Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (J-Web)
- Enabling clusters
See Step 1 in Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (CLI).
- Management interface
See Step 2 in Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (CLI).
- Fabric interface
See Step 3 in Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (CLI).
- Redundancy groups
- Select Configure>System Properties>Chassis Cluster.
- Enter the following, then click Apply:
- Redundant ether-Interfaces Count: 2
- Heartbeat Interval: 1000
- Heartbeat Threshold: 3
- Nodes: 0
- Group Number: 0
- Priorities: 254
- Enter the following, then click Apply:
- Nodes: 0
- Group Number: 1
- Priorities: 254
- Enter the following, then click Apply:
- Nodes: 1
- Group Number: 0
- Priorities: 1
- Enter the following, then click Apply:
- Nodes: 1
- Group Number: 1
- Priorities: 1
- Preempt: Select the check box.
- Interface Monitor—Interface: xe-5/0/0
- Interface Monitor—Weight: 255
- Interface Monitor—Interface: xe-5/1/0
- Interface Monitor—Weight: 255
- Interface Monitor—Interface: xe-17/0/0
- Interface Monitor—Weight: 255
- Interface Monitor—Interface: xe-17/1/0
- Interface Monitor—Weight: 255
- Redundant Ethernet interfaces
- Select Configure>System Properties>Chassis Cluster.
- Select xe-5/1/0.
- Enter the following:
- Redundant Parent: reth1
- Click Apply.
- Select xe-17/1/0.
- Enter the following:
- Redundant Parent: reth1
- Click Apply.
- Select xe-5/0/0.
- Enter the following:
- Redundant Parent: reth0
- Click Apply.
- Select xe-17/0/0.
- Enter the following:
- Redundant Parent: reth0
- Click Apply.
- For last four configuration settings of Step 5, see Step 5 in Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (CLI).
- IPsec configuration
- Static routes
- Select Configure>Routing>Static Routing.
- Click Add.
- Enter the following, then click Apply:
- Static Route Address: 0.0.0.0/0
- Next-Hop Addresses: 10.2.1.1
- Enter the following, then click Apply:
- Static Route Address: 10.3.0.0/16
- Next-Hop Addresses: 10.10.1.2
- Security zones
- Security policies
Related Topics
- JUNOS Software Feature Support Reference for SRX Series and J Series Devices
- Understanding Active/Passive Chassis Cluster Deployment with an IPsec Tunnel
- Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (CLI)
- Understanding What Happens When Chassis Cluster Is Enabled
- Understanding Chassis Cluster Formation