BT Infinity and Juniper SRX Configuration

First time using this community and I have only recently been thrown into the world of Juniper. I bought an SRX210B to use for lab work at home and am trying to get it working with my BT Infinity circuit. The physical link appears up and so does the PPPoE session (from what I can work out) but the logical link is down. Can anyone provide assistance?
interfaces {
ge-0/0/0 {
unit 0 {
encapsulation ppp-over-ether;
ge-0/0/1 {
unit 0 {
description LAB01VMW001;
family ethernet-switching {
port-mode trunk;
vlan {
members [ MGMT DATA VOICE SERVER DMZ ];
native-vlan-id 100;
fe-0/0/2 {
unit 0 {
description LAB01UCM001;
family ethernet-switching {
port-mode trunk;
vlan {
members [ MGMT DATA VOICE DMZ ];
native-vlan-id 100;
fe-0/0/3 {
unit 0 {
family ethernet-switching {
vlan {
members MGMT;
pp0 {
traceoptions {
flag all;
unit 0 {
point-to-point;
ppp-options {
pap {
local-name "[email protected]";
local-password "xxxxxxxxxxxxxxxxxxxxxxx"; ## SECRET-DATA
passive;
pppoe-options {
underlying-interface ge-0/0/0.0;
idle-timeout 0;
auto-reconnect 10;
client;
family inet {
negotiate-address;
vlan {
unit 10 {
family inet {
address 10.10.10.1/24;
unit 20 {
family inet {
address 10.10.20.1/24;
unit 30 {
family inet {
address 10.10.30.1/24;
unit 66 {
family inet {
address 172.16.0.1/24;
unit 99 {
family inet {
address 10.10.99.1/24;
routing-options {
static {
route 0.0.0.0/0 {
next-hop pp0.0;
metric 0;
protocols {
stp;
security {
nat {
source {
rule-set trust-to-untrust {
from zone trust;
to zone untrust;
rule source-nat-rule {
match {
source-address 0.0.0.0/0;
then {
source-nat {
interface;
screen {
ids-option untrust-screen {
icmp {
ping-death;
ip {
source-route-option;
tear-drop;
tcp {
syn-flood {
alarm-threshold 1024;
attack-threshold 200;
source-threshold 1024;
destination-threshold 2048;
timeout 20;
land;
zones {
security-zone trust {
host-inbound-traffic {
system-services {
all;
protocols {
all;
interfaces {
vlan.10;
vlan.99;
vlan.30;
vlan.20;
security-zone untrust {
screen untrust-screen;
interfaces {
ge-0/0/0.0 {
host-inbound-traffic {
system-services {
dhcp;
tftp;
pp0.0 {
host-inbound-traffic {
system-services {
all;
policies {
from-zone trust to-zone untrust {
policy trust-to-untrust {
match {
source-address any;
destination-address any;
application any;
then {
permit;
vlans {
DATA {
description DATA;
vlan-id 10;
l3-interface vlan.10;
DMZ {
description DMZ;
vlan-id 66;
l3-interface vlan.66;
HOLE {
description Blackhole;
vlan-id 100;
MGMT {
description MGMT;
vlan-id 99;
l3-interface vlan.99;
SERVER {
description SERVER;
vlan-id 30;
l3-interface vlan.30;
VOICE {
description VOICE;
vlan-id 20;
l3-interface vlan.20;

All sorted by BT engineer. Super fast broadband download and BT vision up and running perfect.

Similar Messages

  • IPSEC between Cisco ASR1002 and Juniper SRX.

    Hello everyone,
    While trying to setup my ipsec sesion with the devices mentioned above without success, I found that there are differents ways to face the configuration for each device:
    On the cisco side, I can do:
    a)_Crypto-map based configuration, or
    b)_ VTI based configuration.
    On the juniper side, there is:
    a)Route based tunnel config and,
    b)_Policy based tunnel config.
    I wonder wich is the better combination? The one that both devices are more compatible.
    Also if someone can provide any example to follow would bee great.
    Any help would be preciated,
    Rgrds,
    Leo.

