vSRX 기본 구성 이해

IBM Cloud® Juniper vSRX 디바이스는 다음 기본 구성으로 제공됩니다.

  • SSH 및 Ping은 vSRX 공용 및 사설 게이트웨이 IP 주소에 허용됩니다.
  • Juniper Web Management(J-Web) UI 액세스는 공용 및 사설 게이트웨이 IP 주소의 HTTPS 포트 8443에 허용됩니다.
  • 주소 세트 SERVICE는 IBM 서비스 네트워크에 대해 사전 정의됩니다.
  • SL-PRIVATESL-PUBLIC의 두 보안 구역이 사전 정의됩니다.
  • SL-PRIVATE 구역에서 모든 서비스까지의 액세스가 IBM에서 제공되고 주소 세트 SERVICE가 허용됩니다.
  • 기타 모든 네트워크 액세스가 거부됩니다.

두 개의 중복성 그룹이 구성됩니다. 다음 표에서는 이 중복성 그룹에 대해 설명합니다.

중복 그룹
중복성 그룹 중복성 그룹 기능
redundancy-group 0 제어 플레인을 위한 중복성 그룹
redundancy-group 1 데이터 플레인을 위한 중복성 그룹

중복성 그룹의 우선순위는 활성 상태인 vSRX 노드를 결정합니다. 기본적으로 노드 0은 제어 플레인 및 데이터 플레인 모두에 대해 활성 상태입니다.

샘플 1G 독립형 SR-IOV 공용 및 사설 vSRX Gateway의 기본 구성

다음 코드 샘플은 최신 코드 릴리스에서 제공되는 예입니다.

