Moderator: mike
-
ggcc
- Posts: 24
- Joined: Thu Aug 17, 2017 2:01 am
Post
by ggcc » Wed Sep 13, 2017 2:10 am
Hello Team,
Question: Do you know why Interfaces of Juniper Model: vmx Junos: 14.1R4.8 interface are up even there are no connections?
This cause the issue when two vMX are interconnecting, disable interface on one vMX the other vMX interface is still up.
Example:
vMX1: em2 <---> vMX2:em2
Issue:
When disable interface em2 on vMX1 the interface vMX2:em2 is still up, so traffic is still being sent to vMX2:em2 interface.
Thanks,
Code: Select all
eve@vMX1> show interfaces terse
Interface Admin Link Proto Local Remote
cbp0 up up
demux0 up up
dsc up up
em0 up up
em1 up up
em1.0 up up inet 172.16.0.1/16
inet6 fe80::5200:ff:fe01:1/64
em2 up up
em2.0 up up inet 12.12.12.1/24
em3 up up
em3.0 up up inet 13.13.13.1/24
em4 up up
em5 up up
gre up up
ipip up up
irb up up
lo0 up up
lo0.0 up up inet 1.1.1.1 --> 0/0
lo0.16384 up up inet 127.0.0.1 --> 0/0
lo0.16385 up up inet 128.0.0.1 --> 0/0
128.0.0.4 --> 0/0
inet6 fe80::200:f:fc00:0
lo0.32768 up up
lsi up up
mtun up up
pimd up up
pime up up
pip0 up up
pp0 up up
tap up up
vtep up up
eve@vMX1> show version
Hostname: vMX1
Model: vmx
Junos: 14.1R4.8
JUNOS Base OS Software Suite [14.1R4.8]
JUNOS Base OS boot [14.1R4.8]
Thanks
EVE-NG The BEST Emulation for Networking
ggcc
-
Chris929
- Posts: 83
- Joined: Tue Jun 27, 2017 8:51 am
Post
by Chris929 » Wed Sep 13, 2017 8:05 am
All interfaces are always up except you shut them administratively - but physical will always be up - it's how eve is designed - this is expected behavior
-
mike
- Posts: 135
- Joined: Wed Mar 15, 2017 3:30 pm
Post
by mike » Wed Sep 13, 2017 9:35 am
that is not related to design Chris.
Both vMX connected to the linux bridge, not only vMX, but any node in eve.
That is why when you shutdown one side it won't put the other side into "down".
As a suggestion you can use some keepalive protocols to simulate proper behavior.
-
ggcc
- Posts: 24
- Joined: Thu Aug 17, 2017 2:01 am
Post
by ggcc » Wed Sep 13, 2017 1:49 pm
Hi Mike,
Good suggestion. Thank you for your suggestion about keep alive.
Thanks
EVE-NG The BEST Emulation for Networking
ggcc
-
ggcc
- Posts: 24
- Joined: Thu Aug 17, 2017 2:01 am
Post
by ggcc » Wed Sep 13, 2017 3:21 pm
mike wrote: ↑Wed Sep 13, 2017 9:35 am
that is not related to design Chris.
Both vMX connected to the linux bridge, not only vMX, but any node in eve.
That is why when you shutdown one side it won't put the other side into "down".
As a suggestion you can use some keepalive protocols to simulate proper behavior.
Hi Mike,
Please help.
I have searched how to set interface keepalive on Juniper. However, I could not find the keepalive under set interface for both vSRX and vMX.
Thanks.
Code: Select all
version 12.1X47-D15.4
eve@vSRX3# set interfaces ge-0/0/0 ?
Possible completions:
accounting-profile Accounting profile name
+ apply-groups Groups from which to inherit configuration data
+ apply-groups-except Don't inherit configuration data from these groups
description Text description of interface
disable Disable this interface
encapsulation Physical link-layer encapsulation
flexible-vlan-tagging Support for no tagging, or single and double 802.1q VLAN tagging
> gigether-options Gigabit Ethernet interface-specific options
gratuitous-arp-reply Enable gratuitous ARP reply
> hold-time Hold time for link up and link down
link-mode Link operational mode
mac Hardware MAC address
mtu Maximum transmit packet size (256..9192)
native-vlan-id Virtual LAN identifier for untagged frames (0..4094)
no-gratuitous-arp-reply Don't enable gratuitous ARP reply
no-gratuitous-arp-request Ignore gratuitous ARP request
no-per-unit-scheduler Don't enable subunit queuing on Frame Relay or VLAN IQ interface
no-traps Don't enable SNMP notifications on state changes
passive-monitor-mode Use interface to tap packets from another router
per-unit-scheduler Enable subunit queuing on Frame Relay or VLAN IQ interface
promiscuous-mode Enable promiscuous mode for L3 interface
speed Link speed
stacked-vlan-tagging Stacked 802.1q VLAN tagging support
> switch-options Front end ports configuration
> traceoptions Interface trace options
traps Enable SNMP notifications on state changes
> unit Logical interface
vlan-tagging 802.1q VLAN tagging support
[edit]
version 14.1R4.8
eve@vMX2# set interfaces em3 ?
Possible completions:
accounting-profile Accounting profile name
+ apply-groups Groups from which to inherit configuration data
+ apply-groups-except Don't inherit configuration data from these groups
> auto-configure Auto configuration
description Text description of interface
disable Disable this interface
encapsulation Physical link-layer encapsulation
gratuitous-arp-reply Enable gratuitous ARP reply
> hold-time Hold time for link up and link down
interface-transmit-statistics Interface statistics based on the transmitted packets
> layer2-policer Layer2 policing for interface
link-mode Link operational mode
mac Hardware MAC address
mtu Maximum transmit packet size (256..9192)
> multi-chassis-protection Inter-Chassis protection configuration
no-gratuitous-arp-reply Don't enable gratuitous ARP reply
no-gratuitous-arp-request Ignore gratuitous ARP request
no-traps Don't enable SNMP notifications on state changes
> traceoptions Interface trace options
traps Enable SNMP notifications on state changes
> unit Logical interface
vlan-tagging 802.1q VLAN tagging support
[edit]
Thanks
EVE-NG The BEST Emulation for Networking
ggcc
-
mike
- Posts: 135
- Joined: Wed Mar 15, 2017 3:30 pm
Post
by mike » Wed Sep 13, 2017 5:01 pm
-
Chris929
- Posts: 83
- Joined: Tue Jun 27, 2017 8:51 am
Post
by Chris929 » Wed Sep 13, 2017 8:33 pm
mike wrote: ↑Wed Sep 13, 2017 9:35 am
that is not related to design Chris.
Both vMX connected to the linux bridge, not only vMX, but any node in eve.
That is why when you shutdown one side it won't put the other side into "down".
As a suggestion you can use some keepalive protocols to simulate proper behavior.
That's what i mean with "designed" - this is the way that eve works - between every link in every node there are bridges - there are no point-to-point connections - hence it's always "up". YOur idea with keepalives is good - thank you for that - i never bothered about the "up" state as i use BFD for my IGP's and VPN-Monitoring for my IPSec-Tunnels (Juniper only)