labunix's blog



 ホストOSはDebian jessie。vmplayerとvSRXのシングル構成については以下。

$ lsb_release -d
Description:	Debian GNU/Linux 8.1 (jessie)
$ vmplayer -v
VMware Player 12.0.0 build-2985596


 (Linux版)VMware Player 7.1.2からVMware Workstation 12 Playerにアップデートする。台の仮想マシンだけなら以下の起動、起動確認、電源OFFが行える。

$ vmrun -T player list | \
    awk '!/junos-vsrx-12.vmx/{print "vmrun -T player start junos-vsrx-12.vmx nogui"}' | sh

$ vmrun -T player list | awk -F/ '/vmx/{print $NF}'

$ ssh admin@
root@% cli
root> request system halt at now
Halt the system at now? [yes,no] (no) yes 

$ vmrun -T player list | awk '/junos-vsrx-12.vmx/{print "vmrun -T player stop "$0}' | sh



$ grep -A 1 "udp\|" /etc/rsyslog.conf
$ModLoad imudp
$UDPServerRun 514
:fromhost-ip, isequal, "" -/var/log/vSRX.log


root@% cli
root> configure
root# set system syslog host any warning
root# commit
root# exit
root> show configuration system syslog         
user * {
    any emergency;
host {
    any warning;
file messages {
    any any;
    authorization info;
file interactive-commands {
    interactive-commands any;


root> configure
root# set system time-zone Asia/Tokyo 
root# set system ntp server 
root# show | compare   
[edit system]
+  time-zone Asia/Tokyo;
+  ntp {
+      server;
+      source-address;
+  }

root# commit
root# exit
root> show configuration system time-zone 
time-zone Asia/Tokyo;
root> set date ntp 
30 Aug 03:58:17 ntpdate[5806]: step time server offset 0.000039 sec
root> set date ntp 
30 Aug 04:09:06 ntpdate[6833]: step time server offset -0.000075 sec
offset=0.000, frequency=0.000, jitter=0.002, stability=0.000
root> show ntp status          
status=0664 leap_none, sync_ntp, 6 events, event_peer/strat_chg,
version="ntpd 4.2.0-a Tue Mar  3 22:07:26 UTC 2015 (1)",
processor="i386", system="JUNOS12.1X47-D20.7", leap=00, stratum=4,
precision=-19, rootdelay=8.036, rootdispersion=1.545, peer=62828,
reftime=d98c822b.5119c085  Sun, Aug 30 2015  4:10:35.316, poll=6,
clock=d98c823a.2d3876ff  Sun, Aug 30 2015  4:10:50.176, state=3,
offset=0.000, frequency=0.000, jitter=1.570, stability=0.000
root> show ntp associations 
     remote           refid      st t when poll reach   delay   offset  jitter
*     3 -   47   64    1    0.254   -1.741   1.787


root# set snmp community public authorization read-only clients
root# set snmp interface ge-0/0/0
root# commit

root# show interfaces ge-0/0/0       
unit 0 {
    family inet {

root# show snmp                   
interface ge-0/0/0.0;
community public {
    authorization read-only;
    clients {;

root# set snmp trap-group public targets
root# set snmp trap-group public categories startup chassis link

 syslogで「e1000」NICが起動した後、SNMP Trapが3つ出て入ればOKの様子。

root> request system reboot 
Reboot the system ? [yes,no] (no) yes 

Shutdown NOW!

$ sudo tail -f /var/log/vSRX.log
Aug 30 04:25:52  mgd[1170]: UI_REBOOT_EVENT: System rebooted by 'root'
Aug 30 04:27:33   e1000: chip 1 has already been started 
Aug 30 04:27:33   e1000: chip 0 has already been started 

$ sudo tcpdump -i vmnet8 -n -v udp port 161 or 162 | \
    awk '/.1.3.6/{print $(NF-2)}'


root> request system halt
Halt the system ? [yes,no] (no) yes

Shutdown NOW!

$ sudo tail -f /var/log/vSRX.log
Aug 30 04:34:07  mgd[1175]: UI_REBOOT_EVENT: System halted by 'root'
Aug 30 04:34:13   usp_trace_ipc_disconnect:Trace client disconnected. Attempting to reconnect 
Aug 30 04:34:13   usp_trace_ipc_reconnect:USP trace client cannot reconnect to server


root> show security zones untrust           

Security zone: untrust
  Send reset for non-SYN session TCP packets: Off
  Policy configurable: Yes  
  Screen: untrust-screen  
  Interfaces bound: 1
root> conf
root#set security zones security-zone untrust interfaces ge-0/0/0 host-inbound-traffic system-services ping


$ ping
64 bytes from icmp_seq=19 ttl=64 time=2.59 ms
64 bytes from icmp_seq=20 ttl=64 time=1.42 ms
64 bytes from icmp_seq=21 ttl=64 time=5.18 ms
64 bytes from icmp_seq=22 ttl=64 time=2.81 ms
64 bytes from icmp_seq=23 ttl=64 time=1.36 ms
64 bytes from icmp_seq=24 ttl=64 time=4.68 ms
64 bytes from icmp_seq=25 ttl=64 time=3.43 ms

From icmp_seq=50 Destination Host Unreachable
From icmp_seq=51 Destination Host Unreachable
From icmp_seq=52 Destination Host Unreachable
From icmp_seq=53 Destination Host Unreachable
From icmp_seq=54 Destination Host Unreachable
From icmp_seq=55 Destination Host Unreachable