## Last commit: 2020-04-28 00:32:27 UTC by root
version 18.4R1-S1.3;
system {
    login {
        class security {
            permissions [ security-control view-configuration ];
        }
        user admin {
            uid 2000;
            class super-user;
            authentication {
                encrypted-password "$6$5gPuIk9u$JPzyjh5zVz0tf4P3.POWv4UWGDfowbzirGmnpiBUW0tDWLf1ZfvP.YwN88Mc8.cyOIvgDMrksbCYsmZxf4f3p."; ## SECRET-DATA
            }
        }
    }
    root-authentication {
        encrypted-password "$6$q9tQzuqT$/TFQLkHK.woO.Qv9YcZ1nnJqZqhLBqXeg7L3xkUWXVmq8fn4N7mClTpckoCKhombXucxU6StRKOiHTDUeTdd91"; ## SECRET-DATA
    }
    services {
        ssh {
            root-login allow;
        }
        netconf {
            ssh {
                port 830;
            }
        }
        web-management {
            http {
                interface fxp0.0;
            }
            https {
                port 8443;
                system-generated-certificate;
                interface [ fxp0.0 ae0.0 ae1.0 ge-0/0/0.0 ge-0/0/1.0 ];
            }
            session {
                session-limit 100;
            }
        }
    }
    host-name asloma-swap-18-1g-sa0-vsrx-vSRX;
    name-server {
        10.0.80.11;
        10.0.80.12;
    }
    syslog {
        user * {
            any emergency;
        }
        file messages {
            any any;
            authorization info;
        }
        file interactive-commands {
            interactive-commands any;
        }
    }
    ntp {
        server 10.0.77.54;
    }
}
chassis {
    aggregated-devices {
        ethernet {
            device-count 10;
        }
    }
}
security {
    log {
        mode stream;
        report;
    }
    address-book {
        global {
            address SL8 10.1.192.0/20;
            address SL9 10.1.160.0/20;
            address SL4 10.2.128.0/20;
            address SL5 10.1.176.0/20;
            address SL6 10.1.64.0/19;
            address SL7 10.1.96.0/19;
            address SL1 10.0.64.0/19;
            address SL2 10.1.128.0/19;
            address SL3 10.0.86.0/24;
            address SL20 10.3.80.0/20;
            address SL18 10.2.176.0/20;
            address SL19 10.3.64.0/20;
            address SL16 10.2.144.0/20;
            address SL17 10.2.48.0/20;
            address SL14 10.1.208.0/20;
            address SL15 10.2.80.0/20;
            address SL12 10.2.112.0/20;
            address SL13 10.2.160.0/20;
            address SL10 10.2.32.0/20;
            address SL11 10.2.64.0/20;
            address SL_PRIV_MGMT 10.188.111.70/32;
            address SL_PUB_MGMT 169.60.101.121/32;
            address-set SERVICE {
                address SL8;
                address SL9;
                address SL4;
                address SL5;
                address SL6;
                address SL7;
                address SL1;
                address SL2;
                address SL3;
                address SL20;
                address SL18;
                address SL19;
                address SL16;
                address SL17;
                address SL14;
                address SL15;
                address SL12;
                address SL13;
                address SL10;
                address SL11;
            }
        }
    }
    screen {
        ids-option untrust-screen {
            icmp {
                ping-death;
            }
            ip {
                source-route-option;
                tear-drop;
            }
            tcp {
                syn-flood {
                    alarm-threshold 1024;
                    attack-threshold 200;
                    source-threshold 1024;
                    destination-threshold 2048;
                    queue-size 2000; ## Warning: 'queue-size' is deprecated
                    timeout 20;
                }
                land;
            }
        }
    }
    policies {
        from-zone SL-PRIVATE to-zone SL-PRIVATE {
            policy Allow_Management {
                match {
                    source-address any;
                    destination-address [ SL_PRIV_MGMT SERVICE ];
                    application any;
                }
                then {
                    permit;
                }
            }
        }
        from-zone SL-PUBLIC to-zone SL-PUBLIC {
            policy Allow_Management {
                match {
                    source-address any;
                    destination-address SL_PUB_MGMT;
                    application [ junos-ssh junos-https junos-http junos-icmp-ping ];
                }
                then {
                    permit;
                }
            }
        }
    }
    zones {
        security-zone SL-PRIVATE {
            interfaces {
                ae0.0 {
                    host-inbound-traffic {
                        system-services {
                            all;
                        }
                    }
                }
            }
        }
        security-zone SL-PUBLIC {
            interfaces {
                ae1.0 {
                    host-inbound-traffic {
                        system-services {
                            all;
                        }
                    }
                }
            }
        }
    }
}
interfaces {
    ge-0/0/0 {
        ether-options {
            802.3ad ae0;
        }
    }
    ge-0/0/1 {
        ether-options {
            802.3ad ae1;
        }
    }
    ge-0/0/2 {
        ether-options {
            802.3ad ae0;
        }
    }
    ge-0/0/3 {
        ether-options {
            802.3ad ae1;
        }
    }
    ae0 {
        description PRIVATE_VLANs;
        flexible-vlan-tagging;
        native-vlan-id 925;
        unit 0 {
            vlan-id 925;
            family inet {
                address 10.188.111.70/26;
            }
        }
    }
    ae1 {
        description PUBLIC_VLAN;
        flexible-vlan-tagging;
        native-vlan-id 985;
        unit 0 {
            vlan-id 985;
            family inet {
                address 169.60.101.121/28;
            }
            family inet6 {
                address 2607:f0d0:3901:0063:0000:0000:0000:000f/64;
            }
        }
    }
    fxp0 {
        unit 0;
    }
    lo0 {
        unit 0 {
            family inet {
                filter {
                    input PROTECT-IN;
                }
                address 127.0.0.1/32;
            }
        }
    }
}
firewall {
    filter PROTECT-IN {
        term PING {
            from {
                destination-address {
                    169.60.101.121/32;
                    10.188.111.70/32;
                }
                protocol icmp;
            }
            then accept;
        }
        term SSH {
            from {
                destination-address {
                    169.60.101.121/32;
                    10.188.111.70/32;
                }
                protocol tcp;
                destination-port ssh;
            }
            then accept;
        }
        term WEB {
            from {
                destination-address {
                    169.60.101.121/32;
                    10.188.111.70/32;
                }
                protocol tcp;
                port 8443;
            }
            then accept;
        }
        term DNS {
            from {
                protocol udp;
                source-port 53;
            }
            then accept;
        }
    }
}
routing-options {
    static {
        route 166.9.0.0/16 next-hop 10.188.111.65;
        route 0.0.0.0/0 next-hop 169.60.101.113;
        route 161.26.0.0/16 next-hop 10.188.111.65;
        route 10.0.0.0/8 next-hop 10.188.111.65;
    }
}

다음 표는 이전 구성에 대한 네트워크 인터페이스 정의에 대해 설명합니다.

