How to Configure the NFX250 Nextgen
Total Page:16
File Type:pdf, Size:1020Kb
How to Configure the NFX250 NextGen Published 2021-04-20 ii Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, California 94089 USA 408-745-2000 www.juniper.net Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc. in the United States and other countries. All other trademarks, service marks, registered marks, or registered service marks are the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice. How to Configure the NFX250 NextGen Copyright © 2021 Juniper Networks, Inc. All rights reserved. The information in this document is current as of the date on the title page. YEAR 2000 NOTICE Juniper Networks hardware and software products are Year 2000 compliant. Junos OS has no known time-related limitations through the year 2038. However, the NTP application is known to have some difficulty in the year 2036. END USER LICENSE AGREEMENT The Juniper Networks product that is the subject of this technical documentation consists of (or is intended for use with) Juniper Networks software. Use of such software is subject to the terms and conditions of the End User License Agreement ("EULA") posted at https://support.juniper.net/support/eula/. By downloading, installing or using such software, you agree to the terms and conditions of that EULA. iii Table of Contents About This Guide | x 1 Overview NFX250 NextGen Overview | 2 Software Architecture | 3 NFX250 Models | 5 Interfaces | 6 Performance Modes | 7 Benefits and Uses | 11 Junos OS Releases Supported on NFX Series Hardware | 12 Upgrade the NFX250 Software to NFX250 NextGen Software | 14 NFX250 NextGen Software Upgrade Overview | 14 Prerequisites | 14 Upgrade to NFX250 NextGen Software Architecture | 17 NFX Product Compatibility | 17 2 Initial Configuration Initial Configuration on NFX250 NextGen Devices | 22 Factory Default Settings | 22 Enabling Basic Connectivity | 23 Establishing the Connection | 24 Zero Touch Provisioning on NFX Series Devices | 25 Understanding Zero Touch Provisioning | 25 Pre-staging an NFX Series Device | 26 Provisioning an NFX Series Device | 29 Provisioning an NFX Series Device Using Sky Enterprise | 30 iv 3 Generating YANG Files YANG files on NFX250 NextGen Devices | 32 Understanding YANG on NFX250 NextGen Devices | 32 Generating YANG Files | 33 4 Configuring Interfaces Configuring the In-Band Management Interface on NFX250 NextGen Devices | 36 ADSL2 and ADSL2+ Interfaces on NFX250 NextGen Devices | 37 ADSL Interface Overview | 37 Example: Configuring ADSL SFP Interface on NFX250 Devices | 39 Requirements | 39 Overview | 39 Configuration | 39 Results | 41 VDSL2 Interfaces on NFX250 NextGen Devices | 41 VDSL Interface Overview | 41 VDSL2 Network Deployment Topology | 42 VDSL2 Interface Support on NFX Series Devices | 44 Example: Configuring VDSL SFP Interface on NFX250 Devices | 46 Requirements | 47 Overview | 47 Configuration | 47 Results | 49 Configuring the LTE Module on NFX Devices | 49 Configuring the LTE Module for Primary Mode | 50 Configuring the LTE Module for Dial-on-Demand Mode | 52 Configuring the LTE Module for Backup Mode | 54 Configuring the LTE Interface Module in an NFX150 Chassis Cluster | 55 5 Configuring USB Pass-Through on NFX Series Devices Supporting File Transfer from USB on NFX Series Devices | 63 v 6 Configuring Security IP Security on NFX Devices | 67 Overview | 67 Configuring Security | 69 Configuring Interfaces | 69 Configuring Routing Options | 70 Configuring Security IKE | 71 Configuring Security IPsec | 74 Configuring Security Policies | 76 Configuring Security Zones | 77 UTM on NFX Devices | 77 Application Security on NFX Devices | 78 Intrusion Detection and Prevention on NFX Devices | 79 Integrated User Firewall Support on NFX Devices | 80 7 Configuring Virtual Network Functions Prerequisites to Onboard Virtual Network Functions on NFX250 NextGen Devices | 83 NFX250 NextGen Device Prerequisites to Onboard a VNF | 83 VNF Prerequisites to Onboard on an NFX250 NextGen Device | 85 Validate the VNFs | 85 Sample Output | 86 Configuring VNFs on NFX250 NextGen Devices | 91 Load a VNF Image | 92 Prepare the Bootstrap Configuration | 93 Allocate CPUs for a VNF | 94 Allocate Memory for a VNF | 97 (Optional) Attach a Config Drive to the VNF | 99 Configure Interfaces and VLANs for a VNF | 106 Configure Storage Devices for VNFs | 110 vi Instantiate a VNF | 111 Verify the VNF Instantiation | 112 Managing VNFs on NFX Series Devices | 113 Managing VNF States | 113 Managing VNF MAC Addresses | 114 Managing the MTU of a VNF Interface | 115 Accessing a VNF from the JCP | 116 Viewing the List of VNFs | 116 Displaying the Details of a VNF | 117 Deleting a VNF | 117 Configuring