[j-nsp] Problem to ping a node on internet - CLOSED CASE

Roland Droual roland.droual at paris.iufm.fr
Tue Jun 19 07:54:22 EDT 2012



Hello the list, 

I solve most of problems to ping from my SRX cluster. 
- In first, my provider gave me another range IP @, because the first was wrong. So I can ping from my DMZ (with public @); 
- In Second, I put my NAT rules (which I forgot), so I can ping from a node from INSIDE network; 
- In third, I change the cluster ID number, on the cluster of site B; So I can ping the SRX cluster on site A, via the link "INTER-SITE". Because I have the same symetric configuration: 
- same reth_s 
- same cluster ID number = 1 for the both 
- same node number 
- same vlan 
- etc ... 
- vlan INTER-SITE : On site A = 10.1.3.1/29 on 1 cluster (cluster ID =1) , 
On site B = 10.1.3.2/29 on the other cluster (cluster ID = 1) 
The cluster ont Site A (10.1.3.1) is up for 2 weeks. It could ping a node on site B (with 10.1.3.3/29), but the SRX of site B (with 10.1.3.2/29) . 
I couldn't ping the SRX on site B , because the 2 SRX clusters are on the same L2 domain broadcast, and they had the same cluster number ID, that is used to form the virtual MAC address, that is used for the RETH interface. So I think I had a MAC address overlap, and forwarding problems occured. 
When I changed the cluster ID number to 2 , on the cluster on Site B, the problems disappeared. 

Roland 



More information about the juniper-nsp mailing list