네트워크 인터페이스 정의
인터페이스 이름 인터페이스 기능
ge-0/0/0 SL-PRIVATE 전송 VLAN을 위한 기가비트 이더넷 인터페이스
ge-0/0/1 SL-PUBLIC 전송 VLAN을 위한 기가비트 이더넷 인터페이스
ge-0/0/2 SL-PRIVATE 전송 VLAN을 위한 기가비트 이더넷 인터페이스
ge-0/0/3 SL-PUBLIC 전송 VLAN을 위한 기가비트 이더넷 인터페이스
ae0.0 집계된 이더넷 인터페이스
ae1.0 집계된 이더넷 인터페이스
fxp0 관리 인터페이스
lo0 루프백 인터페이스

샘플 10G HA SR-IOV 공용 및 사설 vSRX Gateway의 기본 구성

## Last commit: 2020-04-21 17:22:34 UTC by root
version 18.4R1-S1.3;
groups {
    node0 {
        system {
            host-name asloma-tc1b-18-10g-pubpriv-dual-ha1-vsrx-vSRX-Node0;
        }
    }
    node1 {
        system {
            host-name asloma-tc1b-18-10g-pubpriv-dual-ha1-vsrx-vSRX-Node1;
        }
    }
}
apply-groups "${node}";
system {
    login {
        class security {
            permissions [ security-control view-configuration ];
        }
        user admin {
            uid 2000;
            class super-user;
            authentication {
                encrypted-password "xxx"; ## SECRET-DATA
            }
        }
    }
    root-authentication {
        encrypted-password "xxx”;## SECRET-DATA
    }
    services {
        ssh {
            root-login allow;
        }
        netconf {
            ssh {
                port 830;
            }
        }
        web-management {
            http {
                interface fxp0.0;
            }
            https {
                port 8443;
                system-generated-certificate;
                interface [ fxp0.0 reth1.0 reth0.0 ];
            }
            session {
                session-limit 100;
            }
        }
    }
    name-server {
        10.0.80.11;
        10.0.80.12;
    }
    syslog {
        user * {
            any emergency;
        }
        file messages {
            any any;
            authorization info;
        }
        file interactive-commands {
            interactive-commands any;
        }
    }
    ntp {
        server 10.0.77.54;
    }
}
chassis {
    cluster {
        control-link-recovery;
        reth-count 4;
        heartbeat-interval 2000;
        heartbeat-threshold 8;
        redundancy-group 0 {
            node 0 priority 100;
            node 1 priority 1;
        }
        redundancy-group 1 {
            node 0 priority 100;
            node 1 priority 1;
            inactive: preempt;
            interface-monitor {
                ge-0/0/3 weight 130;
                ge-0/0/4 weight 130;
                ge-7/0/3 weight 130;
                ge-7/0/4 weight 130;
            }
        }
    }
}
security {
    log {
        mode stream;
        report;
    }
    address-book {
        global {
            address SL8 10.1.192.0/20;
            address SL9 10.1.160.0/20;
            address SL4 10.2.128.0/20;
            address SL5 10.1.176.0/20;
            address SL6 10.1.64.0/19;
            address SL7 10.1.96.0/19;
            address SL1 10.0.64.0/19;
            address SL2 10.1.128.0/19;
            address SL3 10.0.86.0/24;
            address SL20 10.3.80.0/20;
            address SL18 10.2.176.0/20;
            address SL19 10.3.64.0/20;
            address SL16 10.2.144.0/20;
            address SL17 10.2.48.0/20;
            address SL14 10.1.208.0/20;
            address SL15 10.2.80.0/20;
            address SL12 10.2.112.0/20;
            address SL13 10.2.160.0/20;
            address SL10 10.2.32.0/20;
            address SL11 10.2.64.0/20;
            address SL_PRIV_MGMT 10.87.40.36/32;
            address SL_PUB_MGMT 169.62.79.21/32;
            address-set SERVICE {
                address SL8;
                address SL9;
                address SL4;
                address SL5;
                address SL6;
                address SL7;
                address SL1;
                address SL2;
                address SL3;
                address SL20;
                address SL18;
                address SL19;
                address SL16;
                address SL17;
                address SL14;
                address SL15;
                address SL12;
                address SL13;
                address SL10;
                address SL11;
            }
        }
    }
    screen {
        ids-option untrust-screen {
            icmp {
                ping-death;
            }
            ip {
                source-route-option;
                tear-drop;
            }
            tcp {
                syn-flood {
                    alarm-threshold 1024;
                    attack-threshold 200;
                    source-threshold 1024;
                    destination-threshold 2048;
                    queue-size 2000; ## Warning: 'queue-size' is deprecated
                    timeout 20;
                }
                land;
            }
        }
    }
    policies {
        from-zone SL-PRIVATE to-zone SL-PRIVATE {
            policy Allow_Management {
                match {
                    source-address any;
                    destination-address [ SL_PRIV_MGMT SERVICE ];
                    application any;
                }
                then {
                    permit;
                }
            }
        }
