GNU GRUB version 2.00 +--------------------------------------------------------------------------+ Juniper Linux Juniper Linux Debug Juniper-Linux-Recovery +--------------------------------------------------------------------------+ Use the ^ and v keys to select which entry is highlighted. Press enter to boot the selected OS, `e' to edit the commands before booting or `c' for a command-line. The highlighted entry will be executed automatically in 0s. Booting `Juniper Linux' Loading Linux... Failed to access perfctr msr (MSR c1 is 0) kvm: no hardware support Consoles: serial port BIOS drive C: is disk0 BIOS drive D: is disk1 BIOS drive E: is disk2 BIOS drive F: is disk3 BIOS drive G: is disk4 BIOS 639kB/999416kB available memory FreeBSD/i386 bootstrap loader, Revision 1.2 (builder@toyotama, Wed Aug 23 05:50:49 2017) /boot/init.4th loaded. Loading /boot/defaults/loader.conf /kernel text=0xc1fc6c data=0x6bf1c+0x1724c0 syms=[0x4+0xb9b60+0x4+0x116be2] /boot/modules/libmbpool.ko text=0xcd0 data=0x10c /boot/modules/if_em_vsrx.ko text=0x18770 data=0x840+0x1a4 / /boot/modules/virtio.ko text=0x20cc data=0x204 syms=[0x4+0x7a0+0x4+0x900] /boot/modules/virtio_pci.ko text=0x2d8c data=0x1fc+0x8 syms=[0x4+0x8a0+0x4+0xaa3] /boot/modules/virtio_blk.ko text=0x28ac data=0x1ec+0xc syms=[0x4+0x890+0x4+0x906] /boot/modules/if_vtnet.ko text=0x604c data=0x354+0x10 syms=[0x4+0xcf0+0x4+0xde5] /boot/modules/pci_hgcomm.ko text=0x1658 data=0x1a8+0x44 syms=[0x4+0x5f0+0x4+0x6d4] /boot/modules/pvi_db.ko text=0x3080 data=0x31e+0x2e syms=[0x4+0x5d0+0x4+0x56d] /boot/modules/chassis.ko text=0x974 data=0x1cc+0x10 syms=[0x4+0x370+0x4+0x356] Hit [Enter] to boot immediately, or space bar for command prompt.
Booting [/kernel]... platform_early_bootinit: Early Boot Initialization tvp mode is true jnx_reboot_reason: 16384 mac base ff:ff:ff:ff:ff:ff len 255 GDB: debug ports: sio GDB: current port: sio KDB: debugger backends: ddb gdb KDB: current backend: ddb Copyright (c) 1996-2017, Juniper Networks, Inc. All rights reserved. Copyright (c) 1992-2007 The FreeBSD Project. Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994 The Regents of the University of California. All rights reserved. FreeBSD is a registered trademark of The FreeBSD Foundation. JUNOS 17.3R1.10 #0: 2017-08-23 06:47:03 UTC builder@toyotama:/volume/build/junos/17.3/release/17.3r1.10/obj/i386/junos/bsd/kernels/srxjcp /kernel can't re-use a leaf (fast_boot)! can't re-use a leaf (sys_alarm_count)! Timecounter "i8254" frequency 1193182 Hz quality 0 CPU: QEMU Virtual CPU version 1.5.0 (2712.15-MHz 686-class CPU) Origin = "GenuineIntel" Id = 0x633 Stepping = 3 Features=0x781abf9<FPU,PSE,TSC,MSR,PAE,MCE,CX8,APIC,SEP,PGE,CMOV,PAT,MMX,FXS R,SSE,SSE2> Features2=0x80800001<SSE3,POPCNT,<b31>> real memory = 1024458752 (977 MB) avail memory = 982069248 (936 MB) ACPI APIC Table: <BOCHS BXPCAPIC> tvp mode is true jnx_reboot_reason: 16384 mac base ff:ff:ff:ff:ff:ff len 255 Security policy loaded: Junos MAC/veriexec (mac_veriexec) MAC/veriexec fingerprint module loaded: SHA256 MAC/veriexec fingerprint module loaded: SHA1 ioapic0 <Version 1.1> irqs 0-23 on motherboard