Re: [j-nsp] JunOS route-based VPN: multiple st interfaces

2010-11-30 Thread Jonathan Lassoff
On Mon, Nov 29, 2010 at 6:49 PM, Adam Leff a...@leff.co wrote: Also, for what it's worth, I do have multiple logical interfaces under st0 (i.e. st0.0 and st0.1) and it is working without requiring NHTB. Without NHTB? So the security ipsec vpn XXX hierarchy has a bind-interface statement, but

Re: [j-nsp] some questions about junipter router and firewall

2010-11-30 Thread Smales, Robert
Derek Kwok wrote: 2/ How can I increase the line in putty? I can't find it in the setting 1. Right click on the title bar of your PuTTY window to call up a menu. 2. The 12th item on the menu is Change Settings. . . click that. 3. This calls up the PuTTY Reconfiguration window, in the Category

[j-nsp] SRX-3600 Rate limit

2010-11-30 Thread atif naeem
Hi folks , Can any one tell me how to implement rate limit on SRX-3600 .I have junos version 10.0R2.10 . i want to restrict user on 1mb. BR Atif Naeem ___ juniper-nsp mailing list juniper-nsp@puck.nether.net

Re: [j-nsp] JunOS route-based VPN: multiple st interfaces

2010-11-30 Thread Adam Leff
On Tue, Nov 30, 2010 at 3:58 AM, Jonathan Lassoff j...@thejof.com wrote: On Mon, Nov 29, 2010 at 6:49 PM, Adam Leff a...@leff.co wrote: Also, for what it's worth, I do have multiple logical interfaces under st0 (i.e. st0.0 and st0.1) and it is working without requiring NHTB. Without NHTB?

[j-nsp] Juniper M120 - PPM causing issues for BFD

2010-11-30 Thread Payam Chychi
Hi, I was wondering if anyone else has had issues with M based routers and PPM, if so, any advice would be greatly appreciated. Here is my situation: - I have a m120 router that is now running BFD and IS-IS on a few links and OSPF on a few other links (no problem here) - when I take a backup

[j-nsp] SRX and IPv6

2010-11-30 Thread martin papik
Hi, We have SRX device. I need to configure 3 zones (Trust, Untrust, DMZ) and each zone will have one interface in inet6. The DMZ is for DNS IPv6 server and Untrust for Inet and Trust for LAN (ipv6 also). And as second I will need maybe trunk interface for inet6. Please if you have any

Re: [j-nsp] SRX-3600 Rate limit

2010-11-30 Thread DeathPacket
Atif, I put this together to limit itunes traffic to 1mb. Use a firewall filter to police the traffic (I did specify www.apple.com but it resolved the address automatically, this may be an issue when round robin DNS happens). You can more specific (i.e. Port 80 etc..) but I was just checking

[j-nsp] How to connect the SSG500M to a switch 2900 cisco

2010-11-30 Thread Juan Cardoza
Hello I am new at this mailing list, but I need to know how to connect the firewall to a switch cisco, do I need to configure the trunk mode at the cisco switch? I am new with the Juniper and Cisco equipments and I have been trying to find the configuration at the internet, but until now I

Re: [j-nsp] How to connect the SSG500M to a switch 2900 cisco

2010-11-30 Thread Payam Chychi
Hey Juan, It depends on if you are wanting to pass multiple vlans to the switch or have it as a flat vlan. If you need more than 1 vlan then yes, the switch must be setup as a trunk port but if you only need 1 vlan then you can setup the switch as an access port. On the ssg500 you define a

Re: [j-nsp] SRX and IPv6

2010-11-30 Thread Matthew M North
Martin, I am running IPv6 Tunnelbroker from Huricane Electric on my SRX 210 10.3R1.9 no issues. The IPv6 configuration is similar to IPv4 on your SRX. Here is some examples off my SRX, hope it helps, more/better stuff out on google. -- #My Inside interface, dual-stack interfaces { ge-0/0/0 {

[j-nsp] Files tcpdump of Junos on Wireshark.

2010-11-30 Thread David Lockuan
Hi guys, I was testing the hidden command of JunOS, monitor traffic write-file name_files interface xx-X/X/X. In theory, this files is with format tcpdump but when I try to see with Wireshark, it don't show me on detail of the packet. I see that the wireshark detect a protocol juniper, I don't

Re: [j-nsp] Files tcpdump of Junos on Wireshark.

2010-11-30 Thread Chuck Anderson
On Tue, Nov 30, 2010 at 08:47:10PM -0500, David Lockuan wrote: Hi guys, I was testing the hidden command of JunOS, monitor traffic write-file name_files interface xx-X/X/X. In theory, this files is with format tcpdump but when I try to see with Wireshark, it don't show me on detail of the

[j-nsp] Angry EX (STP?)

2010-11-30 Thread cb
Hello, We have three EX4500's in the following configuration: EX4500#1-EX4500#2EX4500#3 | | MX80 (router) We are observing xe-0/0/16 on the EX#2 facing the EX#1 site having its port blocked and unblocked over and

Re: [j-nsp] SRX-3600 Rate limit

2010-11-30 Thread atif naeem
Hi Ben, I configured as per given configuration but i am getting message this is not supported on SRX-3600. policer rate-limit-1mb { if-exceeding { bandwidth-limit 1m; burst-size-limit 124k; } then discard; } filter test { term 1 { from {

Re: [j-nsp] Files tcpdump of Junos on Wireshark.

2010-11-30 Thread Kevin Cullimore
On 11/30/2010 8:47 PM, David Lockuan wrote: Hi guys, I was testing the hidden command of JunOS, monitor traffic write-file name_files interface xx-X/X/X. In theory, this files is with format tcpdump but when I try to see with Wireshark, it don't show me on detail of the packet. I see that

Re: [j-nsp] Angry EX (STP?)

2010-11-30 Thread Felix Schueren
CB, Aug 25 12:13:36 ALBQ_EX4500 mib2d[861]: SNMP_TRAP_LINK_DOWN: ifIndex 536, ifAdminStatus up(1), ifOperStatus down(2), ifName xe-0/0/16 Aug 25 12:14:04 ALBQ_EX4500 last message repeated 20 times Aug 25 12:16:06 ALBQ_EX4500 last message repeated 61 times Aug 25 12:26:05 ALBQ_EX4500 last