juniper srx 5800 - Google Search - Google Chrome 2020-03-10 6_32_27 PM (2)
Eric U Ngabonziza

How to request a Data Plane or Control Plane failover in the Juniper firewall SRX 5800

The data plane software manages flow processing, session state redundancy and processes transit traffic. All packets belonging to a particular session are processed on the same node to ensure that the same security treatment is applied to them. The system identifies the node on which a session is active and forwards its packets to that node for processing. (After a packet is processed, the Packet Forwarding Engine transmits the packet to the node on which its egress interface exists if that node is not the local one.)

To provide a redundancy on session (or flow), the data plane software synchronizes its state by sending special payload packets called runtime objects (RTOs) from one node to the other across the fabric data link. By transmitting information about a session between the nodes, RTOs ensure the consistency and stability of sessions if a failover were to occur, and thus they enable the system to continue to process traffic belonging to existing sessions. To ensure that session information is always synchronized between the two nodes, the data plane software gives RTOs transmission priority over transit traffic.

The control plane software, which operates in active/backup mode, is an integral part of JUNOS Software that is active on the primary node of a cluster. It achieves redundancy by communicating state, configuration, and other information to the inactive Routing Engine on the secondary node. If the master Routing Engine fails, the secondary one is ready to assume control.

Below you will see the commands/steps that you can run and follow to request a Data Plane failover (primary -à secondary):

AuthorEric Uwonkunda Ngabonziza

Share this post

Share on facebook
Share on google
Share on twitter
Share on linkedin
Share on pinterest
Share on print
Share on email
fr_CAFrench