Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 

Using the CBA750B 3G/4G Wireless WAN Bridge for Primary Connectivity

 

This scenario shows the gateway configuration when the 3G network is used as the primary WAN link. This can be achieved by connecting the CBA750B 3G/4G wireless WAN bridge to any interface in the untrust zone. On the SRX210 Services Gateway, this is ge-0/0/0 when using the default configuration.

Figure 1 shows the 3G network used as the primary WAN link.

The default configuration is as follows for completeness:

set system services dhcp router 192.168.1.1

set system services dhcp pool 192.168.1.0/24 address-range low 192.168.1.2

set system services dhcp pool 192.168.1.0/24 address-range high 192.168.1.254

set system services dhcp propagate-settings ge-0/0/0.0

set interfaces interface-range interfaces-trust member ge-0/0/1

set interfaces interface-range interfaces-trust member fe-0/0/2

set interfaces interface-range interfaces-trust member fe-0/0/3

set interfaces interface-range interfaces-trust member fe-0/0/4

set interfaces interface-range interfaces-trust member fe-0/0/5

set interfaces interface-range interfaces-trust member fe-0/0/6

set interfaces interface-range interfaces-trust member fe-0/0/7

set interfaces interface-range interfaces-trust unit 0 family ethernet-switching vlan members vlan-trust

set interfaces ge-0/0/0 unit 0 set interfaces vlan unit 0 family inet address 192.168.1.1/24

set security nat source rule-set trust-to-untrust from zone trust

set security nat source rule-set trust-to-untrust to zone untrust

set security nat source rule-set trust-to-untrust rule source-nat-rule match source-address 0.0.0.0/0

set security nat source rule-set trust-to-untrust rule source-nat-rule then source-nat interface

set security zones security-zone trust host-inbound-traffic system-services all

set security zones security-zone trust host-inbound-traffic protocols all

set security zones security-zone trust interfaces vlan.0

set security zones security-zone untrust interfaces ge-0/0/0.0 host-inbound-traffic system-services dhcp

set security zones security-zone untrust interfaces ge-0/0/0.0 host-inbound-traffic system-services tftp

set security policies from-zone trust to-zone untrust policy trust-to-untrust match source-address any

set security policies from-zone trust to-zone untrust policy trust-to-untrust match destination-address any

set security policies from-zone trust to-zone untrust policy trust-to-untrust match application any

set security policies from-zone trust to-zone untrust policy trust-to-untrust then permit

set vlans vlan-trust vlan-id 3 set vlans vlan-trust l3-interface vlan.0

Enabling PoE

On SRX Series Services Gateways, it is possible to use PoE to power the CBA750B. The default configuration has PoE enabled on every PoE-capable interface, requiring you only to connect the CBA750B to a PoE-capable port. Enabling PoE requires only the addition of the following configuration:

/* The priority is optional but it will make sure that, if too many devices are being powered, the bridge will be given a high priority and will not be powered off */

set poe interface ge-0/0/0 priority high