Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Configuration of SRX Series Devices and EX Series Switches

As discussed in Use Case # 1: Configuring Juniper Connected Security, Juniper Connected Security can be deployed in three ways, as shown in Figure 1:

Figure 1: Juniper Connected Security Implementation OptionsJuniper Connected Security Implementation Options

Table 1 provides more detail on these deployment options.

Table 1: Supported Topologies for Juniper Connected Security

Topology 1

Topology 2

Topology 3

EX Series or QFX Series device as Layer 2 switch

EX Series or QFX Series device (access switch) as Layer 2 switch

EX Series or QFX Series device (aggregation switch) as Layer 3 switch

EX Series or QFX Series device as Layer 2/Layer 3 switch

SRX Series device as firewall in Layer 3 mode

SRX Series device as firewall in Layer 3 mode

SRX Series device as firewall in Layer 3 mode

IRB / VLAN tagging on SRX Series device

IRB / VLAN tagging on EX Series or QFX Series device (aggregation switch)

IRB / VLAN tagging on EX Series or QFX Series switch

Configuration files for each topology are provided below.

Note:

These configurations are captured from a lab environment, and are provided for reference only. Actual configurations may vary based on the specific requirements of your environment.

Configuration Files for Topology #1

SRX Series Firewall Configuration

EX4300 Access Switch Configuration

EX2200 Switch Configuration

Note:

In this topology, the EX2200 switch acts as a simple default gateway to the Internet. It does not play any role in the Juniper Connected Security solution.

Configuration Files for Topology #2

SRX Series Firewall Configuration

EX4300-1 Access Switch Configuration

EX4300-2 Access Switch Configuration

EX2200 Aggregation Switch Configuration

EX2200 Internet Gateway Switch Configuration

Note:

In this topology, the EX2200 switch acts as a simple default gateway to the Internet. It does not play any role in the Juniper Connected Security solution.

Configuration Files for Topology #3

SRX Series Firewall Configuration

EX4300 Access Switch Configuration

EX2200 Internet Gateway Switch Configuration

Note:

In this topology, the EX2200 switch acts as a simple default gateway to the Internet. It does not play any role in the Juniper Connected Security solution.