        from-zone SL-PUBLIC to-zone SL-PUBLIC {
            policy Allow_Management {
                match {
                    source-address any;
                    destination-address SL_PUB_MGMT;
                    application [ junos-ssh junos-https junos-http junos-icmp-ping ];
                }
                then {
                    permit;
                }
            }
        }
    }
    zones {
        security-zone SL-PRIVATE {
            interfaces {
                reth0.0 {
                    host-inbound-traffic {
                        system-services {
                            all;
                        }
                    }
                }
            }
        }
        security-zone SL-PUBLIC {
            interfaces {
                reth1.0 {
                    host-inbound-traffic {
                        system-services {
                            all;
                        }
                    }
                }
            }
        }
    }
}
interfaces {
    ge-0/0/1 {
        gigether-options {
            redundant-parent reth0;
        }
    }
    ge-0/0/2 {
        gigether-options {
            redundant-parent reth0;
        }
    }
    ge-0/0/3 {
        gigether-options {
            redundant-parent reth1;
        }
    }
    ge-0/0/4 {
        gigether-options {
            redundant-parent reth1;
        }
    }
    ge-0/0/5 {
        gigether-options {
            redundant-parent reth2;
        }
    }
    ge-0/0/6 {
        gigether-options {
            redundant-parent reth2;
        }
    }
    ge-0/0/7 {
        gigether-options {
            redundant-parent reth3;
        }
    }
    ge-0/0/8 {
        gigether-options {
            redundant-parent reth3;
        }
    }
    ge-7/0/1 {
        gigether-options {
            redundant-parent reth0;
        }
    }
    ge-7/0/2 {
        gigether-options {
            redundant-parent reth0;
        }
    }
    ge-7/0/3 {
        gigether-options {
            redundant-parent reth1;
        }
    }
    ge-7/0/4 {
        gigether-options {
            redundant-parent reth1;
        }
    }
    ge-7/0/5 {
        gigether-options {
            redundant-parent reth2;
        }
    }
    ge-7/0/6 {
        gigether-options {
            redundant-parent reth2;
        }
    }
    ge-7/0/7 {
        gigether-options {
            redundant-parent reth3;
        }
    }
    ge-7/0/8 {
        gigether-options {
            redundant-parent reth3;
        }
    }
    fab0 {
        fabric-options {
            member-interfaces {
                ge-0/0/0;
                ge-0/0/9;
            }
        }
    }
    fab1 {
        fabric-options {
            member-interfaces {
                ge-7/0/0;
                ge-7/0/9;
            }
        }
    }
    lo0 {
        unit 0 {
            family inet {
                filter {
                    input PROTECT-IN;
                }
                address 127.0.0.1/32;
            }
        }
    }
    reth0 {
        redundant-ether-options {
            redundancy-group 1;
        }
        unit 0 {
            description "SL PRIVATE VLAN INTERFACE";
            family inet {
                address 10.87.40.36/26;
            }
        }
    }
    reth1 {
        redundant-ether-options {
            redundancy-group 1;
        }
        unit 0 {
            description "SL PUBLIC VLAN INTERFACE";
            family inet {
                address 169.62.79.21/29;
            }
            family inet6 {
                address 2607:f0d0:2901:002e:0000:0000:0000:0003/64;
            }
        }
    }
    reth2 {
        vlan-tagging;
        redundant-ether-options {
            redundancy-group 1;
        }
    }
    reth3 {
        vlan-tagging;
        redundant-ether-options {
            redundancy-group 1;
        }
    }
}
firewall {
    filter PROTECT-IN {
        term PING {
            from {
                destination-address {
                    169.62.79.21/32;
                    10.87.40.36/32;
                }
                protocol icmp;
            }
            then accept;
        }
        term SSH {
            from {
                destination-address {
                    169.62.79.21/32;
                    10.87.40.36/32;
                }
                protocol tcp;
                destination-port ssh;
            }
            then accept;
        }
        term WEB {
            from {
                destination-address {
                    169.62.79.21/32;
                    10.87.40.36/32;
                }
                protocol tcp;
                port 8443;
            }
            then accept;
        }
        term DNS {
            from {
                protocol udp;
                source-port 53;
            }
            then accept;
        }
    }
}
routing-options {
    static {
        route 166.9.0.0/16 next-hop 10.87.40.1;
        route 0.0.0.0/0 next-hop 169.62.79.17;
        route 161.26.0.0/16 next-hop 10.87.40.1;
        route 10.0.0.0/8 next-hop 10.87.40.1;
    }
}

