Re: [j-nsp] Config archive subtleties

2013-08-07 Thread Saku Ytti
On (2013-08-08 02:38 -0400), Phil Shafer wrote: > What I'd like to see is support for posting the data to https URLs > and some plumbing on a remote web site that makes it trivial to > drop in your repo of choice. Posting as JSON to arbitrary https URL would be have some appealing advantages. You

Re: [j-nsp] Config archive subtleties

2013-08-07 Thread David Siebörger
On Wednesday, 7 August 2013 3:25:57 PM Phil Shafer wrote: > What else can we do to make this more worthwhile? Put the .gz at the end of the filename (or make the name configurable, as Ben Dale suggested) so that this'll work: $ gunzip foo_juniper.conf.gz_20130806_180633 gzip: foo_juniper.conf.gz

Re: [j-nsp] Config archive subtleties

2013-08-07 Thread Phil Shafer
Ben Dale writes: >- checking it into git/subversion rather than just copying it to upstream >folder (hey, a > guy can dream) The issue would have been the need to ship all the various repo technologies. What I'd like to see is support for posting the data to https URLs and some plumbing on a rem

Re: [j-nsp] Config archive subtleties

2013-08-07 Thread Ben Dale
I haven't use this in anger for a while, so apologies if some of this functionality is already available, but how about: - an option to disable compression of the config file - an option to specify the naming convention used - eg: always back up to a single file-name rather than appending the da

Re: [j-nsp] family inet6 on st0.x

2013-08-07 Thread ashish verma
I think you would need to run GRE over ipsec for ipv6 support. On Aug 6, 2013 3:06 AM, "Mike Williams" wrote: > Hey all, > > Am I being dense, or now that 'family inet6' can be configured on an st0.x > interface, does it not actually work? > > > I've configured the following on a pair of J6350 cl

Re: [j-nsp] 答复: 答复: SRX650 full-mesh vpn, ssh not passed

2013-08-07 Thread Payam Chychi
so your valid path was actually invalid? On 2013-08-06 6:43 PM, 徐见 wrote: > Thx for you attention, I have found out the reason, it’s ospf issue, > because ospf generate two next-hop for NET A on node 2. > > > > 发件人: Muhammad Atif Jauhar [mailto:atif.jau...@gmail.com] > 发送时间: 2013年8月5日 21:36 >

Re: [j-nsp] Config archive subtleties

2013-08-07 Thread Misak Khachatryan
I would recommend NOC project, an open source OSS/BSS. It has many goodies, works with lot of hardware. http://www.nocproject.org I use it for bunch of Cisco's, Juniper's and D-Link switches for config archivation, as IP address management with integrated DNS support and lot of other stuff. S

Re: [j-nsp] Config archive subtleties

2013-08-07 Thread Phil Shafer
>7 aug 2013 kl. 18:03 skrev Phil Mayers : > Recently this fell apart on us, as the SSH key on the server changed and the > archival >transfers started to silently[1] fail. Ick. Silence is deadly. This (and the other issues) is now PR 910647. > All of which has me wondering if the feature is m

Re: [j-nsp] Config archive subtleties

2013-08-07 Thread Tammy A Wisdom
Another cisco bug is the npe/rsp crashes when it polls just be aware there's gotchas Sent from my iPhone On Aug 7, 2013, at 11:25, Mark Felder wrote: > On Wed, Aug 7, 2013, at 11:32, Jensen Tyler wrote: >> RANCID? - http://www.shrubbery.net/rancid/ >> >> Works for us and you can monitor multi

Re: [j-nsp] Config archive subtleties

2013-08-07 Thread Per Westerlund
RANCID! If you then augment the basic timed polling setup with SNMP-triggered polling, you can have every committed config backed up, and have a timed poll as backup in case there is some problems with the SNMP traps. /Per Sent from my iPad, please ignore stupid spelling corrections! 7 aug 20

Re: [j-nsp] Config archive subtleties

2013-08-07 Thread Mark Felder
On Wed, Aug 7, 2013, at 11:32, Jensen Tyler wrote: > RANCID? - http://www.shrubbery.net/rancid/ > > Works for us and you can monitor multiple vendors gear. > Put everything in RANCID you will never regret it. Beware of a Cisco/ASA bug that you may run across in existing deployments that don't g

