control view-configuration ];
}
user admin {
uid 2000;
class super-user;
authentication {
encrypted-password "xxx"; ## SECRET-DATA
}
}
}
root-authentication {
encrypted-password "xxx”;## SECRET-DATA
}
services {
ssh {
root-login allow;
}
netconf {
ssh {
port 830;
}
}
web-management {
http {
interface fxp0.0;
}
https {
port 8443;
system-generated-certificate;
interface [ fxp0.0 reth1.0 reth0.0 ];
}
session {
session-limit 100;
}
}
}
name-server {
10.0.80.11;
10.0.80.12;
}
syslog {
user * {
any emergency;
}
file messages {
any any;
authorization info;
}
file interactive-commands {
interactive-commands any;
}
}
ntp {
server 10.0.77.54;
}
}
chassis {
cluster {
control-link-recovery;
reth-count 4;
heartbeat-interval 2000;
heartbeat-threshold 8;
redundancy-group 0 {
node 0 priority 100;
node 1 priority 1;
}
redundancy-group 1 {
node 0 priority 100;
node 1 priority 1;
inactive: preempt;
interface-monitor {
ge-0/0/3 weight 130;
ge-0/0/4 weight 130;
ge-7/0/3 weight 130;
ge-7/0/4 weight 130;
}
}
}
}
security {
log {
mode stream;
report;
}
address-book {
global {
address SL8 10.1.192.0/20;
address SL9 10.1.160.0/20;
address SL4 10.2.128.0/20;
address SL5 10.1.176.0/20;
address SL6 10.1.64.0/19;
address SL7 10.1.96.0/19;
address SL1 10.0.64.0/19;
address SL2 10.1.128.0/19;
address SL3 10.0.86.0/24;
address SL20 10.3.80.0/20;
address SL18 10.2.176.0/20;
address SL19 10.3.64.0/20;
address SL16 10.2.144.0/20;
address SL17 10.2.48.0/20;
address SL14 10.1.208.0/20;
address SL15 10.2.80.0/20;
address SL12 10.2.112.0/20;
address SL13 10.2.160.0/20;
address SL10 10.2.32.0/20;
address SL11 10.2.64.0/20;
address SL_PRIV_MGMT 10.87.40.36/32;
address SL_PUB_MGMT 169.62.79.21/32;
address-set SERVICE {
address SL8;
address SL9;
address SL4;
address SL5;
address SL6;
address SL7;
address SL1;
address SL2;
address SL3;
address SL20;
address SL18;
address SL19;
address SL16;
address SL17;
address SL14;
address SL15;
address SL12;
address SL13;
address SL10;
address SL11;
}
}
}
screen {
ids-option untrust-screen {
icmp {
ping-death;
}
ip {
source-route-option;
tear-drop;
}
tcp {
syn-flood {
alarm-threshold 1024;
attack-threshold 200;
source-threshold 1024;
destination-threshold 2048;
queue-size 2000; ## Warning: 'queue-size' is deprecated
timeout 20;
}
land;
}
}
}
policies {
from-zone SL-PRIVATE to-zone SL-PRIVATE {
policy Allow_Management {
match {
source-address any;
destination-address [ SL_PRIV_MGMT SERVICE ];
application any;
}
then {
permit;
}
}
}
from-zone SL-PUBLIC to-zone SL-PUBLIC {
policy Allow_Management {
match {
source-address any;
destination-address SL_PUB_MGMT;
application [ junos-ssh junos-https junos-http junos-icmp-ping ];
}
then {
permit;
}
}
}
}
zones {
security-zone SL-PRIVATE {
interfaces {
reth0.0 {
host-inbound-traffic {
system-services {
all;
}
}
}
}
}
security-zone SL-PUBLIC {
interfaces {
reth1.0 {
host-inbound-traffic {
system-services {
all;
}
}
}
}
}
}
}
interfaces {
ge-0/0/1 {
gigether-options {
redundant-parent reth0;
}
}
ge-0/0/2 {
gigether-options {
redundant-parent reth0;
}
}
ge-0/0/3 {
gigether-options {
redundant-parent reth1;
}
}
ge-0/0/4 {
gigether-options {
redundant-parent reth1;
}
}
ge-0/0/5 {
gigether-options {
