[j-nsp] mpls lsp mapping

2012-09-08 Thread Vladislav A. VASILEV
Hi all, I have a requirement that all prefixes coming from various PE routers in my AS get mapped to a default LSP. The default term is after any other terms I have for mapping various services to statically routed LSPs. -term DEFAULT_FROM_10.10.10.10 { -from { -protocol

Re: [j-nsp] Best way to detect abnormal traffic without enabling security?

2012-09-08 Thread Mark Radabaugh
My suggestion would be a managed Ethernet switch on whichever side of the J2350 that you can put it with a SPAN port to dump traffic to Wireshark. It should be fairly easy to spot the offending traffic. Mark On 3/31/12 12:50 AM, Yucong Sun (叶雨飞) wrote: Hi, I am currently using a pair of

Re: [j-nsp] Best way to detect abnormal traffic without enabling security?

2012-09-08 Thread Tim Eberhard
Additionally Netflow/jflow sampling would provide a greater level of insight. Careful with the sampling rate however as you don't want to make the ddos worse... There are lots of free and paid products that will analyze jflow. Juniper sells a Q1 labs product they call STRM. It does a great

Re: [j-nsp] SRX Static NAT - Not working in both directions

2012-09-08 Thread ashish verma
are you using routing instance? On Sat, Sep 8, 2012 at 11:01 AM, Patrick Dickey dickeypj...@yahoo.comwrote: I'm a little confused here. Where does the 192.168.17.16 network reside? The static NAT will only NAT the 192.168.35.200 IP when its initiating traffic to the FROM zone in the static