Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Full Stack Design for SRX Series Firewalls

The Juniper® SD-WAN driven by Mist AI™ Full Stack design example is a follow-up to the Mist WAN Assurance deployment for SRX Series Firewalls. For more details, see WAN Assurance Configuration Overview.

Overview

With this configuration example, you’re expanding network capabilities by integrating Mist APs and Juniper EX Switches. This full stack example shows you how to set up your Juniper SD-WAN SRX Series WAN edge devices in concert with Juniper EX Series Switches deployed in wired assurance. This brings all your network devices into a cohesive onboarding, monitoring, and troubleshooting dashboard.

The example begins at the highest level of WAN assurance, focusing on SRX Series Firewalls. We assume that you already deployed SRX Series Firewall in a hub and spoke network. The SRX Series Firewall serves as the WAN edge device and foundation for building out your entire network.

For this full-stack design, you'll need at least one Juniper EX Switch to onboard into the Mist cloud. If you plan to do advanced testing with virtual circuits, two EX Switches is ideal. Additionally, you can incorporate a Mist AP into the setup to enhance the wireless capabilities of the network. Integrating APs and switches into your LAN network for management by Mist allows effortless monitoring and control of WAN edge devices, switches, and APs via the Juniper Mist portal dashboard.

Figure 1 shows the Full Stack Juniper Mist WAN Assurance topology used in this example.

Figure 1: Juniper® Mist Validated Design - Mist WAN Assurance with Wireless and Wired Assurance Juniper® Mist Validated Design - Mist WAN Assurance with Wireless and Wired Assurance

Requirements

To get started, you’ll need to alter some of the interfaces configured on SRX Series Firewall for WAN deployment. In this example, we'll change interfaces using WAN edge templates. You can find the details on WAN edge templates here: Configure WAN Edge Templates for SRX Series Firewalls.

In addition, this example uses:

  • Desktop3 VM (VLAN1077) - Operates as a viewer for the Raspberry Pi, the wireless client. Alternatively, you could use a local notebook.
  • Desktop1 VM (VLAN1099) - Connected to the interface ge-0/0/0 of the new branch switch.

Create a New Spokes Configuration Template

To create a new spokes configuration quickly and efficiently, you can clone the template for an existing spoke and then make the necessary changes. It makes things much easier.

  1. In the Juniper Mist™ portal, click Organization > WAN > WAN Edge Templates.
    Figure 2: Navigate to WAN Edge Template Navigate to WAN Edge Template
    Note:

    You can create a template by importing the shared JSON file also.

    A list of existing templates, if any, appears.
    Figure 3: List of WAN Edge Templates List of WAN Edge Templates

    Create a spoke template by cloning an existing spoke template.

  2. Click More and select Clone.
    Figure 4: Selecting Clone Option for Template Selecting Clone Option for Template
  3. Enter the name as Spokes-with-Switch and click Clone.
    Figure 5: Saving Cloned Template Saving Cloned Template
    Tip:

    Refresh your browser after cloning. This ensures objects displayed are truly refreshed.

Edit the LAN Interface

  1. On the LAN interface configuration section, edit the existing interface (LAN1).
    Figure 6: LAN Interface Configuration on Template LAN Interface Configuration on Template
    Change the name of LAN1 interface as SPOKE-LAN1 and apply following changes:
    Figure 7: Modify LAN Interface Configuration Modify LAN Interface Configuration
    • Interface—ge-0/0/5, ge-0/0/6.
    • Port Aggregation—Enable.
    • Enable Force Up—Enable. We recommend this configuration when the switch has no dedicated OOB interface in the LAG and using in-band managed interface. This setting prevents the switch from losing the connection to the Juniper Mist Cloud
    • AE Index—0 (as there is no LAG port enabled).
  2. Continue to configure the SPOKE-LAN1 interface:
    Figure 8: Modify LAN Interface Configuration Modify LAN Interface Configuration
    • Untagged VLAN—Yes. This setting enables VLAN access/native to handout DHCP-leases to the switch. Otherwise, set the site variable {{SPOKE_LAN1_VLAN}} to “0” to have the same results.