netisr_init: forcing maxthreads from 4 to 1 Initializing SRXTVP platform properties.. random: <Software, Yarrow> initialized pci-hgcomdev module loadedacpi0: <BOCHS BXPCRSDT> on motherboard acpi0: Power Button (fixed) Timecounter "ACPI-safe" frequency 3579545 Hz quality 1000 acpi_timer0: <24-bit timer at 3.579545MHz> port 0xb008-0xb00b on acpi0 pcib0: <ACPI Host-PCI bridge> port 0xcf8-0xcff on acpi0 pci0: <ACPI PCI bus> on pcib0 isab0: <PCI-ISA bridge> at device 1.0 on pci0 isa0: <ISA bus> on isab0 atapci0: <Intel PIIX3 WDMA2 controller> port 0x1f0-0x1f7,0x3f6,0x170-0x177,0x376,0xc200-0xc20f at device 1.1 on pci0 ata0: <ATA channel 0> on atapci0 ata1: <ATA channel 1> on atapci0
uhci0: <Intel 82371SB (PIIX3) USB controller> port 0xc180-0xc19f irq 11 at device 1.2 on pci0 usb0: <Intel 82371SB (PIIX3) USB controller> on uhci0 usb0: USB revision 1.0 uhub0: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1 uhub0: 2 ports with 2 removable, self powered smb0: <Intel 82371AB SMB controller> irq 9 at device 1.3 on pci0 virtio_pci0: <VirtIO PCI Network adapter> port 0xc1a0-0xc1bf mem 0xfebe0000-0xfebe0fff irq 11 at device 3.0 on pci0 em0: <VirtIO Networking Adapter> on virtio_pci0 virtio_pci0: host features: 0x719fffe3 <EventIdx,RingIndirect,NotifyOnEmpty,0x800000,RxModeExtra,VLanFilter,RxMode,ControlVq,S tatus,mrgrxbuf,txufo,txtsoecn,txtsov6,txtsov4,rxufo,rxecn,rxtsov6,rxtsov4,t xallgso,macaddress,rxchecksum,txchecksum> virtio_pci0: negotiated features: 0x110f8020 <RingIndirect,NotifyOnEmpty,VLanFilter,RxMode,ControlVq,Status,MrgRxBuf,MacAddress> virtio_pci1: <VirtIO PCI Network adapter> port 0xc1c0-0xc1df mem 0xfebe1000-0xfebe1fff irq 11 at device 4.0 on pci0 em1: <VirtIO Networking Adapter> on virtio_pci1 virtio_pci1: host features: 0x719fffe3 <EventIdx,RingIndirect,NotifyOnEmpty,0x800000,RxModeExtra,VLanFilter,RxMode,ControlVq,S tatus,mrgrxbuf,txufo,txtsoecn,txtsov6,txtsov4,rxufo,rxecn,rxtsov6,rxtsov4,t xallgso,macaddress,rxchecksum,txchecksum> virtio_pci1: negotiated features: 0x110f8020 <RingIndirect,NotifyOnEmpty,VLanFilter,RxMode,ControlVq,Status,MrgRxBuf,MacAddress> virtio_pci2: <VirtIO PCI Network adapter> port 0xc1e0-0xc1ff mem 0xfebe2000-0xfebe2fff irq 10 at device 5.0 on pci0 em2: <VirtIO Networking Adapter> on virtio_pci2 virtio_pci2: host features: 0x719fffe3 <EventIdx,RingIndirect,NotifyOnEmpty,0x800000,RxModeExtra,VLanFilter,RxMode,ControlVq,S tatus,mrgrxbuf,txufo,txtsoecn,txtsov6,txtsov4,rxufo,rxecn,rxtsov6,rxtsov4,t xallgso,macaddress,rxchecksum,txchecksum> virtio_pci2: negotiated features: 0x110f8020 <RingIndirect,NotifyOnEmpty,VLanFilter,RxMode,ControlVq,Status,MrgRxBuf,MacAddress> virtio_pci3: <VirtIO PCI Block adapter> port 0xc000-0xc03f mem 0xfebe3000-0xfebe3fff irq 10 at device 6.0 on pci0 vtblk0: <VirtIO Block Adapter> on virtio_pci3 virtio_pci3: host features: 0x71000cd4 <EventIdx,RingIndirect,NotifyOnEmpty,0x800,Topology,SCSICmds,BlockSize,DiskGeometry,Ma xnumsegs> virtio_pci3: negotiated features: 0x10000054 <RingIndirect,BlockSize,DiskGeometry,MaxNumSegs> vtblk0: 706MB (1445913 512 byte sectors) virtio_pci4: <VirtIO PCI Block adapter> port 