例:SRXシリーズファイアウォールでIP監視を設定する
この例では、SRXシリーズファイアウォールでIPを監視する方法を示しています。
要件
始める前に:
RPM テスト用に以下の RPM オプションを設定します。
ターゲットアドレス
プローブカウント
プローブインターバル
テストインターバル
閾値
ネクストホップ
概要
この例では、SRXシリーズファイアウォールでIP監視を設定する方法を示しています。
設定
手順
CLIクイックコンフィグレーション
この例をすばやく設定するには、以下のコマンドをコピーしてテキストファイルに貼り付け、改行を削除し、ネットワーク設定に合わせて詳細を変更し、コマンドを [edit] 階層レベルのCLIにコピーアンドペーストして、設定モードから commit を入力します。
set services rpm probe Probe-Payment-Server test paysvr target address 1.1.1.10 set services rpm probe Probe-Payment-Server test paysvr probe-count 10 set services rpm probe Probe-Payment-Server test paysvr probe-interval 5 set services rpm probe Probe-Payment-Server test paysvr test-interval 5 set services rpm probe Probe-Payment-Server test paysvr thresholds successive-loss 10 set services rpm probe Probe-Payment-Server test paysvr next-hop 2.2.2.1 set services ip-monitoring policy Payment-Server-Tracking match rpm-probe Probe-Payment-Server set services ip-monitoring policy Payment-Server-Tracking then preferred-route route 1.1.1.0/24 next-hop 1.1.1.99
ステップバイステップの手順
次の例では、設定階層のさまざまなレベルに移動する必要があります。その方法の詳細については、『Junos OS CLIユーザーガイド』の 設定モードでの CLIエディターの使用 を参照してください。
SRXシリーズファイアウォールでIP監視を設定するには:
RPM プローブの下でターゲット アドレスを設定します。
[edit ] user@host# set services rpm probe Probe-Payment-Server test paysvr target address 1.1.1.10
RPMプローブの下のプローブカウントを設定します。
[edit ] user@host# set services rpm probe Probe-Payment-Server test paysvr probe-count 10
RPM プローブの下でプローブ間隔(秒単位)を設定します。
[edit ] user@host# set services rpm probe Probe-Payment-Server test paysvr probe-interval 5
RPM プローブの下でテスト間隔(秒単位)を設定します。
[edit ] user@host# set services rpm probe Probe-Payment-Server test paysvr test-interval 5
RPM の下で連続損失カウントのしきい値を設定します。
[edit ] user@host# set services rpm probe Probe-Payment-Server test paysvr thresholds successive-loss 10
RPM プローブの下にネクストホップ IP アドレスを設定します。
[edit ] user@host# set services rpm probe Probe-Payment-Server test paysvr next-hop 2.2.2.1
サービスでIP監視ポリシーを設定します。
[edit ] user@host# set services ip-monitoring policy Payment-Server-Tracking match rpm-probe Probe-Payment-Server
注:以下の手順は必須ではありません。インターフェイスアクションとルートアクションを個別に設定することも、1つのIP監視ポリシーでインターフェイスアクションとルートアクションの両方を一緒に設定することもできます。
サービスでIP監視優先ルートを設定します。
[edit ] user@host# set services ip-monitoring policy Payment-Server-Tracking then preferred-route route 1.1.1.0/24 preferred-metric 4
IP監視インターフェイスのアクションを設定します。
有効にする
[edit ] user@host# set services ip-monitoring policy Payment-Server-Tracking then interface ge-0/0/1 enable
無効にする
[edit ] user@host# set services ip-monitoring policy Payment-Server-Tracking then interface fe-0/0/[4-6] disable
no-preemptオプションを設定します。
[edit ] user@host# set services ip-monitoring policy Payment-Server-Tracking no-preempt