Junos Primary and Preferred Interface Commands

This blog post was spurred on by a recent real-world experience where I had to configure a primary IP address on an ISP facing interface. In this scenario, we needed to maintain the corporate ARIN assigned IP on an interface for VPN traffic to originate from and terminate on. Yet the ISP would only allow the customer to use the ISP provided IP address for BGP peering.
Fair warning, this is a bit of a long one and has a twist and turn. Also, take note that I am using interface overload NAT only for demonstration purposes.
There was some discussion around the primary and preferred interface commands, so why not learn more about it and, in turn, write a blog post about it.
Below is the lab diagram we will use for this blog post. I have preconfigured the devices to pass traffic with vSRX2 set to NAT all internal traffic to its outside (ge-0/0/2) interface. vSRX1, vSRX3, and vSRX4 are all configured in packet mode to keep the configurations simple. You can find a copy of the eve-ng topology, starting configs, and ending configs at the end of this post.

Fryguy's Blog






