Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

Chassis Cluster Dual Control Links

date_range 27-Mar-25

Dual control links provide a redundant link for controlling network traffic.

Use Feature Explorer to confirm platform and release support for specific features.

Review the Platform-Specific Dual Control Links Behavior section for notes related to your platform.

Dual Control Link Connections for SRX Series Firewalls in a Chassis Cluster

You can connect two control links between SRX5600 devices and SRX5800 devices, effectively reducing the chance of control link failure.

Note:

Junos OS does not support dual control links on SRX5400 devices, due to the limited number of slots.

For SRX5600 devices and SRX5800 devices, connect two pairs of the same type of Ethernet ports. For each device, you can use ports on the same Services Processing Card (SPC), but we recommend that you connect the control ports to two different SPCs to provide high availability. Figure 1 shows a pair of SRX5800 devices with dual control links connected. In this example, control port 0 and control port 1 are connected on different SPCs.

Figure 1: Dual Control Link Connections (SRX5800 Devices)Dual Control Link Connections (SRX5800 Devices)

For SRX5600 devices and SRX5800 devices, you must connect control port 0 on one node to control port 0 on the other node. You must also connect control port 1 on one node to control port 1 on the other node. If you connect control port 0 to control port 1, the nodes cannot receive heartbeat packets across the control links.

Platform-Specific Dual Control Links Behavior

Use Feature Explorer to confirm platform and release support for specific features.

Use the following table to review platform-specific behaviors for your platform.

Platform

Difference

SRX Series

  • SRX5600 and SRX5800 Firewalls that support dual control links, use the show chassis hardware command to see the serial number and the hardware version details of the second Routing Engine.

    You must use a second Routing Engine for each device in a cluster when using dual control links. The second Routing Engine initializes the switch on the Switch Control Board (SCB) but does not provide backup functionality. The second Routing Engine must be running Junos OS. For more information, see knowledge base article KB30371.

Change History Table

Feature support is determined by the platform and release you are using. Use Feature Explorer to determine if a feature is supported on your platform.

Release
Description
20.4
Starting with Junos OS Release 20.4R1, you can enable or disable the control links on SRX1500 Services Gateways using operational mode CLI commands and configuration mode CLI commands, described in a subsequent paragraph. This CLI feature enables you to control the status of cluster nodes during a cluster upgrade.
footer-navigation