ICT Diary

Network、Server系の内容を気まぐれにUPしていく。

Juniper SRX Static Route Configuration

前提設定

RT1 (CiscoRT)

interface GigabitEthernet0/0
 ip address 10.0.10.3 255.255.255.0

ip route 0.0.0.0 0.0.0.0 10.0.10.1
ip route 0.0.0.0 0.0.0.0 10.0.10.2 10

RT2 (CiscoRT)

interface GigabitEthernet0/0
 ip address 10.0.10.1 255.255.255.0

interface GigabitEthernet0/1
 ip address 10.0.20.1 255.255.255.0

RT3 (CiscoRT)

interface GigabitEthernet0/0
 ip address 10.0.10.2 255.255.255.0

interface GigabitEthernet0/1
 ip address 10.0.20.2 255.255.255.0

FW

set interfaces ge-0/0/0 unit 0 family inet address 10.0.20.3/24

Command Format

  • ※1: CiscoでいうAdministrative Distance(AD値)
  • ※2:
    • discard: 何もせずパケットを破棄
    • reject: ICMP Unreachableを返した上で、パケットを破棄
  • ※3: 再帰ルートとはNextHopがDirectConnectedではない経路
set routing-options static route [Subnet]/[Prefix] next-hop [NEXTHOP]:転送先のIPを指定
set routing-options static route [Subnet]/[Prefix] preference [VALUE]:ルートプリファレンス値を指定 ※1
set routing-options aggregate route [Subnet]/[Prefix]:経路集約の設定
set routing-options aggregate route [Subnet]/[Prefix] [discard|reject]:経路集約でのブラックホールルートを設定(NullRoute) ※2
set routing-options static route [Subnet]/[Prefix] next-hop [NEXTHOP] resolove:再帰ルートオプションを指定 ※3

確認コマンド

show route
show route protocol static
show route [NETWORK]

Static Route

トポロジー

[RT1].3-----------.1[RT2].1-----------.3[FW]
    |<------------->|   |<------------->|
           NW1                 NW2
      10.0.10.0/24         10.0.20.0/24

設定

set routing-options static route 10.0.10.0/24 next-hop 10.0.20.1

Qualified NextHop (フローティングルート)

トポロジー

            |------.1[RT1].1------|
[RT1].3-----|                     |------.3[FW]
            |------.2[RT3].2------|

    |<-------------->|   |<--------------->|
            NW1                  NW2
        10.0.10.0/24         10.0.20.0/24

設定

set routing-options static route 10.0.10.0/24 next-hop 10.0.20.1
set routing-options static route 10.0.10.0/24 qualified-next-hop 10.0.20.2 preference 10

確認

root> show route protocol static
10.0.10.0/24       *[Static/5] 06:37:11
                    >  to 10.0.20.1  via ge-0/0/0.0
                    [Static/10] 00:00:30
                    >  to 10.0.20.2  via ge-0/0/0.0

SRXでのRT1の障害検知のconfigは省略する