다음 표의 정보에서는 위에 있는 구성을 보여줍니다.

구성 정보
인터페이스 이름 인터페이스 기능 중복 인터페이스
ge-0/0/1 / ge-0/0/2 노드 0의 SL-PRIVATE 전송 VLAN을 위한 기가비트 이더넷 인터페이스 reth0
ge-0/0/3 / ge-0/0/4 노드 0의 SL-PUBLIC 전송 VLAN을 위한 기가비트 이더넷 인터페이스 reth1
ge-0/0/5 / ge-0/0/6 노드 0의 고객 사설 VLAN을 위한 기가비트 이더넷 인터페이스 reth2
ge-0/0/7 / ge-0/0/8 노드 0의 고객 공용 VLAN을 위한 기가비트 이더넷 인터페이스 reth3
ge-7/0/1 / ge-7/0/2 노드 1의 SL-PRIVATE 전송 VLAN을 위한 기가비트 이더넷 인터페이스 reth0
ge-7/0/3 / ge-7/0/4 노드 1의 SL-PUBLIC 전송 VLAN을 위한 기가비트 이더넷 인터페이스 reth1
ge-7/0/5 / ge-7/0/6 노드 1의 고객 사설 VLAN을 위한 기가비트 이더넷 인터페이스 reth2
ge-7/0/7 / ge-7/0/8 노드 1의 고객 공용 VLAN을 위한 기가비트 이더넷 인터페이스 reth3
fab0 섀시 클러스터 패브릭 링크는 ge-0/0/0 및 ge-0/0/9를 사용함
fab1 섀시 클러스터 패브릭 링크는 ge-7/0/0 및 ge-7/0/9를 사용함
fxp0 관리 인터페이스
lo0 루프백 인터페이스

인터페이스 구성

이 구성에 대한 레거시 아키텍처는 Ubuntu 호스트 하이퍼바이저의 Linux Bridging을 활용했습니다. 이후 IBM은 호스트에서 SR-IOV를 활용하는 게이트웨이를 위해 새 아키텍처로 전환했습니다. 대부분의 경우 이로 인해 vSRX 구성의 인터페이스 맵핑이 변경되었습니다. 또한 다음과 같은 vSRX의 상태에 따라 인터페이스 구성이 달라집니다.

  • 10G 또는 1G
  • 독립형 또는 고가용성
  • 공용 및 사설 또는 사설 전용
  • vSRX 버전
    • 모든 15.1 기반의 vSRX는 레거시 아키텍처를 사용합니다.
    • 일부 18.4 기반의 vSRX도 레거시 아키텍처를 사용합니다.