0xc040-0xc07f mem 0xfebe4000-0xfebe4fff irq 11 at device 7.0 on pci0 vtblk1: <VirtIO Block Adapter> on virtio_pci4 virtio_pci4: host features: 0x71000ed4 <EventIdx,RingIndirect,NotifyOnEmpty,0x800,Topology,FlushCmd,SCSICmds,BlockSize,DiskGe ometry,maxnumsegs> virtio_pci4: negotiated features: 0x10000254 <RingIndirect,FlushCmd,BlockSize,DiskGeometry,MaxNumSegs> vtblk1: 3072MB (6291456 512 byte sectors) virtio_pci5: <VirtIO PCI Block adapter> port 0xc080-0xc0bf mem 0xfebe5000-0xfebe5fff irq 11 at
device 8.0 on pci0 vtblk2: <VirtIO Block Adapter> on virtio_pci5 virtio_pci5: host features: 0x71000ed4 <EventIdx,RingIndirect,NotifyOnEmpty,0x800,Topology,FlushCmd,SCSICmds,BlockSize,DiskGe ometry,maxnumsegs> virtio_pci5: negotiated features: 0x10000254 <RingIndirect,FlushCmd,BlockSize,DiskGeometry,MaxNumSegs> vtblk2: 102MB (209715 512 byte sectors) virtio_pci6: <VirtIO PCI Block adapter> port 0xc0c0-0xc0ff mem 0xfebe6000-0xfebe6fff irq 10 at device 9.0 on pci0 vtblk3: <VirtIO Block Adapter> on virtio_pci6 virtio_pci6: host features: 0x71000ed4 <EventIdx,RingIndirect,NotifyOnEmpty,0x800,Topology,FlushCmd,SCSICmds,BlockSize,DiskGe ometry,maxnumsegs> virtio_pci6: negotiated features: 0x10000254 <RingIndirect,FlushCmd,BlockSize,DiskGeometry,MaxNumSegs> vtblk3: 128MB (262144 512 byte sectors) virtio_pci7: <VirtIO PCI Block adapter> port 0xc100-0xc13f mem 0xfebe7000-0xfebe7fff irq 10 at device 10.0 on pci0 vtblk4: <VirtIO Block Adapter> on virtio_pci7 virtio_pci7: host features: 0x71000ed4 <EventIdx,RingIndirect,NotifyOnEmpty,0x800,Topology,FlushCmd,SCSICmds,BlockSize,DiskGe ometry,maxnumsegs> virtio_pci7: negotiated features: 0x10000254 <RingIndirect,FlushCmd,BlockSize,DiskGeometry,MaxNumSegs> vtblk4: 614MB (1259059 512 byte sectors) em3: <Intel(R) PRO/1000 Network Connection Version - 3.2.18> port 0xc140-0xc17f mem 0xfebc0000-0xfebdffff irq 11 at device 16.0 on pci0 em3: Memory Access and/or Bus Master bits were not set! hgcommdev0: <HGCOMMDEV For Host VM communication> mem 0xfebe8000-0xfebe8fff at device 22.0 on pci0 hgcommdev0: hgcommdev: registers at 0xdfb38000 cpu0: <ACPI CPU> on acpi0 atkbdc0: <Keyboard controller (i8042)> port 0x60,0x64 irq 1 on acpi0 atkbd0: <AT Keyboard> irq 1 on atkbdc0 kbd0 at atkbd0 psm0: <PS/2 Mouse> irq 12 on atkbdc0 psm0: model IntelliMouse Explorer, device ID 4 sio0: <16550A-compatible COM port> port 0x3f8-0x3ff irq 4 flags 0x90 on acpi0 sio0: type 16550A, console orm0: <ISA Option ROM> at iomem 0xe5800-0xeffff on isa0 vga0: <Generic ISA VGA> at port 0x3b0-0x3bb iomem 0xb0000-0xb7fff on isa0 sc0: <System console> at flags 0x100 on isa0 sc0: MDA <16 virtual consoles, flags=0x300> sio1: configured irq 5 not in bitmap of probed irqs 0 sio1: port may not be enabled sio2: configured irq 3 not in bitmap of probed irqs 0 sio2: port may not be enabled sio3: configured irq 7 not in bitmap of probed irqs 0 sio3: port may not be enabled tvp mode is true jnx_reboot_reason: 16384 mac base ff:ff:ff:ff:ff:ff len 255
