Re: [j-nsp] EX4550 DC Power Supply

2013-05-28 Thread Sean Mentzer
No, those separate inputs are actually connected together in the power supply. There is a description of that on the hardware documentation for the QFX3600 (which uses the same DC power supply as the EX4550): http://www.juniper.net/techpubs/en_US/release-independent/junos/topics/reference/specific

Re: [j-nsp] [OT] unit-level vs interface-level description

2013-05-28 Thread Daniel Roesen
Hi, On Tue, May 28, 2013 at 05:00:25PM +0400, Nick Kritsky wrote: > One additional question: do you use the same approach (description on both > levels) for switch-ports inside DC or in campus network? Assuming that we > talk about regular access level ports that only have unit 0 with "family > et

Re: [j-nsp] SRX 3600 dropped packets - how to debug?

2013-05-28 Thread Phil Mayers
On 28/05/13 14:51, OBrien, Will wrote: The primary use of the dns alg is to reduce session count. This is very apparent on net screens. I reduced 500k sessions down to 400k by turning it on. That said, you can achieve similar results by setting dns specific policies with short timeouts. Out of

Re: [j-nsp] SRX 3600 dropped packets - how to debug?

2013-05-28 Thread Phil Mayers
On 28/05/13 14:40, Julien Goodwin wrote: On 28/05/13 19:40, ashish verma wrote: That said, I can't believe the firewall was *actually* dropping 1500pps of DNS traffic; we'd have widespread problems reported, surely. So, it seems that maybe ALG-processed traffic is being counted under "packets dr

Re: [j-nsp] SRX 3600 dropped packets - how to debug?

2013-05-28 Thread OBrien, Will
The primary use of the dns alg is to reduce session count. This is very apparent on net screens. I reduced 500k sessions down to 400k by turning it on. That said, you can achieve similar results by setting dns specific policies with short timeouts. Will On May 28, 2013, at 8:41 AM, "Julien Goo

Re: [j-nsp] SRX 3600 dropped packets - how to debug?

2013-05-28 Thread Julien Goodwin
On 28/05/13 19:40, ashish verma wrote: >> That said, I can't believe the firewall was *actually* dropping 1500pps of >> DNS traffic; we'd have widespread problems reported, surely. So, it seems >> that maybe ALG-processed traffic is being counted under "packets dropped" >> for "show security flow s

Re: [j-nsp] [OT] unit-level vs interface-level description

2013-05-28 Thread Nick Kritsky
Thank you all for your answers. That gave me a lot to think about. One additional question: do you use the same approach (description on both levels) for switch-ports inside DC or in campus network? Assuming that we talk about regular access level ports that only have unit 0 with "family eth" on th

Re: [j-nsp] SRX 3600 dropped packets - how to debug?

2013-05-28 Thread ashish verma
See if this article helps you (juniper login required) http://kb.juniper.net/InfoCenter/index?page=content&id=KB16509&smlogin=true On Tue, May 28, 2013 at 2:41 AM, Phil Mayers wrote: > On 05/27/2013 03:45 PM, OBrien, Will wrote: > > Are you using any alg? >> > > Ah ha... thanks for the nudge.