    I dont't know Junipter config, but for Cisco it should be crypto-map, Juniper could be policy based.
    Michael
    Please rate all helpful posts

  • Cisco ACS 5.1 Tacacs with Juniper Srx 210

    Hi all,
    I am trying to do authentication for Juniper SRX 210 FW With Cisco ACS 5.1 Tacacs but I am unable to acheive it ..
    Can any one help me how to add Junos service in ACS 5.1..How to Intergarte Juniper SRX 210 in Cisco ACS 5.1

    Hello Pranav
    As Nicolas said, you really need to know what attributes Juniper SRX is using. It also depends on what you're looking for, for example it's very different "password authentication" from "command authorization". I answered a similar question here https://supportforums.cisco.com/thread/2111466
    You don't need to enable any new service. ACS is capable to attend any TACACS (or RADIUS) device as long as you tell ACS what are the TACACS (or RADIUS) attributes needed for that device.
    This is an example in which I have configured ACS 5.x with an attribute called "local-user-name" which JunOS router use for authentication. For that you need to go to "Policy Elements > Authorization and Permissions > Device Administration > Shell Profiles".
    If you don't know the attributes you can capture the packets and troubleshoot from Juniper cli and from "ACS view" side. That's how I find out the "local-user-name" attribute.
    Please rate if it helps. Kind regards

  • Cisco APs get disconnected from cisco WLC after 30 min when connected on Juniper SRX

    Hi,
    I am connecting all my Cisco 1131AG APs via Juniper SRX 240 box and Cisco WLC is placed in the LAN.
    We are running LWAPP in layer 3 mode. The APs get dissassociated form the WLC after 30 min.
    The Setup is like :-
    AP->AccessSwitch-->JuniperSRX(reth2.0)-->JuniperSRX(reth1.0)-->CoreSwitch-->CiscoWLC
    could anyone please help me to resolve this issue.

    Firmware for WLC is AIR-WLC4400-K9-4-2-99-0
    Firmware for AP is 12.4(10b)JA1
    The logs form WLC during disconnection :-
    Mon Sep 6 20:05:52 2010 AP Disassociated. Base Radio MAC:00:1f:ca:2d:4e:a0
    1 Mon Sep 6 20:05:52 2010 AP's Interface:0(802.11b) Operation State Down: Base Radio MAC:00:1f:ca:2d:4e:a0 Cause=Heartbeat Timeout
    2 Mon Sep 6 20:05:51 2010 AP Disassociated. Base Radio MAC:00:1f:9e:c1:0d:30
    3 Mon Sep 6 20:05:51 2010 AP's Interface:0(802.11b) Operation State Down: Base Radio MAC:00:1f:9e:c1:0d:30 Cause=Heartbeat Timeout

  • Juniper SRX VPN Profile

    I am unable to fully establish a VPN connection between my Blackberry Passport (SQW100-1) using OS 10.3.2.2239 and my Juniper SRX210H using JUNOS Software Release 12.1X44-D45.2. Both Phase 1 and Phase 2 seem to complete and the Blackberry displays the green connected icon in the VPN Setting screen however I cannot pass traffic and after the DPD timeout the gateway disconnects. Further investigation revealed that I am not getting a proper IP or Subnet and also not getting the DNS information from the gateway. Also, on the SRX side, immediately after successfully completing the IPSec negotiation the SRX sends an ike_send_notify packet to the Blackberry which never seems to be received. It retransmits several times, but eventually times out. On the Blackberry I'm using the Juniper IPSec VPN (SRX Series) profile with XAUTH-PSK as the authentication type and all of the settings match on both sides.  I believe the issue is in the XAUTH communication since that is the part that doesn't seem to be completing (No DNS or IP Address). I was able to find a discussion regarding a change in JUNOS handling of XAUTH from another IPSec client mailing list.  I'm wondering if Blackberry updated their VPN profile to conform to this change. Can anyone confirm that BB10 can establish a VPN to a Juniper SRX using a modern version of JUNOS? 