TVP: Model Name read from HostOS is vsrx Initializing product: 200.. fxp0: bus=0, device=16, func=0, Ethernet address 52:e5:92:65:0b:00 fxp0 MAC address 52:e5:92:65:0b:00 Timecounter "TSC" frequency 2712148853 Hz quality 800 Registering tcp_platform_dependent = tcp_handle_special_ports random: unblocking device. Loading JUNOS chassis module chassis_init_hw_chassis_startup_time: chassis startup time 0.000000 Kernel thread "wkupdaemon" (pid 56) exited prematurely. Trying to mount root from ufs:/dev/vtbd0s1a WARNING: / was not properly dismounted Attaching /cf/packages/junos via /dev/mdctl... Mounted junos package on /dev/md0... Automatic reboot in progress... ** /dev/vtbd0s1a ** Last Mounted on / ** Root file system ** Phase 1 - Check Blocks and Sizes ** Phase 2 - Check Pathnames ** Phase 3 - Check Connectivity ** Phase 4 - Check Reference Counts ** Phase 5 - Check Cyl groups 167 files, 221453 used, 133918 free (2 frags, 33479 blocks, 0.0% fragmentation) ***** FILE SYSTEM MARKED CLEAN ***** Verified jboot signed by PackageProductionEc_2017 method ECDSA256+SHA256 veriexec: cannot update veriexec for /cf/etc/ssh/moduli: No such file or directory Verified junos signed by PackageProductionEc_2017 method ECDSA256+SHA256 veriexec: cannot update veriexec for /usr/lib/libyaml.so.3: Too many links Verified junos-srxjcp-17.3r1.10-domestic signed by PackageProductionEc_2017 method ECDSA256+SHA256 Detected data disk ** /dev/vtbd1s1e ** Last Mounted on /config ** Phase 1 - Check Blocks and Sizes ** Phase 2 - Check Pathnames ** Phase 3 - Check Connectivity ** Phase 4 - Check Reference Counts ** Phase 5 - Check Cyl groups 12 files, 13 used, 154720 free (24 frags, 19337 blocks, 0.0% fragmentation) ***** FILE SYSTEM MARKED CLEAN ***** ** /dev/vtbd1s1f ** Last Mounted on /var ** Phase 1 - Check Blocks and Sizes ** Phase 2 - Check Pathnames ** Phase 3 - Check Connectivity ** Phase 4 - Check Reference Counts ** Phase 5 - Check Cyl groups 457 files, 36039 used, 1355585 free (161 frags, 169428 blocks, 0.0% fragmentation)
***** FILE SYSTEM MARKED CLEAN ***** remount /config...success remount /var...success Mounting shared partition /var/host.. Detected swap drive *** Creating PVIDb..\n 1126+0 records in 1126+0 records out 585520 bytes transferred in 0.360522 secs (1624089 bytes/sec) Copied libschema-filter-dd.tlv to /opt/lib/dd/filter\n Executing the Junos host files signature script Verified manifest signed by PackageDevelopmentEc_2017 method ECDSA256+SHA256 Loading configuration... mgd: commit complete [: auth.conf: unexpected operator Setting initial options:. Starting optional daemons: usbd. Doing initial network setup:. Initial interface configuration: kenv: unable to get vmtype additional daemons: eventd. checking for core dump... savecore: Reboot reason(s): 0x4000: VJUNOS reboot savecore: Reboot reason(s): 0x4000: VJUNOS reboot savecore: no dumps found Additional routing options:kern.module_path: /boot//kernel;/boot/modules -> /boot/modules;/modules/peertype;/modules/ifpfe_drv;/modules/platform;/modules; kld netpfe drv: ifpfed_ep ifpfed_esp ifpfed_ism ifpfed_ml_ha ifpfed_ppeer ifpfed_ps ifpfed_st ifpfed_vtkld platform: if_em_vsrx if_vtnet virtio virtio_blk virtio_console virtio_pcikld peertype: peertype_fwdd peertype_pfpc grat_arp_delay=1: