[j-nsp] Content filtering/malware protection

2010-03-17 Thread Kevin Day
Does anyone have any experience with Juniper's inline filtering appliances? A client is looking for something to sit between their office LAN and router, to filter out employees clicking on malware, as well as logging what computer visits what sites. They're looking for something plug-and-play,

Re: [j-nsp] SSG140 - Configure Ethernet ports as switch ports?

2010-03-17 Thread Stefan Fouant
> -Original Message- > From: juniper-nsp-boun...@puck.nether.net [mailto:juniper-nsp- > boun...@puck.nether.net] On Behalf Of TCIS List Acct > Sent: Wednesday, March 17, 2010 12:46 PM > To: juniper-nsp@puck.nether.net > Subject: [j-nsp] SSG140 - Configure Ethernet ports as switch ports? >

[j-nsp] SSG140 - Configure Ethernet ports as switch ports?

2010-03-17 Thread TCIS List Acct
Is it possible in a SSG-140 to configure a few of the Ethernet interfaces as a L2 segment/VLAN to emulate a switch, but also have L3 functions (firewall rules, MIPs, etc) work for hosts in that L2 segment? (without having the device in transparent mode) TIA. --Mike __

Re: [j-nsp] Routing-Instance Removal Memory Savings

2010-03-17 Thread Richard A Steenbergen
On Wed, Mar 17, 2010 at 12:27:11PM -0400, Jose Madrid wrote: > Hello everyone, > > I have a customer who is using a routing-instance per provider on an > M7i. There is no real reason for this doing this and he only has it > this way due to a previous consultant who decided that would be best. > T

Re: [j-nsp] L2VPN/L2Circuit and Vlan transparent

2010-03-17 Thread Mark Tinka
On Thursday 18 March 2010 01:15:56 am youssef chagh wrote: > Can I connect 2 sites (cisco switches ) each one to an > Extreme with a trunk ports (many vlans on the ciscos ), > and using a L2VPN/L2circuit , so that the entire path > between the 2 Extreme will be vlan transparent (It's > like t

Re: [j-nsp] L2VPN/L2Circuit and Vlan transparent

2010-03-17 Thread sthaug
> I have the following architecture : > > *Switch*(Extreme)*M7i*( GE IQ PIC, 9.6R3.8)MPLS*M20* (GE > IQ PIC, 8.5R1.13)-*Switch*(EXtreme) > > > Can I connect 2 sites (cisco switches ) each one to an Extreme with a trunk > ports (many vlans on the ciscos ), and using a L2VP

[j-nsp] L2VPN/L2Circuit and Vlan transparent

2010-03-17 Thread youssef chagh
Hi All, I have the following architecture : *Switch*(Extreme)*M7i*( GE IQ PIC, 9.6R3.8)MPLS*M20* (GE IQ PIC, 8.5R1.13)-*Switch*(EXtreme) Can I connect 2 sites (cisco switches ) each one to an Extreme with a trunk ports (many vlans on the ciscos ), and using a L2VPN/L2ci

[j-nsp] Routing-Instance Removal Memory Savings

2010-03-17 Thread Jose Madrid
Hello everyone, I have a customer who is using a routing-instance per provider on an M7i. There is no real reason for this doing this and he only has it this way due to a previous consultant who decided that would be best. The box is running hot and sits at 93% memory utilization. I am trying to

Re: [j-nsp] BGP Flowspec + NSR

2010-03-17 Thread Sean Clarke
On 3/17/10 11:01 AM, Felix Schueren wrote: confirmed and very, very annoying. I've filed this as a bug over a year ago when my MBGP sessions broke in NSR on the backup RE - apparently, it was always broken and not working properly when using flowspec, Not really a bug - it's just never been

Re: [j-nsp] BGP Flowspec + NSR

2010-03-17 Thread Felix Schueren
Richard A Steenbergen wrote: So I noticed something interesting about NSR, apparently it doesn't support BGP sessions with flowspec SAFIs enabled. Here is a sh bgp sum It just sits and spins forever trying to bring up the BGP sync session between the master and backup RE, and turning off inetflow