Juniper EX/vQFX integration

Note – In this example, an Juniper vQFX configuration is provided as tested on 18.4R1.8 firmware and 20.3R1.8 firmware, however any Juniper-Switch EX/QFX supporting the following features are eligible for integration.

  • <NAC-IP> is the NAC VM IP address (e.g. 10.40.177.2)

  • <NAC-Subnet> is a subnet containing both the NAC IP and Juniper interface IP (e.g. 10.40.177.0/28)

  • <Client-Subnet> is a subnet where clients will connect from (e.g. 10.40.180.243/28).NOTE: The network portion of this CIDR string must be the IP of the Juniper gateway interface for the subnet

firewall {
family inet {
filter fil {
term dns_dhcp {
from {
destination-port [ 53 67 ];
}
then accept;
}
term internal {
from {
destination-address {
<NAC-IP>…