net.link.ether.inet.grat_arp_delay: 1 -> 1 [: -eq: unexpected operator ipsec kldcryptosoft0: <software crypto> on motherboard kats kldipsec: Initialized Security Association Processing. resrsv. Doing additional network setup:. Starting final network daemons:. setting ldconfig path: /usr/lib /opt/lib starting standard daemons: cron. Initial rc.i386 initialization:. Local package initialization:. starting local daemons:set cores for group access. kern.securelevel: -1 -> 1 kern.timecounter.hardware: ACPI-safe -> TSC kern.timecounter.hardware: TSC -> TSC kern.maxfiles: 2500 -> 10500 kern.maxfilesperproc: 2500 -> 10500 The machine id is empty. Cleaning up... Thu Apr 5 17:49:09 UTC 2018 vsrx (ttyd0)
login: root Password: --- JUNOS 17.3R1.10 built 2017-08-23 06:47:03 UTC root@vsrx% cli [edit] root@vsrx> configure Entering configuration mode [edit] root@vsrx# [edit] root@vsrx# show ## Last changed: 2018-04-05 17:48:57 UTC version 17.3R1.10; system { host-name vsrx; domain-name home.co.uk; root-authentication { encrypted-password "$6$hSJIMYmW$lHbrbhoUYoERszbEGcSFPiVEMsz6kzrJTwxDXGhWPkwcosZXOXbMc4YR8 OhvZpYz6epPYhqlf3BN.M1EQREHn1"; ## SECRET-DATA name-server { 192.168.0.1; 8.8.8.8;
services { ssh; dns { dns-proxy { interface { ge-0/0/1.0; web-management { http { interface fxp0.0; dhcp { pool 172.16.1.0/24 { address-range low 172.16.1.10 high 172.16.1.20; default-lease-time 3600; domain-name home.co.uk; name-server { 172.16.1.1; router { 172.16.1.1; syslog { user * { any emergency; file messages { any any; authorization info; file interactive-commands { interactive-commands any; license { autoupdate { url https://ae1.juniper.net/junos/key_retrieval;
security { screen { ids-option untrust-screen { icmp { ping-death; ip { source-route-option; tear-drop; tcp { syn-flood { alarm-threshold 1024; attack-threshold 200; source-threshold 1024; destination-threshold 2048; queue-size 2000; ## Warning: 'queue-size' is deprecated timeout 20; land; nat { source { rule-set Internet-NAT { from zone Internal; to zone External; rule Internet-NAT-1 { match { source-address 172.16.1.0/24; then { source-nat { interface;
policies { from-zone trust to-zone trust { policy default-permit { match { source-address any; destination-address any; application any; then { permit; from-zone trust to-zone untrust { policy default-permit { match { source-address any; destination-address any; application any; then { permit; from-zone Internal to-zone External { policy Internet-Access { match { source-address LAN-1; destination-address any; application any; then { permit;
zones { security-zone trust { tcp-rst; security-zone untrust { screen untrust-screen; security-zone External { interfaces { ge-0/0/0.0 { host-inbound-traffic { system-services { all; security-zone Internal { address-book { address LAN-1 172.16.1.0/24; interfaces { ge-0/0/1.0 { host-inbound-traffic { system-services { all; dhcp;
interfaces { ge-0/0/0 { unit 0 { family inet { address 192.168.0.100/24; ge-0/0/1 { unit 0 { family inet { address 172.16.1.1/24; fxp0 { unit 0; routing-options { static { route 0.0.0.0/0 next-hop 192.168.0.1; [edit] root@vsrx#