Short step-by-step screenshot guide for an initial configuration of NSRP of two Juniper ScreenOS firewalls, such as the SSGs. One screenshot pack for the http GUI and another one for the Network and Security Manager (NSM) since I am always searching for the positions of the commands on it. Finally, I am listing the appropriate CLI commands.
The following commands have two HA interfaces configured (eth0/0 and eth0/1). Furthermore, two monitored interfaces were configured: eth0/8 and eth0/9.
GUI
SSG140, 6.3.0r17.0:
data:image/s3,"s3://crabby-images/83acc/83acc0ebc022e732bc99077c97f77b88e0ccf62e" alt="Juniper SSG NSRP GUI 01 Interfaces HA"
data:image/s3,"s3://crabby-images/c2e75/c2e75d1686ddab113c9da066715c769da44de23c" alt="Juniper SSG NSRP GUI 02 Cluster"
data:image/s3,"s3://crabby-images/3a4c7/3a4c70dda5c5560def9d571c95cc4949af6a0b38" alt="Juniper SSG NSRP GUI 03 VSD Group"
data:image/s3,"s3://crabby-images/0e1b2/0e1b2cd8934a4a4a0596270657bd50d14f73087e" alt="Juniper SSG NSRP GUI 04 Monitor Interface"
data:image/s3,"s3://crabby-images/9875b/9875b2891edd0cbb8375e29d7eb4416271890335" alt="Juniper SSG NSRP GUI 05 Link"
data:image/s3,"s3://crabby-images/4c1cf/4c1cf0217a13b53db379bb197278587cea341a33" alt="Juniper SSG NSRP GUI 06 Synchronization"
NSM
Version 2012.R3:
data:image/s3,"s3://crabby-images/7fedd/7fedd3c9a7b8c4ce9a149c8138a864778aa4d736" alt="Juniper SSG NSRP NSM 01 Interfaces HA"
data:image/s3,"s3://crabby-images/cdbd4/cdbd433c515ecdf46912643253943d5e6369f322" alt="Juniper SSG NSRP NSM 02 NSRP General"
data:image/s3,"s3://crabby-images/25a34/25a3485e963101d8a8fc44c117254e24d90e7711" alt="Juniper SSG NSRP NSM 03 NSRP RTO Mirror"
data:image/s3,"s3://crabby-images/991e8/991e8597151b4b7b6a8cf8958674244e502b8d89" alt="Juniper SSG NSRP NSM 04 NSRP VSD Group Info"
data:image/s3,"s3://crabby-images/a7f44/a7f44378bc20200866cc1569aad3780b96d72e72" alt="Juniper SSG NSRP NSM 05 NSRP Cluster Member Info"
data:image/s3,"s3://crabby-images/4c6e9/4c6e96f09aab9b1451254e1d965cafa3187d749f" alt="Juniper SSG NSRP NSM 06 NSRP Cluster Member Monitoring"
CLI
NSRP commands on the master device:
set interface "ethernet0/0" zone "HA" set interface "ethernet0/1" zone "HA" set nsrp cluster id 1 set nsrp rto-mirror sync set nsrp rto-mirror route set nsrp rto-mirror session ageout-ack set nsrp vsd-group id 0 priority 50 set nsrp vsd-group id 0 preempt set nsrp encrypt password hBsm8xVGdpqusGT set nsrp auth password cGvVjn5gYUF2yJK set nsrp secondary-path ethernet0/8 set nsrp monitor interface ethernet0/8 set nsrp monitor interface ethernet0/9
Links
- Juniper: Basic configuration steps of Active/Passive High Availability (NSRP)
- Juniper: How to configure NSRP options: secondary path, hb-interval, auth password, encrypt password, master-always-exist, link-up-on-backup
- Juniper: Conditions to use the ‘set nsrp ha-link probe’ command
- Juniper Help: NSRP Session Synchronization
- Juniper: HA LED remains green in Backup with “set nsrp rto-mirror session non-vsi”