Re: [j-nsp] GRE packet fragmentation on j-series

2012-01-30 Thread Ben Dale
Hi Lukasz, J-Series only needs a license to download signature updates for IDP - in order to stop fragmentation, all you need to do is create a security policy that matches on GRE traffic "match application junos-gre" and then references the idp engine in the action "then permit application-ser

Re: [j-nsp] Recommended Releases now posted for MX, M, T, QFX

2012-01-30 Thread Chris Cappuccio
that only took...about 5 years ? sweet, juniperdude. Chris Kawchuk [juniperd...@gmail.com] wrote: > Just noticed this today - Seems JNPR has filled out the recommended release > JunOS matrix for all the products now (incl M, T, MX, QFX) > > http://kb.juniper.net/InfoCenter/index?page=content&id=

Re: [j-nsp] Filter on lo0, MX80

2012-01-30 Thread Pajlatek
Hello Jonas, You should use the new template for securing your router, use this book. http://www.juniper.net/us/en/community/junos/training-certification/day-one/fundamentals-series/securing-routing-engine/ Also when you finish always check all connections to RE with this command: show sy

Re: [j-nsp] Junos 10.4R8 on MX (PR 701928)

2012-01-30 Thread Jim Boyle
Hi Daniel, just an update on this. The PR now has a workaround outlined and it can be implemented via a script. You mentioned our "beta" PR search, and we will be launching that officially this week at http://prsearch.juniper.net. For this PR, customers with a valid support contract can acce

Re: [j-nsp] Filter on lo0, MX80

2012-01-30 Thread Jonas Björklund
On Mon, 30 Jan 2012, Stacy W. Smith wrote: On Jan 30, 2012, at 1:05 AM, Per Granath wrote: Im trying a basic filer to deny traffic to lo0. SSH, OSPF and ICMP is allowed. It doesnt work, it allows all traffic. Same filter work on a ge-interface. ge-1/0/0 { unit 0 { family inet

Re: [j-nsp] Recommended Releases now posted for MX, M, T, QFX

2012-01-30 Thread James Jones
I am just curious what issues you guys are having with the junos releases? I am currently not having issues with any of my Juniper kit. It would be interesting to understand the use cases in which you are seeing issues. Sent from my iPhone On Jan 30, 2012, at 6:39 AM, Mark Tinka wrote: > On M

Re: [j-nsp] Filter on lo0, MX80

2012-01-30 Thread Stacy W. Smith
On Jan 30, 2012, at 1:05 AM, Per Granath wrote: >> Im trying a basic filer to deny traffic to lo0. >> SSH, OSPF and ICMP is allowed. >> >> It doesnt work, it allows all traffic. >> >> Same filter work on a ge-interface. >> >> ge-1/0/0 { >> unit 0 { >> family inet { >> f

Re: [j-nsp] Recommended Releases now posted for MX, M, T, QFX

2012-01-30 Thread Mark Tinka
On Monday, January 30, 2012 07:31:39 PM Derick Winkworth wrote: > R9 will be good... we hope. That's what we always say starting from R4, and yet here we are... again :-). Mark. signature.asc Description: This is a digitally signed message part. __

Re: [j-nsp] Recommended Releases now posted for MX, M, T, QFX

2012-01-30 Thread Derick Winkworth
10.4R9?  This makes me very happy...  I thought they were going to stop at R8.   I think they really need/want a golden release for the MX and R8 was supposed to be it. R9 will be good... we hope.   Derick Winkworth  CCIE #15672 (RS, SP), JNCIE-M #721  http://packetpushers.net/author/dwinkworth/

Re: [j-nsp] Recommended Releases now posted for MX, M, T, QFX

2012-01-30 Thread Paul Stewart
Hey Chris yeah, that just showed up about 2 weeks ago (at least that's when I noticed it). Since JTAC isn't supposed to provide you with recommended releases on M/T/MX, at least this KB is a reference point... also nice to see them update the MX recommended release ;) Paul -Original Mess

[j-nsp] Recommended Releases now posted for MX, M, T, QFX

2012-01-30 Thread Chris Kawchuk
Just noticed this today - Seems JNPR has filled out the recommended release JunOS matrix for all the products now (incl M, T, MX, QFX) http://kb.juniper.net/InfoCenter/index?page=content&id=KB21476 - Chris. ... Riding the 10.4 MX Release Train. Next Stop, R9.

[j-nsp] Únete a mi red en LinkedIn

2012-01-30 Thread Maurice Gil Cruz a través de LinkedIn
LinkedIn Maurice Gil Cruz ha solicitado añadirte como contacto en LinkedIn: -- Me gustaría añadirte a mi red profesional en LinkedIn. Aceptar invitación de Maurice Gil Cruz http://www.linkedin.com/e/u96119-gy18slbe-16/XqZSB0oknt5cTY

Re: [j-nsp] Filter on lo0, MX80

2012-01-30 Thread Per Granath
> Im trying a basic filer to deny traffic to lo0. > SSH, OSPF and ICMP is allowed. > > It doesnt work, it allows all traffic. > > Same filter work on a ge-interface. > > ge-1/0/0 { > unit 0 { > family inet { > filter { > input admin-access; >