redundant-parent reth2;
}
}
ge-0/0/6 {
gigether-options {
redundant-parent reth2;
}
}
ge-0/0/7 {
gigether-options {
redundant-parent reth3;
}
}
ge-0/0/8 {
gigether-options {
redundant-parent reth3;
}
}
ge-7/0/1 {
gigether-options {
redundant-parent reth0;
}
}
ge-7/0/2 {
gigether-options {
redundant-parent reth0;
}
}
ge-7/0/3 {
gigether-options {
redundant-parent reth1;
}
}
ge-7/0/4 {
gigether-options {
redundant-parent reth1;
}
}
ge-7/0/5 {
gigether-options {
redundant-parent reth2;
}
}
ge-7/0/6 {
gigether-options {
redundant-parent reth2;
}
}
ge-7/0/7 {
gigether-options {
redundant-parent reth3;
}
}
ge-7/0/8 {
gigether-options {
redundant-parent reth3;
}
}
fab0 {
fabric-options {
member-interfaces {
ge-0/0/0;
ge-0/0/9;
}
}
}
fab1 {
fabric-options {
member-interfaces {
ge-7/0/0;
ge-7/0/9;
}
}
}
lo0 {
unit 0 {
family inet {
filter {
input PROTECT-IN;
}
address 127.0.0.1/32;
}
}
}
reth0 {
redundant-ether-options {
redundancy-group 1;
}
unit 0 {
description "SL PRIVATE VLAN INTERFACE";
family inet {
address 10.87.40.36/26;
}
}
}
reth1 {
redundant-ether-options {
redundancy-group 1;
}
unit 0 {
description "SL PUBLIC VLAN INTERFACE";
family inet {
address 169.62.79.21/29;
}
family inet6 {
address 2607:f0d0:2901:002e:0000:0000:0000:0003/64;
}
}
}
reth2 {
vlan-tagging;
redundant-ether-options {
redundancy-group 1;
}
}
reth3 {
vlan-tagging;
redundant-ether-options {
redundancy-group 1;
}
}
}
firewall {
filter PROTECT-IN {
term PING {
from {
destination-address {
169.62.79.21/32;
10.87.40.36/32;
}
protocol icmp;
}
then accept;
}
term SSH {
from {
destination-address {
169.62.79.21/32;
10.87.40.36/32;
}
protocol tcp;
destination-port ssh;
}
then accept;
}
term WEB {
from {
destination-address {
169.62.79.21/32;
10.87.40.36/32;
}
protocol tcp;
port 8443;
}
then accept;
}
term DNS {
from {
protocol udp;
source-port 53;
}
then accept;
}
}
}
routing-options {
static {
route 166.9.0.0/16 next-hop 10.87.40.1;
route 0.0.0.0/0 next-hop 169.62.79.17;
route 161.26.0.0/16 next-hop 10.87.40.1;
route 10.0.0.0/8 next-hop 10.87.40.1;
}
}
다음 표의 정보에서는 위에 있는 구성을 보여줍니다.
| 인터페이스 이름 | 인터페이스 기능 | 중복 인터페이스 |
|---|---|---|
| ge-0/0/1 / ge-0/0/2 | 노드 0의 SL-PRIVATE 전송 VLAN을 위한 기가비트 이더넷 인터페이스 | reth0 |
| ge-0/0/3 / ge-0/0/4 | 노드 0의 SL-PUBLIC 전송 VLAN을 위한 기가비트 이더넷 인터페이스 | reth1 |
| ge-0/0/5 / ge-0/0/6 | 노드 0의 고객 사설 VLAN을 위한 기가비트 이더넷 인터페이스 | reth2 |
| ge-0/0/7 / ge-0/0/8 | 노드 0의 고객 공용 VLAN을 위한 기가비트 이더넷 인터페이스 | reth3 |
| ge-7/0/1 / ge-7/0/2 | 노드 1의 SL-PRIVATE 전송 VLAN을 위한 기가비트 이더넷 인터페이스 | reth0 |
| ge-7/0/3 / ge-7/0/4 | 노드 1의 SL-PUBLIC 전송 VLAN을 위한 기가비트 이더넷 인터페이스 | reth1 |
| ge-7/0/5 / ge-7/0/6 | 노드 1의 고객 사설 VLAN을 위한 기가비트 이더넷 인터페이스 | reth2 |
| ge-7/0/7 / ge-7/0/8 | 노드 1의 고객 공용 VLAN을 위한 기가비트 이더넷 인터페이스 | reth3 |
| fab0 | 섀시 클러스터 패브릭 링크는 ge-0/0/0 및 ge-0/0/9를 사용함 | |
| fab1 | 섀시 클러스터 패브릭 링크는 ge-7/0/0 및 ge-7/0/9를 사용함 | |
| fxp0 | 관리 인터페이스 | |
| lo0 | 루프백 인터페이스 |
인터페이스 구성
이 구성에 대한 레거시 아키텍처는 Ubuntu 호스트 하이퍼바이저의 Linux Bridging을 활용했습니다. 이후 IBM은 호스트에서 SR-IOV를 활용하는 게이트웨이를 위해 새 아키텍처로 전환했습니다. 대부분의 경우 이로 인해 vSRX 구성의 인터페이스 맵핑이 변경되었습니다. 또한 다음과 같은 vSRX의 상태에 따라 인터페이스 구성이 달라집니다.
- 10G 또는 1G
- 독립형 또는 고가용성
- 공용 및 사설 또는 사설 전용
- vSRX 버전
- 모든 15.1 기반의 vSRX는 레거시 아키텍처를 사용합니다.
- 일부 18.4 기반의 vSRX도 레거시 아키텍처를 사용합니다.