    • DHCP—Server

    • IP Start—{{SPOKE_LAN1_PFX}}.100

    • IP End—{{SPOKE_LAN1_PFX}}.199

    • Gateway—{{SPOKE_LAN1_PFX}}.1

    • DNS Servers—8.8.8.8, 9.9.9.9

  3. Figure 9shows the LAN interface you modified.
    Figure 9: Summary of LAN Interface Summary of LAN Interface
  4. Click Save to save your changes.
    Figure 10: Saving WAN Edge Template Saving WAN Edge Template

Assign the New Template to a Site

  1. Scroll to the top of the WAN Edge Templates page and click Assign to Sites under Spokes panel.
    Figure 11: Assign Spoke Templates to Sites Assign Spoke Templates to Sites
  2. In the Assign Template to Sites pane, select spoke1-site template and click Apply.
    Figure 12: Select Sites to Assign Spoke Templates Select Sites to Assign Spoke Templates
  3. Review the template settings as shown in Figure 13.
    Figure 13: Details of WAN Edge Template Details of WAN Edge Template

Add Your Switch to the Topology

Now it is time to onboard your switch and add it to your infrastructure. For details on how to onboard your switch, refer to the product documentation for your switch in the Juniper TechLibrary.

For details on getting a new cloud-ready EX switch up and running in the Juniper Mist AI cloud portal, see Cloud-Ready EX and QFX Switches with Mist.

To assign a switch to a site:

  1. In the Juniper Mist portal, click Organization > Admin > Inventory.
    Figure 14: Navigating to Inventory Navigating to Inventory
  2. In the Inventory page, ensure the inventory view is set to org (Entire Org) and refresh your browser until you see all your devices.
    Figure 15: EX Series Switch in Inventory EX Series Switch in Inventory
  3. Select your new switch and click Assign to Site.
  4. On the Assign Switches page:
    • Select the spoke1-site.
    • Disable Manage configuration with Mist option. You can enable this option at a later stage if required.
    Figure 16: Selecting Site for Assigning Switch Selecting Site for Assigning Switch
  5. Click Assign to Site.
  6. Confirm the changes in the inventory once you assign the device to the site.

    You can see spoke1-site under New Site.

    Figure 17: Assigned Switch to Site Details Assigned Switch to Site Details
  7. In the Juniper Mist portal, go to Switches and select spoke1-site.
    Figure 18: Selecting Assigned Switch for Modification Selecting Assigned Switch for Modification
    The page displays the list of switches assigned to the site.
  8. Click the required switch to open the switch configuration page.
  9. Verify the device name, then scroll down to Switch Configuration section and check Enable Configuration Management.
    Figure 19: Configuration of Assigned Switch Configuration of Assigned Switch
  10. Under Port Configuration, click Add Port Range.
    Figure 20: Port Configuration of Assigned Switch Port Configuration of Assigned Switch
  11. In the New Port Range page, configure the following options:
    • Enable Port Aggregation.

    • Set AE Index to 0 to ensure that the AE index is the same on both sides.

    • Set the Port IDs as ge-0/0/1 and ge-0/0/2 ( two ports for the LAG).

    • Select the existing Configuration Profile as Uplink.

    Figure 21: Port Configuration of Assigned Switch Port Configuration of Assigned Switch
  12. Figure 20 shows the summary of port configuration.
    Figure 22: Port Configuration of Assigned Switch Port Configuration of Assigned Switch
  13. Save your changes.
    Figure 23: Save Changes Save Changes
You’ve now added a Juniper switch to your Mist WAN Assurance deployment.
Optionally, you can confirm your switch has the two links towards SRX Series Firewall using Remote Shell as shown in the following sample: