SRX210 network configuration example

[edit]
ylara@R1# show | display set

set version 12.1X44-D35.5
set system host-name R1
set system time-zone America/New_York
set system root-authentication encrypted-password “$1$6gNz/e.a$3PwYertOAmvSXeWEYVkKF1”
set system login user ylara uid 2000
set system login user ylara class super-user
set system login user ylara authentication encrypted-password “$1$tWTTA9FV$WTL22E4Hj2JKLEmbODI8i0”
set system services ssh root-login allow
set system services netconf ssh

set interfaces lt-0/0/0 unit 1 encapsulation ethernet
set interfaces lt-0/0/0 unit 1 peer-unit 2
set interfaces lt-0/0/0 unit 1 family inet address 10.1.1.1/24

set interfaces lt-0/0/0 unit 2 encapsulation ethernet
set interfaces lt-0/0/0 unit 2 peer-unit 1
set interfaces lt-0/0/0 unit 2 family inet address 10.1.1.2/24

set interfaces lt-0/0/0 unit 3 encapsulation ethernet
set interfaces lt-0/0/0 unit 3 peer-unit 4
set interfaces lt-0/0/0 unit 3 family inet address 10.2.2.1/24

set interfaces lt-0/0/0 unit 4 encapsulation ethernet
set interfaces lt-0/0/0 unit 4 peer-unit 3
set interfaces lt-0/0/0 unit 4 family inet address 10.2.2.2/24

set interfaces lt-0/0/0 unit 5 encapsulation ethernet
set interfaces lt-0/0/0 unit 5 peer-unit 6
set interfaces lt-0/0/0 unit 5 family inet address 10.3.3.1/24

set interfaces lt-0/0/0 unit 6 encapsulation ethernet
set interfaces lt-0/0/0 unit 6 peer-unit 5
set interfaces lt-0/0/0 unit 6 family inet address 10.3.3.2/24

set interfaces lt-0/0/0 unit 7 encapsulation ethernet
set interfaces lt-0/0/0 unit 7 peer-unit 8
set interfaces lt-0/0/0 unit 7 family inet address 10.4.4.1/24
set interfaces lt-0/0/0 unit 7 family iso

set interfaces lt-0/0/0 unit 8 encapsulation ethernet
set interfaces lt-0/0/0 unit 8 peer-unit 7
set interfaces lt-0/0/0 unit 8 family inet address 10.4.4.2/24
set interfaces lt-0/0/0 unit 8 family iso

set interfaces lt-0/0/0 unit 9 encapsulation ethernet
set interfaces lt-0/0/0 unit 9 peer-unit 10
set interfaces lt-0/0/0 unit 9 family inet address 10.5.5.1/24
set interfaces lt-0/0/0 unit 9 family iso

set interfaces lt-0/0/0 unit 10 encapsulation ethernet
set interfaces lt-0/0/0 unit 10 peer-unit 9
set interfaces lt-0/0/0 unit 10 family inet address 10.5.5.2/24
set interfaces lt-0/0/0 unit 10 family iso

set interfaces lt-0/0/0 unit 11 encapsulation ethernet
set interfaces lt-0/0/0 unit 11 peer-unit 12
set interfaces lt-0/0/0 unit 11 family inet address 10.6.6.1/24
set interfaces lt-0/0/0 unit 11 family iso

set interfaces lt-0/0/0 unit 12 encapsulation ethernet
set interfaces lt-0/0/0 unit 12 peer-unit 11
set interfaces lt-0/0/0 unit 12 family inet address 10.6.6.2/24
set interfaces lt-0/0/0 unit 12 family iso

set interfaces lt-0/0/0 unit 13 encapsulation ethernet
set interfaces lt-0/0/0 unit 13 peer-unit 14
set interfaces lt-0/0/0 unit 13 family inet address 172.16.1.1/24

set interfaces lt-0/0/0 unit 14 encapsulation ethernet
set interfaces lt-0/0/0 unit 14 peer-unit 13
set interfaces lt-0/0/0 unit 14 family inet address 172.16.1.2/24

set interfaces lt-0/0/0 unit 15 encapsulation ethernet
set interfaces lt-0/0/0 unit 15 peer-unit 16
set interfaces lt-0/0/0 unit 15 family inet address 172.16.2.1/24

set interfaces lt-0/0/0 unit 16 encapsulation ethernet
set interfaces lt-0/0/0 unit 16 peer-unit 15
set interfaces lt-0/0/0 unit 16 family inet address 172.16.2.2/24

set interfaces fe-0/0/2 unit 0 family inet address 10.7.7.1/24
set interfaces fe-0/0/2 unit 0 family iso

set interfaces fe-0/0/3 unit 0 family inet address 10.7.7.2/24
set interfaces fe-0/0/3 unit 0 family iso

set interfaces fe-0/0/4 unit 0 family inet address 10.8.8.1/24
set interfaces fe-0/0/4 unit 0 family iso

set interfaces fe-0/0/5 unit 0 family inet address 10.8.8.2/24
set interfaces fe-0/0/5 unit 0 family iso

set interfaces lo0 unit 1 family inet address 192.168.1.1/32

set interfaces lo0 unit 2 family inet address 192.168.2.2/32
set interfaces lo0 unit 2 family iso address 49.0001.0000.1002.0200.00

set interfaces lo0 unit 3 family inet address 192.168.3.3/32
set interfaces lo0 unit 3 family iso address 49.0001.0000.1003.0300.00

set interfaces lo0 unit 4 family inet address 192.168.4.4/32
set interfaces lo0 unit 4 family iso address 49.0001.0000.1004.0400.00

set interfaces lo0 unit 5 family inet address 192.168.5.5/32
set interfaces lo0 unit 5 family iso address 49.0001.0000.1005.0500.00

set interfaces lo0 unit 6 family inet address 192.168.6.6/32
set interfaces lo0 unit 6 family iso address 49.0001.0000.1006.0600.00

set interfaces lo0 unit 10 family inet address 200.200.10.1/32
set interfaces lo0 unit 10 family inet address 200.200.10.2/32

set interfaces lo0 unit 20 family inet address 200.200.20.1/32
set interfaces lo0 unit 20 family inet address 200.200.20.2/32

set routing-options forwarding-table export load-balance

set policy-options policy-statement BGP1 term 1 from protocol direct
set policy-options policy-statement BGP1 term 1 from interface lo0.10
set policy-options policy-statement BGP1 term 1 then accept

set policy-options policy-statement BGP2 term 1 from protocol direct
set policy-options policy-statement BGP2 term 1 from interface lo0.20
set policy-options policy-statement BGP2 term 1 then accept

set policy-options policy-statement ISIS_to_OSPF term 0 from protocol isis
set policy-options policy-statement ISIS_to_OSPF term 0 from tag 100
set policy-options policy-statement ISIS_to_OSPF term 0 then reject
set policy-options policy-statement ISIS_to_OSPF term 1 from protocol isis
set policy-options policy-statement ISIS_to_OSPF term 1 from route-filter 192.168.0.0/16 orlonger
set policy-options policy-statement ISIS_to_OSPF term 1 then tag 200
set policy-options policy-statement ISIS_to_OSPF term 1 then accept
set policy-options policy-statement NHS term 1 then next-hop self

set policy-options policy-statement OSFP_to_ISIS term 0 from protocol ospf
set policy-options policy-statement OSFP_to_ISIS term 0 from tag 200
set policy-options policy-statement OSFP_to_ISIS term 0 then reject
set policy-options policy-statement OSFP_to_ISIS term 1 from protocol direct
set policy-options policy-statement OSFP_to_ISIS term 1 from route-filter 192.168.0.0/16 orlonger
set policy-options policy-statement OSFP_to_ISIS term 1 then tag 100
set policy-options policy-statement OSFP_to_ISIS term 1 then accept
set policy-options policy-statement OSFP_to_ISIS term 2 from protocol ospf
set policy-options policy-statement OSFP_to_ISIS term 2 from route-filter 192.168.0.0/16 orlonger
set policy-options policy-statement OSFP_to_ISIS term 2 then tag 100
set policy-options policy-statement OSFP_to_ISIS term 2 then accept

set policy-options policy-statement load-balance term 1 then load-balance per-packet

set routing-instances CE1 instance-type virtual-router
set routing-instances CE1 interface lt-0/0/0.13
set routing-instances CE1 interface lo0.10
set routing-instances CE1 routing-options autonomous-system 100
set routing-instances CE1 routing-options autonomous-system independent-domain
set routing-instances CE1 protocols bgp group CE1<=>R1 neighbor 172.16.1.2 export BGP1
set routing-instances CE1 protocols bgp group CE1<=>R1 neighbor 172.16.1.2 peer-as 200

set routing-instances CE2 instance-type virtual-router
set routing-instances CE2 interface lt-0/0/0.16
set routing-instances CE2 interface lo0.20
set routing-instances CE2 routing-options autonomous-system 300
set routing-instances CE2 routing-options autonomous-system independent-domain
set routing-instances CE2 protocols bgp group CE2<=>R6 neighbor 172.16.2.1 export BGP2
set routing-instances CE2 protocols bgp group CE2<=>R6 neighbor 172.16.2.1 peer-as 200

set routing-instances R1 instance-type virtual-router
set routing-instances R1 interface lt-0/0/0.1
set routing-instances R1 interface lt-0/0/0.3
set routing-instances R1 interface lt-0/0/0.14
set routing-instances R1 interface lo0.1
set routing-instances R1 routing-options router-id 1.1.1.1
set routing-instances R1 routing-options autonomous-system 200
set routing-instances R1 routing-options autonomous-system independent-domain
set routing-instances R1 protocols bgp group R1<=>R6 multipath
set routing-instances R1 protocols bgp group R1<=>R6 neighbor 192.168.6.6 local-address 192.168.1.1
set routing-instances R1 protocols bgp group R1<=>R6 neighbor 192.168.6.6 export NHS
set routing-instances R1 protocols bgp group R1<=>R6 neighbor 192.168.6.6 peer-as 200
set routing-instances R1 protocols bgp group R1<=>CE1 neighbor 172.16.1.1 peer-as 100
set routing-instances R1 protocols ospf area 0.0.0.0 interface lo0.1
set routing-instances R1 protocols ospf area 0.0.0.0 interface lt-0/0/0.1 point-to-point
set routing-instances R1 protocols ospf area 0.0.0.0 interface lt-0/0/0.3 point-to-point

set routing-instances R2 instance-type virtual-router
set routing-instances R2 interface lt-0/0/0.2
set routing-instances R2 interface lt-0/0/0.5
set routing-instances R2 interface lt-0/0/0.7
set routing-instances R2 interface lo0.2
set routing-instances R2 routing-options router-id 2.2.2.2
set routing-instances R2 protocols ospf export ISIS_to_OSPF
set routing-instances R2 protocols ospf area 0.0.0.0 interface lo0.2
set routing-instances R2 protocols ospf area 0.0.0.0 interface lt-0/0/0.2 point-to-point
set routing-instances R2 protocols ospf area 0.0.0.0 interface lt-0/0/0.5 point-to-point
set routing-instances R2 protocols isis export OSFP_to_ISIS
set routing-instances R2 protocols isis level 1 disable
set routing-instances R2 protocols isis level 2 wide-metrics-only
set routing-instances R2 protocols isis interface lt-0/0/0.7 point-to-point

set routing-instances R3 instance-type virtual-router
set routing-instances R3 interface lt-0/0/0.4
set routing-instances R3 interface lt-0/0/0.6
set routing-instances R3 interface lt-0/0/0.9
set routing-instances R3 interface lo0.3
set routing-instances R3 routing-options router-id 3.3.3.3
set routing-instances R3 protocols ospf area 0.0.0.0 interface lo0.3
set routing-instances R3 protocols ospf area 0.0.0.0 interface lt-0/0/0.4 point-to-point
set routing-instances R3 protocols ospf area 0.0.0.0 interface lt-0/0/0.6 point-to-point
set routing-instances R3 protocols isis export OSFP_to_ISIS
set routing-instances R3 protocols isis level 1 disable
set routing-instances R3 protocols isis level 2 wide-metrics-only
set routing-instances R3 protocols isis interface lt-0/0/0.9 point-to-point

set routing-instances R4 instance-type virtual-router
set routing-instances R4 interface lt-0/0/0.8
set routing-instances R4 interface lt-0/0/0.11
set routing-instances R4 interface fe-0/0/2.0
set routing-instances R4 interface lo0.4
set routing-instances R4 routing-options router-id 4.4.4.4
set routing-instances R4 protocols isis level 1 disable
set routing-instances R4 protocols isis level 2 wide-metrics-only
set routing-instances R4 protocols isis interface lt-0/0/0.8 point-to-point
set routing-instances R4 protocols isis interface lt-0/0/0.11 point-to-point
set routing-instances R4 protocols isis interface fe-0/0/2.0 point-to-point
set routing-instances R4 protocols isis interface lo0.4

set routing-instances R5 instance-type virtual-router
set routing-instances R5 interface lt-0/0/0.10
set routing-instances R5 interface lt-0/0/0.12
set routing-instances R5 interface fe-0/0/4.0
set routing-instances R5 interface lo0.5
set routing-instances R5 routing-options router-id 5.5.5.5
set routing-instances R5 protocols isis level 1 disable
set routing-instances R5 protocols isis level 2 wide-metrics-only
set routing-instances R5 protocols isis interface lt-0/0/0.10 point-to-point
set routing-instances R5 protocols isis interface lt-0/0/0.12 point-to-point
set routing-instances R5 protocols isis interface fe-0/0/4.0 point-to-point
set routing-instances R5 protocols isis interface lo0.5

set routing-instances R6 instance-type virtual-router
set routing-instances R6 interface lt-0/0/0.15
set routing-instances R6 interface fe-0/0/3.0
set routing-instances R6 interface fe-0/0/5.0
set routing-instances R6 interface lo0.6
set routing-instances R6 routing-options router-id 6.6.6.6
set routing-instances R6 routing-options autonomous-system 200
set routing-instances R6 routing-options autonomous-system independent-domain
set routing-instances R6 protocols bgp group R6<=>R1 multipath
set routing-instances R6 protocols bgp group R6<=>R1 neighbor 192.168.1.1 local-address 192.168.6.6
set routing-instances R6 protocols bgp group R6<=>R1 neighbor 192.168.1.1 export NHS
set routing-instances R6 protocols bgp group R6<=>R1 neighbor 192.168.1.1 peer-as 200
set routing-instances R6 protocols bgp group R6<=>CE2 neighbor 172.16.2.2 peer-as 300
set routing-instances R6 protocols isis level 1 disable
set routing-instances R6 protocols isis level 2 wide-metrics-only
set routing-instances R6 protocols isis interface fe-0/0/3.0 point-to-point
set routing-instances R6 protocols isis interface fe-0/0/5.0 point-to-point
set routing-instances R6 protocols isis interface lo0.6

Related posts