    Something interesting. I confirmed my tcp-mss setting on my juniper SRX (software version 12.1x44D35.5) is at 1350 per recommendation.
    I decide to test packet size.  and ping from on premise to Azure vm packet size of 1400 succeeds.   Ping of 1400 from azure to on premise fails.  packet size of 1399 succeeds from azure to on premise.   Why would this be? 
    And is it the problem that is causing my intermittent connection issues?  
    Fred Zilz

  • BT Infinity and DD-WRT (Other Routers)

    Hi, 
    How can I setup BT Infinity with DD-WRT (Linksys WRT54G-TM). A lot of things say just put in PPPoE Username and It'll configure, but I think I'm missing something. 
    Thanks for the Help 

    Hi have you connected the linksys to the homehub2 using ethernet and if so would the linksys with dd-wrt allow you to use Wake on Lan over the internet? I am trying to wake a pc from outside of my lan and bthomehub doesnt support this but routers with dd-wrt do, have you tried this at all?

  • BT Infinity and Zyxel Powerline Adapters - connect...

    Hi,
    I recently upgraded the Infinity and also moved house. So now I have the HH3 with BT Infinity. I use Zyxel Powerline adapters, but struggling to get a connection. 
    I'm using the following to connect to the HH3 http://www.zyxel.com/uk/en/products_services/pla4225.shtml?t=p and connecting through the Giga or Ethernet inputs on the back of the HH3 but when I try to connect my PC/Laptop to the Powerline adapter in my bedroom it cannot find the network.
    Any thoughts? Should I be connecting the Powerline Adapter to the HH3 or the white router BT supply? Do I need to configure something when setting up the Ethernet connection with my PC? I'm using my BT account credentials [email protected] and password but it's not connecting.
    Any inspiration/experimentation welcomed.
    Thanks.

    Should I be connecting the Powerline Adapter to the HH3 or the white router BT supply?
    Do I need to configure something when setting up the Ethernet connection with my PC? I'm using my BT account credentials [email protected] and password but it's not connecting.
    Normally, connect one powerline to the HomeHub and the other to the PC.  If the PC has been set up in the standard way, it will then get a local ip address by DHCP from the HomeHub.  You might go to your PC ethernet adaptor settings and make sure they are set up for 'dhcp' and 'get DNS setttings automatically'.   You won't need to enter any credentials in the PC for this method.  You shouldn't go near the 'connect to the internet' dialog; it should just work automatically.
    If you only want to connect a single PC, you could connect the first powerline to the white modem and leave out the HH3 completely.  You would then need to put credentials into the PC: the normal thing there is to enter user '[email protected]', and the password doesn't matter.  That goes into a 'connect to the internet' dialog.
    Make sure the 'internet' or whatever lights are blinking on both powerlines, otherwise there is a problem with those, or  the bedroom ring is not connected closely enough to the other ring.  Unlikely, I had a perfectly good connection through different rings and different fuse boxes on different floors with similar zyxel powerline (only single ethernet ones); at least until one stopped working altogether.

  • BT Infinity and to VOIP

    i am new to infinity and whilst having a "chat" with zara on the bt website i was invited to chat and discuss my broadband needs. i had orange livebox, unlimited calls and unlimited voip calls via a bt phone in the livebox/router. zara explained i would still have the facility to make international calls (australia) with my new infinity hub. i cancelled my free internet service from orange and ported over...when the hub 3 was fitted the engineer told me there is no way you can make a call via hub??? who do i complain to because the muppets i speak to in delhi bangaloor and phuket are hopeless and promise to call at given times to resolve this matter but never do. i was clkearly mis sold this service (i printed the chat history which states calls can be made via hub)
    q can i insist they resolve this and or provide the means to make calls via my new hub?
    q2 could i piggy back my livebox router via the phone line if bt configure this....can that be done
    i am fuming and would appreciate some feedback
    yours
    steve

    The quick answer is no. The livebox is an ADSL router which will only work on that type of line.
    This is an all to common problem, I would rarely trust call centres with this type of enquiry! And unless you have retained an orange broadband account, access to second line will cease anyway.

