Le 22/07/15 15:51, Colton Conor a écrit :
We would be getting redundant (2) RE-2000's with redundant (2) standard SCB's. The configuration would be full BGP tables with 4 providers on 10G ports. The MS-DCP is a requirement for JFLOW on these older cards right? We would also use the MS-DCP for IPSec tunnels to Cisco ASAs. Any issues with Juniper MS-DPC talking to Cisco ASA? Might also do some NATting with the MS-DCP.
I think your setup will be perfectly fine. regarding the flow, you have two options, inline jflow (with the help of ms-dpc) or software flow (this is what I am doing for now with no issues). I had not played with ms-dpc so I don't know if they are good at making ipsec (but as ipsec is a common standard and asas the most common device to make ipsec tunnel, I think this is safe ?). Don't know for the nat.
-- Raphael Mazelier _______________________________________________ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp