Professional Documents
Culture Documents
Layer 2 Next-Generation - L2NG - EX Core CLI Overview Internal Training Presentation
Layer 2 Next-Generation - L2NG - EX Core CLI Overview Internal Training Presentation
OVERVIEW
Rajesh Patil
PSD Technical Marketing
L2NG – INFRASTRUCTURE FEATURES
2 Copyright © 2009 Juniper Networks, Inc. www.juniper.net
L2NG – VLAN CONFIGURATION
§ MX Series: VLAN is not a Broadcast Domain – it’s a Circuit ID
§ MX VLAN equivalent is a Bridge-domain
§ Bridge-domain is supported under routing-instances stanza
§ L2NG CLI – MX Series capability to configure Bridge-
domains under routing instances – except “Bridge-
Domain,” which is replaced with VLAN keyword
§ “Family bridge” changed to “Ethernet-switching”
EX Series L2NG MX Series
[edit
vlans]
[edit
vlans]
[edit
bridge]
Family
Ethernet-‐ Family
Ethernet-‐ Family
bridge
switching
switching
EX Series MX Series/L2NG
[edit prototols rstp ] [edit prototols rstp ]
EX L2NG
[edit forwarding-options storm-control-profiles ]
[edit ethernet-switching-options storm-
foo {
control] all {
interface ge-0/0/0.0 { bandwidth [percentage] 1500;
[no-unknown-unicast | no-broadcast | no-
bandwidth 1500;
multicast | no-registered-multicast | no-unregistered-
[no-broadcast | no-unknown- multicast]
unicast | no-multicast |..] }
shutdown;
} }
action shutdown; [edit interfaces]
ge-0/0/0 {
ether-options {
[edit ethernet-switching-options]
ethernet-switch-profile {
port-error-disable { storm-control foo;
disable-timeout 60; disable-timeout <x>;
}
} }
}
ge-0/0/0 {
unit 0 {
13 JUNIPER NETWORKS CONFIDENTIAL Copyright © 2014 Juniper Networks, Inc. family ethernet-switching {
www.juniper.net
storm-control bar;
disable-timeout <x>;
L2NG – sFLOW
sFlow Collector
sFlow
Traffic
§ Used to monitor traffic to Data
[edit interfaces]
ge-0/0/1 {
unit 0 {
family ethernet-switching {
filter input port-mirror-filter;
filter output port-mirror-filter;
}
}
ge-0/0/5 {
unit 0 {
family ethernet-switching {
filter input port-mirror-filter;
filter output port-mirror-filter;
}
}
[edit firewall family ethernet-switching filter port-mirror-filter]
term 0 {
then port-mirror foo;
}
EX L2NG MX
ethernet-switching-options {
secure-access-port { interface ge-0/0/0 { interface ge-0/0/0 {
interface ge-0/0/0.0 { ether-options { gigether-options {
allowed-mac 00:05:85:3A: source-address-filter {
source-address-filter {
82:80; 00:05:85:3A:82:80; 00:05:85:3A:82:80;
allowed-mac 00:05:85:3A: 00:05:85:3A:82:81; 00:05:85:3A:82:81;
82:81; 00:05:85:3A:82:83; 00:05:85:3A:82:83;
allowed-mac 00:05:85:3A: 00:05:85:3A:82:85; 00:05:85:3A:82:85;
82:83; } }
allowed-mac 00:05:85:3A: }
82:85; }
}
}
}
EX Series L2NG
[edit interfaces]
ge-0/0/0 {
ether-options {
redundant-trunk-group {
rtg0;
[edit ethernet-switching-options] primary;
redundant-trunk-group { }
group g1 { }
preempt-cutover-timer 60; }
interface ge-0/0/9.0 { ge-0/0/1 {
primary; ether-options {
} redundant-trunk-group {
interface ge-0/0/10.0; rtg0;
} }
} }
}
rtg0 {
rtg-ether-options {
preempt-cutover-timer <time_in_secs>
}
}
23 JUNIPER NETWORKS CONFIDENTIAL Copyright © 2014 Juniper Networks, Inc. www.juniper.net
L2NG – PRIVATE VLAN (PVLAN)
§ PVLAN allows to spilt a broadcast domain into multiple isolated broadcast domains
EX Series L2NG
edit vlans ] interfaces {
hr-comm { ge-1/1/1 {
vlan-id 300; unit 0 {
interface { family ethernet-switching {
ge-1/1/13.0; interface-mode access;
ge-1/1/14.0; vlan {
} members 10; ß promiscuous port
primary-vlan vlan100; }
} }
vlan100 { ge-1/1/2 {
vlan-id 100; unit 0 {
pvlan { family ethernet-switching {
isolation-vlan-id 200; vlan {
} members 20 ; ß isolated port
interface { }
ge-1/1/1.0 { routing-instances {
pvlan-trunk; vs {
} instance-type virtual-switch;
ge-1/1/2.0 { interface ge-1/1/1.0;
promiscuous; interface ge-1/1/2.0;
} vlans {
ge-1/1/3.0 { Vp {
24 JUNIPER isolated;
NETWORKS CONFIDENTIAL vlan-id 10; ß primary vlan
Copyright © 2014 Juniper Networks, Inc. www.juniper.net
} isolated-vlan 20 name Vi;
}
KEY TAKEAWAYS