Analyzer VNF and Port-mirroring | 118 8 Configuring Mapping of Address and Port with Encapsulation (MAP-E) Mapping of Address and Port with Encapsulation on NFX Series Devices | 120 Overview | 120 Benefits of MAP-E | 120 MAP-E Terminology | 121 MAP-E Functionality | 122 Configuring MAP-E on NFX Series Devices | 123 Overview | 123 Requirements | 123 Topology Overview | 123 Configure an NFX Series Device as a MAP-E CE Device | 124 Configure an MX Series Device as a BR Device | 127 Verify the MAP-E Configuration | 129 9 Configuring High Availability Chassis Cluster on NFX250 NextGen Devices | 136 vii NFX250 NextGen Chassis Cluster Overview | 136 Chassis Cluster Interfaces | 137 Chassis Cluster Limitation | 138 Example: Configuring a Chassis Cluster on NFX250 NextGen Devices | 138 Requirements | 138 Overview | 139 Configuration | 140 Verification | 148 Upgrading or Disabling a Chassis Cluster on NFX250 NextGen Devices | 152 Upgrading Individual Devices in a Chassis Cluster Separately | 152 Disabling a Chassis Cluster | 153 10 Configuring Service Chaining Example: Configuring Service Chaining Using VLANs on NFX250 NextGen Devices | 155 Requirements | 155 Overview | 155 Configuration | 157 Example: Configuring Service Chaining Using SR-IOV on NFX250 NextGen Devices | 162 Requirements | 162 Overview | 163 Configuration | 165 Example: Configuring Service Chaining Using a Custom Bridge on NFX250 NextGen Devices | 169 Requirements | 170 Overview | 170 Configuration | 171 Verifying the Configuration | 174 Example: Configuring Cross-Connect on NFX250 NextGen Devices | 180 Requirements | 181 viii Overview | 181 Configuration | 182 Verifying the Configuration | 185 Example: Configuring Service Chaining for LAN Routing on NFX250 NextGen Devices | 192 Requirements | 192 Overview | 193 Configuration | 194 Example: Configuring Service Chaining for LAN to WAN Routing on NFX250 NextGen Devices | 195 Requirements | 196 Overview | 196 Configuration | 197 Verification | 199 Example: Configuring Service Chaining for LAN to WAN Routing through Third-party VNFs on NFX250 NextGen Devices | 201 Requirements | 201 Overview | 201 Configuration | 202 Verification | 206 11 Troubleshooting Recovering the Root Password for NFX150, NFX250 NextGen, and NFX350 Devices | 209 Troubleshooting Interfaces on NFX Devices | 213 Monitoring Interface Status and Traffic on NFX Series Devices | 213 12 Operational Commands request vmhost cleanup | 220 request vmhost file-copy | 221 request vmhost halt | 223 ix request vmhost mode | 225 request vmhost power-off | 227 request vmhost reboot | 228 request vmhost software add | 232 request vmhost storage | 235 show system visibility cpu | 238 show system visibility host | 243 show system visibility memory | 255 show system visibility network | 258 show system visibility vnf | 267 show vmhost connections | 274 show vmhost control-plane | 277 show vmhost crash | 278 show vmhost forwarding-options analyzer | 280 show vmhost memory | 282 show vmhost mode | 284 show vmhost status | 292 show vmhost storage | 294 show vmhost uptime | 301 show vmhost version | 303 show vmhost vlans | 306 x About This Guide Use this guide to perform initial provisioning, configure Junos OS features, chain multiple virtualized network functions, monitor, and manage the NFX250 NextGen devices. 1CHAPTER Overview NFX250 NextGen Overview | 2 Upgrade the NFX250 Software to NFX250 NextGen Software | 14 NFX Product Compatibility | 17 2 NFX250 NextGen Overview IN THIS SECTION Software Architecture | 3 NFX250 Models | 5 Interfaces | 6 Performance Modes | 7 Benefits and Uses | 11 Junos OS Releases Supported on NFX Series Hardware | 12 The Juniper Networks NFX250 Network Services Platform is a secure, automated, software-driven customer premises equipment (CPE) platform that delivers virtualized network and security services on demand. The NFX250 is part of the Juniper Cloud CPE solution, which leverages Network Functions Virtualization (NFV). It enables service providers to deploy and chain multiple, secure, and high- performance virtualized network functions (VNFs) on a single device. Figure 1 on page 2 shows the NFX250 device. Figure 1: NFX250 Device The NFX250 is a complete SD-WAN CPE, which provides secure router functionality and Next- Generation Firewall (NGFW) solution. NGFW includes security features such as • VPN (see VPN User Guide for Security Devices) • NAT (see NAT User Guide) 3 • ALG (see Application Layer Gateways User Guide) • Application Security (see AppSecure User Guide) • UTM features including Enhanced Web Filtering and Anti-Virus (see UTM User Guide) The NFX250 device is suitable for small to midsize businesses and large multinational or distributed