Re: [j-nsp] Flow analysis question

2012-04-08 Thread Asad Ul-Islam
I guess what you want to do is to configure the traffic sampling and send its output to the file in router. Viewing that file can give you real time output like show ip cache-flow in cisco. Have a look at http://www.juniper.net/techpubs/software/junos/junos94/swconfig-policy/confi guring-traffic-s

Re: [j-nsp] Flow analysis question

2012-04-08 Thread Jose Madrid
I understand what you are asking but i am not sure. Maybe the monitor traffic command? Although thats more like tcpdump than viewing netflow. Sent from my iPhone On Apr 8, 2012, at 5:55 PM, Morgan McLean wrote: > That won't show you flows...only routes in control plane and routes in > forward p

Re: [j-nsp] Flow analysis question

2012-04-08 Thread Morgan McLean
That won't show you flows...only routes in control plane and routes in forward plane.. Morgan On Sun, Apr 8, 2012 at 2:35 PM, Giuliano Medalha wrote: > Show route > > Show route forwarding-table > > On Sunday, April 8, 2012, Michael Smith wrote: > > > Hello: > > > > Is it possible on the MX seri

Re: [j-nsp] Flow analysis question

2012-04-08 Thread Giuliano Medalha
Show route Show route forwarding-table On Sunday, April 8, 2012, Michael Smith wrote: > Hello: > > Is it possible on the MX series to look at the flow logs real time? In > Cisco, you can attach to the linecard and do a 'sho ip cache flow' that > shows you the Netflow data. I'm looking for some

[j-nsp] Flow analysis question

2012-04-08 Thread Michael Smith
Hello: Is it possible on the MX series to look at the flow logs real time? In Cisco, you can attach to the linecard and do a 'sho ip cache flow' that shows you the Netflow data. I'm looking for something similar on the MX. Thanks, Mike ___ juniper-

Re: [j-nsp] SSH_Brute_Force events

2012-04-08 Thread Pavel Lunin
4/6/2012 г. 3:08 Tim Hogard wrote: i.e. going from port 22 to 10022 means the attacker needs to scan first > and that makes that job 10^4 times harder. > It's just like if an MX router doing lookups in 400-entries table had 1000 times more performance than this same router looking against the fu

Re: [j-nsp] SSH_Brute_Force events

2012-04-08 Thread Pavel Lunin
We are getting "SSH_Brute_Force" alerts quite often from our Intrusion > prevention systems (IPS) - ISS GX. > > [...] > What could be best practices to handle these alerts ? i.e. > Configure rate-limits to ssh. E. g. n attempts per something from a single IP. JUNOS has such an option under ssh s