  • BT Infinity and Gmail

    Hi,
    We have two wifi internet lines in our house, one BT Infinity and one with another provider.
    I use Outlook 2003 as my email client, in pop3 mode.
    I have configured my Outlook 2003 client with my Gmail account, using the setting suggested by Gmail.
    Using BT Infinity, surfing etc works fine, however there is a problem with my Gmail account and Outlook.
    When I connect to our other wifi network, with another ISP, Outlook 2003 works fine with my Gmail account.  
    If I then switch to my BT Infinity wifi network (using the provided home hub), Outlook cannot now connect to Gmail, nagging me to input my correct username and password.
    If I then log back in to our other wifi network, Outlook again works fine with Gmaiil.
    Why is BT Infinity causing this problem?

    Its going to take a few days, as all the tasks associated with your new service, have to be closed by all the departments.
    With the Bank Holiday, its goint to take an extra day as well.
    Just use your gmail address for now, you will be given the opportunity to use a BT one, a bit later on. You can then change your login e-mail address to the btinternet one.
    There are some useful help pages here, for BT Broadband customers only, on my personal website.
    BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones.

  • I want to set up the Time Machine and I would love to use the Time  Capsule but since I already have a wireless router I need suggestions on  what other external disks Apple could recommend to use with the Time Machine and  how to configure that disk

    I want to set up the Time Machine and I would love to use the Time
    Capsule but since I already have a wireless router I need suggestions on
    what other
    external disks Apple could recommend to use with the Time Machine and
    how to configure that disk.
    A complication that I need to resolve is the fact that I am using Vmware
    Fusion to be able to use Windows on my Mac. Now it seems that Time
    Machine is not backing up my files
    on that virtual Windows without additional configuration and my question
    is whether you can advise me here or whether this is only a matter for
    the Fusion virtual machine.

    If you want to use Time Capsule you can.. you simply bridge it and plug it into the existing router.. wireless can be either turned off or used to reinforce the existing wireless.. eg use 5ghz in the TC which is much faster than your 2.4ghz.
    You can also use a NAS.. many brands available but the top brands are synology, qnap and netgear readynas  series. These will all do Time Machine backups although how well always depends on Apple sticking to a standard. There are cheaper ones.. I bought a single disk zyxel which was rebadged and sold through my local supermarket. It actually works very well for TM at least on Snow Leopard. Major changes were made in Lion and again ML so do not instantly think it will work on later versions. I haven't tried it yet with those versions.
    Any external drive can be plugged into the mac. Use the one with the fastest connection or cheapest price according to your budget. USB2 drives are cheap and plentiful. But no where near as fast as USB3 or FW800. So just pick whichever suits the ports on your Mac. Interesting Apple finally moved to USB3 on their latest computers.
    TM should exclude the VM partition file.. it is useless backing it up from Mac OS side.. and will slow TM as it needs to backup that partition everyday for no purpose.. TM cannot see the files inside it to backup just the changes.
    You need to backup windows from windows. Use MSbackup to external drive.. if you have pro or ultimate versions you can backup to network drive. But MSbackup is a dog.. at least until the latest version it cannot restore the partition without first loading windows. There are about a zillion backup software versions for windows.. look up reviews and buy one which works for you. I use a free one Macrium Reflect which does full disk backups and is easy to restore.. to do incremental backups though you have to pay for it.

  • What are some of the best iOS apps can remotely played videos, audios, photos and text files from a NAS hdd connected to Airport Extreme USB port? And how to configure this setup?

    I have already set up NAS hdd as connecting it at USB port of Airport Extreme, i also want to remotely access it from iPhone, so what's the next step? What are some of the best iOS apps can remotely played videos, audios, photos and text files from the NAS hdd and how to configure this setup?

    *Edit - I am not able to connect to the NAS when hardwired to the airport extreme.

