Jump to content

Не идет трафик через NS5200


Очень с трудом мы подняли интерфейс mgt на Juniper NetScreen 5200, тоже упорно не хотел подниматься. Следующие интерфейсы eth.. не поднимаются вообще.


ns5200-> get route

IPv4 Dest-Routes for <untrust-vr> (0 entries)


H: Host C: Connected S: Static A: Auto-Exported

I: Imported R: RIP/RIPng P: Permanent D: Auto-Discovered


iB: IBGP eB: EBGP O: OSPF/OSPFv3 E1: OSPF external type 1

E2: OSPF/OSPFv3 external type 2 trailing B: backup route



IPv4 Dest-Routes for <trust-vr> (6 entries)


ID IP-Prefix Interface Gateway P Pref Mtr Vsys


* 28 eth2/1 *.*.218.1 S 20 1 Root

* 29 mgt *.*.231.1 S 20 1 Root

* 24 *.*.218.129/32 eth2/1 H 0 0 Root

* 23 *.*.218.0/24 eth2/1 C 0 0 Root

* 20 *.*.231.0/24 mgt C 0 0 Root

* 21 *.*.231.90/32 mgt H 0 0 Root


ns5200-> get interface


A - Active, I - Inactive, U - Up, D - Down, R - Ready


Interfaces in vsys Root:

Name IP Address Zone MAC VLAN State VSD Vsys

mgt *.*.231.90/24 MGT 0010.dbb8.5e00 - U - Root

ha1 HA 0010.dbb8.5e05 - D - Root

ha2 HA 0010.dbb8.5e06 - D - Root

eth2/1 *.*.218.129/24 Trust 0010.dbb8.5e07 - U - Root

eth2/2 Trust 0010.dbb8.5e08 - D - Root

vlan1 VLAN 0010.dbb8.5e0f 1 D - Root

null Null N/A - U - Root


До mgt интерфейса пинг ходит (и обратно), с eth2/1 ничего не ходит в оба направления. set policy from trust to untrust any any any permit сделан.

Подскажите, пожалуйста!

Share this post

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this