This article clarifies that only users with root access will be able to get console access into a virtual network function (VNF) from Juniper Device Manager (JDM) or vjunos0 (JCP) and not non-root users. It also gives the reason for this.
I am logged in as a non-root super-user and am trying to gain console access into a VNF from either JDM or vjunos (on nfx-3 platform).
Note: Confirm that the VNF is built as shown below:
lab> show virtual-network-functions ID Name State Liveliness -------------------------------------------------------------------------------- 2 ubuntu1604 Running down 1 vjunos0 Running alive
However, when attempting to gain console access into ubuntu1604, I see the following:
lab> request virtual-network-functions console ubuntu1604 Internal instance: vnf0 ssh: Could not resolve hostname jdm: hostname nor servname provided, or not known
Note: Sometimes, the following message may be seen on some versions of code: ssh: connect to host jdm port 22: Operation timed out) .
ssh: connect to host jdm port 22: Operation timed out)
On NFX platforms, vjunos (JCP) communicates with JDM via a pre-configured SSH channel. An SSH key is exchanged between the JCP root user and the JDM, and many features use this channel, including console connections.
JDM, therefore, accepts communication from JCP only if the user is a root user. Because of this, console access of a VNF can be accomplished only when logged in as a root user. Additionally, if you ssh from the NFX to the VNF, you have to be logged in as root user (on the NFX).
1/17/2020 - Article created 12/12/2024 - Added note regarding logging in to vnf via ssh from NFX or JDM.