  • Infinity and online gaming

    Hello
    I am relativly new to infinity and was wondering if anyone could tell me why its so bad for online gaming?
    My download speeds are virtually always 37.5mb download and between 8 - 9mb upload although upload drops sometmimes to slightly lower 
    http://www.speedtest.bbmax.co.uk/results.php?t=1333920063&v=15486878
    http://www.speedtest.bbmax.co.uk/results.php?t=1333920583&v=15486955
    however i always get loads of lag when playing on xbox live, to the point it is not worth playing, it gets worse than when I was on normal copper wire broadband.
    I have also noticed that there is quite a delay before web pages open when browsing the internet in general, my ping used to be pretty consistent at around 17 - 20ms before I switched to infininty but now seems to jump around lot even going as high as 300ms on occasion.
    my line profile seems to have set at 38.10mb which I am happy with, and the engineer who installed my infinity said that my line stats were excellent.
    all this said then why do i seem to be suffering when using xbox live??

    Hi Cameron
    No I have been trying it with the wireless disabled, although on our old connection this wasnt an issues, myself and my son could both use our xboxs together on the one connection and still it was better than at presen
    I didnt have the cable in the gigabyte port, I have now though, what does this port do?
    Yes port forwarding set to xbox live

  • What's the implicit joins and how to configure it?

    Hello guys
    what's the implicit joins and how to configure it? What's the purpose of implicit and explicit joins?
    Please help
    Thank you

    Thus, on my side, I think that :
    Explicit join define the join condition between the key column from the table.
    (table1.di = table2.id)
    While
    Implicit Join define :
    * the type of join outer, inner, ...
    http://gerardnico.com/wiki/dw/join/start
    * And the relationship (one-to-many, cardinality)
    http://gerardnico.com/wiki/dw/data_quality/relationships
    And all this information are used to generate the statement (query).
    And I don't really know why you have two type of key :
    * Physical Foreign Keys
    * Logical Foreign Keys
    Regards
    Nico

  • HT3546 I have been unsuccessfully trying to extend the wifi of my Time 2T Capsule with an Airport Extreme 2nd Gen. It works for a while and then loses configuration. I have done everything possible, disconnected it, reset it but it keeps failing, what to

    I have been unsuccessfully trying to extend the wifi of my Time 2T Capsule with an Airport Extreme 2nd Gen. It works for a while and then loses configuration. I have done everything possible, disconnected it, reset it but it keeps failing, what to do?

    What model and firmware is the 2TB TC?
    What firmware is the AE?
    Does the AE get good signal from the TC in its current location?
    Signal can only be extended that is received intact.
    Is it extending on 5ghz? As I remember it a Gen2 AE is only single band, although you can choose either 2.4ghz or 5ghz.
    I am fairly sure you are going to tell me your TC is AC model..
    I would do a couple of things..
    1. Fix the wireless name, make it short, no spaces and pure alphanumeric.
    2. Fix the wireless channel for 2.4ghz so it is not going to jump around.
    3. Get real results from the AE in its current location for signal strength.. this is really only possible on v5 utility. And that is a double pain with Mavericks because you cannot use it.
    Apple have removed all the useful diagnostics from the airport utility. There is next to nothing left. So you need to use the computer and its diagnostics to find signal levels in the location.
    http://support.apple.com/kb/HT5606

  • Getting problem while installing Snow Leopard (10.6.3) on my Mac Mini. The following issue is showing :  "mac os x snow leopard cannot be installed on this computer"  And My Mac Configuration details:  Model Name: Mac Mini Model Identifier: Macmini2,1

    Getting problem while installing Snow Leopard (10.6.3) on my Mac Mini. The following issue is showing : 
    "mac os x snow leopard cannot be installed on this computer" 
    And My Mac Configuration details:  Model Name: Mac Mini Model Identifier: Macmini2,1
    Intel Core 2 Duo
    1.83Ghz
    l2Cache: 2mb
    Memory : 2GB
    Bus Speed: 667MHz
    Please help me......
    Thanks

    Actually i have Mac OS X 10.5.4 DVD, I need to upgrade it to Snow Loepard(OS X 10.6)...
    Please suggest me what to do???
    Thanks

Maybe you are looking for