Re: [j-nsp] Config archive subtleties

2013-08-07 Thread Jensen Tyler
RANCID? - http://www.shrubbery.net/rancid/ Works for us and you can monitor multiple vendors gear. Jensen Tyler Sr Engineering Manager Fiberutilities Group, LLC This message may contain confidential and/or privileged information. If you are not the addressee or authorized to receive this for th

Re: [j-nsp] VPN tunnel between OpenSwan and SRX220

2013-08-07 Thread Phil Fagan
try turning up your IKE debug on the SRX to help expose more: >request security ike debug-enable local remote level 15 On Tue, Aug 6, 2013 at 9:55 AM, Laurent CARON wrote: > Hi, > > I'm trying to establish a VPN tunnel between a SRX220 and an OpenSwan box. > > SRX is: > Model: srx220h > JUNOS

Re: [j-nsp] Juniper MX240 to Alcatel SAS-M epipe

2013-08-07 Thread Saku Ytti
On (2013-08-07 17:43 +0200), Mark Tinka wrote: > True, but the OP suggested that some of the web sites he's > browsing don't load correctly, which could allude to an MTU > issue in the data plane. Mea culpa, luckily point remains it does not matter what the eline MTU is. Fully agreed on your s

[j-nsp] Config archive subtleties

2013-08-07 Thread Phil Mayers
All, For several years, we've used "system archival configuration" in "on-commit" mode, to backup each commit to a separate file on an sftp/scp server, then check them individually into subversion. Recently this fell apart on us, as the SSH key on the server changed and the archival transfer

Re: [j-nsp] Juniper MX240 to Alcatel SAS-M epipe

2013-08-07 Thread Mark Tinka
On Wednesday, August 07, 2013 04:22:26 PM Eduardo Barrios wrote: > It's a mixture of Alcatel and Juniper, we always use the > lowest MTU 2102 (this is the MAX MTU on a 7705). Our > M10s do 9192. Even though we might have a primary path > that was discovered @ 9192 we still have to take into > ac

Re: [j-nsp] Juniper MX240 to Alcatel SAS-M epipe

2013-08-07 Thread Mark Tinka
On Wednesday, August 07, 2013 04:24:04 PM Saku Ytti wrote: > MTU in martini is carried in LDP and in kompella in BGP > NLRI as extended community. > In both case it has no effect to actual forwarding nor is > it enforced by padding signaling. > In JunOS martini/l2circuit you can configure arbitrar

Re: [j-nsp] Juniper MX240 to Alcatel SAS-M epipe

2013-08-07 Thread Eduardo Barrios
It's a mixture of Alcatel and Juniper, we always use the lowest MTU 2102 (this is the MAX MTU on a 7705). Our M10s do 9192. Even though we might have a primary path that was discovered @ 9192 we still have to take into account detours and secondary paths that might be 2102. Eduardo -O

Re: [j-nsp] Juniper MX240 to Alcatel SAS-M epipe

2013-08-07 Thread Saku Ytti
On (2013-08-07 11:06 +0200), Tomasz Mikołajek wrote: > Internet but not every webpage work. I think the problem is in MTU in > epipe. Alcatel has MTU 1522. How to calculate MTU size for MX? Thanks for > help in advance. MTU in martini is carried in LDP and in kompella in BGP NLRI as extended comm

Re: [j-nsp] Juniper MX240 to Alcatel SAS-M epipe

2013-08-07 Thread Mark Tinka
On Wednesday, August 07, 2013 04:01:46 PM Eduardo Barrios wrote: > We have a couple of VPLS instances b/t a Juniper M10i and > an Alcatel7705. The difference seems to be 14. > Unfortunately Alcatel does not have an > "ignore-mtu-mismatch" switch. Not sure what ALU do, but if it's anything like I

Re: [j-nsp] Juniper MX240 to Alcatel SAS-M epipe

2013-08-07 Thread Eduardo Barrios
Tom, We have a couple of VPLS instances b/t a Juniper M10i and an Alcatel7705. The difference seems to be 14. Unfortunately Alcatel does not have an "ignore-mtu-mismatch" switch. We also turn on RSVP mtu path discovery (adspec and flowspec TLVs - records MTUs and reports back the lowest MTU f

[j-nsp] Juniper MX240 to Alcatel SAS-M epipe

2013-08-07 Thread Tomasz Mikołajek
Hi All I am triing to configure link between MX240 and SAS-M. I want to terminate Alcatel epipe on MX. I used l2circuit to do this. I can ping address in the Internet but not every webpage work. I think the problem is in MTU in epipe. Alcatel has MTU 1522. How to calculate MTU size for MX? Thanks f