레거시 및 현재 아키텍처는 다음 절에 자세히 설명되어 있습니다.

vSRX 고가용성 인터페이스(현재 아키텍처)

vSRX 고가용성 인터페이스(현재 아키텍처)
인터페이스 10G 공용 및 사설 10G 사설 전용 1G 공용 및 사설 1G 사설 전용
ge-0/0/0 fab0 fab0 fab0 fab0
ge-0/0/1 reth0 reth0 reth0 reth0
ge-0/0/2 reth0 reth0 reth0 reth0
ge-0/0/3 reth1 reth2 reth1 reth2
ge-0/0/4 reth1 reth2 reth1 reth2
ge-0/0/5 reth2 fab0 reth2 fab0
ge-0/0/6 reth2 없음 reth2 없음
ge-0/0/7 reth3 없음 reth3 없음
ge-0/0/8 reth3 없음 reth3 없음
ge-0/0/9 fab0 없음 fab0 없음
ge-7/0/0 fab1 fab1 fab1 fab1
ge-7/0/1 reth0 reth0 reth0 reth0
ge-7/0/2 reth0 reth0 reth0 reth0
ge-7/0/3 reth1 reth2 reth1 reth2
ge-7/0/4 reth1 reth2 reth1 reth2
ge-7/0/5 reth2 fab1 reth2 fab1
ge-7/0/6 reth2 없음 reth2 없음
ge-7/0/7 reth3 없음 reth3 없음
ge-7/0/8 reth3 없음 reth3 없음
ge-7/0/9 fab1 없음 fab1 없음

vSRX 독립형 인터페이스(현재 아키텍처)

vSRX 독립형 인터페이스(현재 아키텍처)
인터페이스 10G 공용 및 사설 10G 사설 전용 1G 공용 및 사설 1G 사설 전용
ge-0/0/0 ae0 ae0 ae0 ae0
ge-0/0/1 ae1 ae0 ae1 ae0
ge-0/0/2 ae0 없음 ae0 없음
ge-0/0/3 ae1 없음 ae1 없음

vSRX 고가용성 인터페이스(레거시 아키텍처)

vSRX 고가용성 인터페이스(레거시 아키텍처)
인터페이스 10G 공용 및 사설 10G 사설 전용 1G 공용 및 사설 1G 사설 전용
ge-0/0/0 fab0 fab0 fab0 fab0
ge-0/0/1 reth0 reth0 reth0 reth0
ge-0/0/2 reth0 reth0 reth2 reth2
ge-0/0/3 reth1 reth2 reth1 사용되지 않음
ge-0/0/4 reth1 reth2 reth3 사용되지 않음
ge-0/0/5 reth2 사용되지 않음 없음 없음
ge-0/0/6 reth2 사용되지 않음 없음 없음
ge-0/0/7 reth3 사용되지 않음 없음 없음
ge-0/0/8 reth3 사용되지 않음 없음 없음
ge-7/0/0 fab1 fab1 fab1 fab1
ge-7/0/1 reth0 reth0 reth0 reth0
ge-7/0/2 reth0 reth0 reth2 reth2
ge-7/0/3 reth1 reth2 reth1 사용되지 않음
ge-7/0/4 reth1 reth2 reth3 사용되지 않음
ge-7/0/5 reth2 사용되지 않음 없음 없음
ge-7/0/6 reth2 사용되지 않음 없음 없음
ge-7/0/7 reth3 사용되지 않음 없음 없음
ge-7/0/8 reth3 사용되지 않음 없음 없음

vSRX 독립형 인터페이스(레거시 아키텍처)

vSRX 독립형 인터페이스(레거시 아키텍처)
인터페이스 10G 공용 및 사설 10G 사설 전용 1G 공용 및 사설 1G 사설 전용
ge-0/0/0 ae0 ae0 ge-0/0/0 ge-0/0/0
ge-0/0/1 ae1 ae0 ge-0/0/1 없음
ge-0/0/2 ae0 없음 없음 없음
ge-0/0/3 ae1 없음 없음 없음