레거시 및 현재 아키텍처는 다음 절에 자세히 설명되어 있습니다.
vSRX 고가용성 인터페이스(현재 아키텍처)
| 인터페이스 | 10G 공용 및 사설 | 10G 사설 전용 | 1G 공용 및 사설 | 1G 사설 전용 |
|---|---|---|---|---|
| ge-0/0/0 | fab0 | fab0 | fab0 | fab0 |
| ge-0/0/1 | reth0 | reth0 | reth0 | reth0 |
| ge-0/0/2 | reth0 | reth0 | reth0 | reth0 |
| ge-0/0/3 | reth1 | reth2 | reth1 | reth2 |
| ge-0/0/4 | reth1 | reth2 | reth1 | reth2 |
| ge-0/0/5 | reth2 | fab0 | reth2 | fab0 |
| ge-0/0/6 | reth2 | 없음 | reth2 | 없음 |
| ge-0/0/7 | reth3 | 없음 | reth3 | 없음 |
| ge-0/0/8 | reth3 | 없음 | reth3 | 없음 |
| ge-0/0/9 | fab0 | 없음 | fab0 | 없음 |
| ge-7/0/0 | fab1 | fab1 | fab1 | fab1 |
| ge-7/0/1 | reth0 | reth0 | reth0 | reth0 |
| ge-7/0/2 | reth0 | reth0 | reth0 | reth0 |
| ge-7/0/3 | reth1 | reth2 | reth1 | reth2 |
| ge-7/0/4 | reth1 | reth2 | reth1 | reth2 |
| ge-7/0/5 | reth2 | fab1 | reth2 | fab1 |
| ge-7/0/6 | reth2 | 없음 | reth2 | 없음 |
| ge-7/0/7 | reth3 | 없음 | reth3 | 없음 |
| ge-7/0/8 | reth3 | 없음 | reth3 | 없음 |
| ge-7/0/9 | fab1 | 없음 | fab1 | 없음 |
vSRX 독립형 인터페이스(현재 아키텍처)
| 인터페이스 | 10G 공용 및 사설 | 10G 사설 전용 | 1G 공용 및 사설 | 1G 사설 전용 |
|---|---|---|---|---|
| ge-0/0/0 | ae0 | ae0 | ae0 | ae0 |
| ge-0/0/1 | ae1 | ae0 | ae1 | ae0 |
| ge-0/0/2 | ae0 | 없음 | ae0 | 없음 |
| ge-0/0/3 | ae1 | 없음 | ae1 | 없음 |
vSRX 고가용성 인터페이스(레거시 아키텍처)
| 인터페이스 | 10G 공용 및 사설 | 10G 사설 전용 | 1G 공용 및 사설 | 1G 사설 전용 |
|---|---|---|---|---|
| ge-0/0/0 | fab0 | fab0 | fab0 | fab0 |
| ge-0/0/1 | reth0 | reth0 | reth0 | reth0 |
| ge-0/0/2 | reth0 | reth0 | reth2 | reth2 |
| ge-0/0/3 | reth1 | reth2 | reth1 | 사용되지 않음 |
| ge-0/0/4 | reth1 | reth2 | reth3 | 사용되지 않음 |
| ge-0/0/5 | reth2 | 사용되지 않음 | 없음 | 없음 |
| ge-0/0/6 | reth2 | 사용되지 않음 | 없음 | 없음 |
| ge-0/0/7 | reth3 | 사용되지 않음 | 없음 | 없음 |
| ge-0/0/8 | reth3 | 사용되지 않음 | 없음 | 없음 |
| ge-7/0/0 | fab1 | fab1 | fab1 | fab1 |
| ge-7/0/1 | reth0 | reth0 | reth0 | reth0 |
| ge-7/0/2 | reth0 | reth0 | reth2 | reth2 |
| ge-7/0/3 | reth1 | reth2 | reth1 | 사용되지 않음 |
| ge-7/0/4 | reth1 | reth2 | reth3 | 사용되지 않음 |
| ge-7/0/5 | reth2 | 사용되지 않음 | 없음 | 없음 |
| ge-7/0/6 | reth2 | 사용되지 않음 | 없음 | 없음 |
| ge-7/0/7 | reth3 | 사용되지 않음 | 없음 | 없음 |
| ge-7/0/8 | reth3 | 사용되지 않음 | 없음 | 없음 |
vSRX 독립형 인터페이스(레거시 아키텍처)
| 인터페이스 | 10G 공용 및 사설 | 10G 사설 전용 | 1G 공용 및 사설 | 1G 사설 전용 |
|---|---|---|---|---|
| ge-0/0/0 | ae0 | ae0 | ge-0/0/0 | ge-0/0/0 |
| ge-0/0/1 | ae1 | ae0 | ge-0/0/1 | 없음 |
| ge-0/0/2 | ae0 | 없음 | 없음 | 없음 |
| ge-0/0/3 | ae1 | 없음 | 없음 | 없음 |