Tuesday, September 9, 2014

Juniper MC-LAG Active / Active








Core Switch B configuration



set chassis aggregated-devices ethernet device-count 100
set interfaces xe-1/2/6 description ***ICCP-LINK-MEM***
set interfaces xe-1/2/6 ether-options 802.3ad ae0
set interfaces xe-1/3/1 description ***ICCP-LINK-MEM***
set interfaces xe-1/3/1 ether-options 802.3ad ae0
set interfaces ge-5/0/0 ether-options 802.3ad ae6
set interfaces ae0 description ***ICCP-LINK-BUNDLE***
set interfaces ae0 unit 0 family ethernet-switching interface-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members all


Core configuration for MC-LAG 


set version 13.2R5.10
set system host-name IGTE_CHN_SIP_PH2_COREA
set system arp aging-timer 5
set system root-authentication encrypted-password "$1$lMQOImBk$MHdIosHh0E6gIYlpg7ai60"
set system login user igate uid 2001
set system login user igate class super-user
set system login user igate authentication encrypted-password "$1$wtZGfmM9$FkZYN3PTTVqFexAUpDM5/0"
set system syslog user * any emergency
set system syslog file messages any notice
set system syslog file messages authorization info
set system syslog file interactive-commands interactive-commands any
set system commit synchronize
set chassis redundancy routing-engine 0 master
set chassis redundancy routing-engine 1 backup
set chassis redundancy graceful-switchover
set chassis aggregated-devices ethernet device-count 100

set interfaces xe-1/2/6 description ***ICCP-LINK-PORT-MEM***
set interfaces xe-1/2/6 ether-options 802.3ad ae0

set interfaces xe-1/3/1 description ***ICCP-LINK-PORT-MEM***
set interfaces xe-1/3/1 ether-options 802.3ad ae0
set interfaces ge-5/0/0 ether-options 802.3ad ae6

set interfaces ae0 description ***ICCP-LINK-BUNDLE***
set interfaces ae0 unit 0 family ethernet-switching interface-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members all

set interfaces ae6 aggregated-ether-options lacp active
set interfaces ae6 aggregated-ether-options lacp system-id 00:00:00:00:00:02
set interfaces ae6 aggregated-ether-options lacp admin-key 20
set interfaces ae6 aggregated-ether-options mc-ae mc-ae-id 6
set interfaces ae6 aggregated-ether-options mc-ae redundancy-group 1
set interfaces ae6 aggregated-ether-options mc-ae chassis-id 0
set interfaces ae6 aggregated-ether-options mc-ae mode active-active
set interfaces ae6 aggregated-ether-options mc-ae status-control active
set interfaces ae6 aggregated-ether-options mc-ae init-delay-time 240
set interfaces ae6 unit 0 family ethernet-switching interface-mode trunk
set interfaces ae6 unit 0 family ethernet-switching vlan members GODC1

set interfaces irb unit 6 family inet address 10.219.11.2/24 arp 10.219.11.3 l2-interface ae0.0
set interfaces irb unit 6 family inet address 10.219.11.2/24 arp 10.219.11.3 mac cc:e1:7f:06:4b:f0
set interfaces irb unit 6 family inet address 10.219.11.2/24 vrrp-group 6 virtual-address 10.219.11.1
set interfaces irb unit 6 family inet address 10.219.11.2/24 vrrp-group 6 priority 120
set interfaces irb unit 6 family inet address 10.219.11.2/24 vrrp-group 6 accept-data

set interfaces irb unit 99 family inet address 3.3.3.1/30
set multi-chassis multi-chassis-protection 3.3.3.1 interface ae0
set routing-options nonstop-routing

set protocols iccp local-ip-addr 3.3.3.1
set protocols iccp peer 3.3.3.2 session-establishment-hold-time 50
set protocols iccp peer 3.3.3.2 redundancy-group-id-list 1
set protocols iccp peer 3.3.3.2 liveness-detection minimum-interval 60
set protocols iccp peer 3.3.3.2 liveness-detection transmit-interval minimum-interval 60

set protocols lldp interface all
set switch-options service-id 2
set vlans GODC1 vlan-id 6
set vlans GODC1 l3-interface irb.6
set vlans iccp vlan-id 99
set vlans iccp l3-interface irb.99






Access Switch configuration


root# show |display set
set version 12.3R6.6
set system root-authentication encrypted-password "$1$Ek0Moath$5eWQXZpXvShoGGzGumYbK/"
set system syslog user * any emergency
set system syslog file messages any notice
set system syslog file messages authorization info
set system syslog file interactive-commands interactive-commands any
set system commit synchronize
set chassis redundancy graceful-switchover
set chassis aggregated-devices ethernet device-count 10
set interfaces ge-0/0/0 description ***connection_coreA***
set interfaces ge-0/0/0 ether-options 802.3ad ae0

set interfaces ge-0/0/1 ether-options 802.3ad ae0
set interfaces ge-1/0/0 description ***Connection_coreB***
set interfaces ge-1/0/0 ether-options 802.3ad ae0
set interfaces ae0 description ***connection_core_Link***
set interfaces ae0 aggregated-ether-options lacp active
set interfaces ae0 unit 0 family ethernet-switching port-mode trunk
set interfaces ae0 unit 0 family ethernet-switching vlan members godc
set interfaces vlan unit 6 family inet address 10.219.11.100/24
set protocols igmp-snooping vlan all
set protocols rstp
set protocols lldp interface all
set protocols lldp-med interface all
set ethernet-switching-options storm-control interface all
set vlans godc vlan-id 6
set vlans godc interface ge-0/0/2.0
set vlans godc l3-interface vlan.6
set poe interface all
set virtual-chassis member 0 mastership-priority 254
set virtual-chassis member 1 mastership-priority 250


{master:0}[edit]
root#

Optimization of fortigate IPS

IPS signature need select according to infrastructure environment  Eg:-  if  we are not have Linux servers this ips signature can disable (d...