[j-nsp] SRX Dynamic VPN Active Directory Auth WITHOUT a local user?

2014-03-28 Thread Skeeve Stevens
Again, same area, different topic. We've got AD auth working just fine... but I have over 100 users I want to be able to login to the VPN service. At the moment I can't seem to do AD auth without having the following line: 'set security dynamic-vpn clients all user skeeve' for each user. Surel

[j-nsp] SRX Dynamic VPN landing in a VRF

2014-03-28 Thread Skeeve Stevens
Hi all, Same topic, different question. On the SRX(SRX550 Cluster) I have a VRF I want VPN users to land in. Maybe I am using the wrong terminology and that isn't how dynamic VPN works on the SRX's? I'd like to be able to have a layer 3 path to the internal network and put routing, firewall res

Re: [j-nsp] Dynamic VPN with Pulse, AD Integration and more

2014-03-28 Thread Skeeve Stevens
That is awesome... Will be trying it this weekend! Any news on the iPad/Android clients supporting dynamic? ...Skeeve *Skeeve Stevens - *eintellego Networks Pty Ltd ske...@eintellegonetworks.com ; www.eintellegonetworks.com Phone: 1300 239 038; Cell +61 (0)414 753 383 ; skype://skeeve faceboo

Re: [j-nsp] Dynamic VPN with Pulse, AD Integration and more

2014-03-28 Thread Jed Laundry
Hey, Just in case everyone missed this, Pulse 5r3 came out 2 days ago, and adds Dynamic VPN support for the OS X client. Looks like someone saw this. Whoever it was, thanks! Thanks, Jed. On 25 March 2014 17:32, Louis Kowolowski wrote: > Briefly, but I didn't put much effort into it (I alrea

Re: [j-nsp] J2300/J4300 FPCs cannot go online

2014-03-28 Thread Sascha Luck
On Fri, Mar 28, 2014 at 10:44:40PM +, Tom Storey wrote: However my FPC is still seemingly refusing to come online: root> request chassis fpc slot 0 online FPC 0 is in transition, try again I'm not sure this is the same issue - TTBOMK the standard routing on J-series doesn't require a licen

Re: [j-nsp] J2300/J4300 FPCs cannot go online

2014-03-28 Thread xxyton
Have you contacted JTAC or where did you get the certificate from? Regards, Alex ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] J2300/J4300 FPCs cannot go online

2014-03-28 Thread Yasser Rana
Please refer to: http://kb.juniper.net/TSB16366. Thanks, -Yasser On 3/28/14 3:44 PM, "Tom Storey" wrote: >Ive just tried this on my J2300 running 9.3r4.4. > >The certificate now appears, unlike before when nothing appeared: > >root> show system certificate >Certificate identifier: FeatureLicens

Re: [j-nsp] J2300/J4300 FPCs cannot go online

2014-03-28 Thread Tom Storey
Ive just tried this on my J2300 running 9.3r4.4. The certificate now appears, unlike before when nothing appeared: root> show system certificate Certificate identifier: FeatureLicense-v4 However my FPC is still seemingly refusing to come online: root> show chassis fpc detail Slot 0 information:

Re: [j-nsp] Admin Password change issue !!

2014-03-28 Thread Chuck Anderson
On Fri, Mar 28, 2014 at 11:33:29AM -0700, Harri Makela wrote: > Hi There > > I am trying to change Admin password on our devices. Problem is that even > after changing the admin password, I am still able to login with the old > password. Following is the ocnfiguration which I have:- > > > > s

Re: [j-nsp] Admin Password change issue !!

2014-03-28 Thread Harri Makela
Hi Mark This is the command which I am applying:- admin@SWT> show system rollback compare 1 0 [edit system login user admin authentication] - encrypted-password "XXX"; ## SECRET-DATA + encrypted-password "XXX"; ## SECRET-DATA On Friday, 28 March 2014, 19:44, Mark Tinka wrote:

[j-nsp] Least impactful way to migrate from private ASN to public ASN

2014-03-28 Thread Andy Litzinger
We have two MX80 routers that currently each have an eBGP neighbor to the same upstream ISP and are iBGP neighbors. We are using the same internal ASN for both iBGP and eBGP. It's the autonomous-system number defined under routing-options. We're adding a second peer and have recently received ou

Re: [j-nsp] J2300/J4300 FPCs cannot go online

2014-03-28 Thread Mircho Mirchev
Tomorrow I test this with 9.3 and keep the list posted about the result. In 9.3 there's no specific license to enable all the ports. Seems it's embedded. Sent from my mobile. On 28 Mar 2014 21:41, "Damon Vaughn" wrote: > Please refer to Juniper technical service bulletin TSB16366 that documents

Re: [j-nsp] J2300/J4300 FPCs cannot go online

2014-03-28 Thread Damon Vaughn
Please refer to Juniper technical service bulletin TSB16366 that documents the fix for the certificate issue. - Confidentiality Notice: This email and any of its attachments may be legally privileged and/or confidential. If you are not an intended recipien

[j-nsp] maximum BGP multipath ECMP supported on M7i or M10i routers?

2014-03-28 Thread Yucong Sun
Hi, Does anyone know how many BGP multipath ECMP routes does a M7i/M10i router support? 16? 32 ? 64? I found this document : http://www.juniper.net/techpubs/en_US/junos13.3/topics/reference/configuration-statement/maximum-ecmp-edit-chassis.html which says 16/32/64 but it was only mentioning MP

Re: [j-nsp] Admin Password change issue !!

2014-03-28 Thread Mark Tinka
On Friday, March 28, 2014 08:33:29 PM Harri Makela wrote: > set system login user admin authentication > encrypted-password "xxx" > > set system root-authentication encrypted-password "XXX" Are you issuing encrypted or clear-text passwords? I'm sure you know either option requires a different

[j-nsp] Admin Password change issue !!

2014-03-28 Thread Harri Makela
Hi There I am trying to change Admin password on our devices. Problem is that even after changing the admin password, I am still able to login with the old password. Following is the ocnfiguration which I have:- set system login user ADMIN uid 2004 set system login user ADMIN class super-use

Re: [j-nsp] J2300/J4300 FPCs cannot go online

2014-03-28 Thread Blake Willis
Juniper just released a KB on this: http://kb.juniper.net/InfoCenter/index?page=content&id=TSB16366 Apparently you can add the "v4" cert from 12.1 on boxes running 11.4 or older, but then you need to get a new license from Customer Care in order to make it stop complaining. The KB also confirm

Re: [j-nsp] J2300/J4300 FPCs cannot go online

2014-03-28 Thread Eric Van Tol
> Hi all, > We have a lot of J2300/J4300 routers in educational labs. > Suddenly (this weekend) on all of them all the interfaces (both embedded > and on line cards) disappeared. This was just released: http://kb.juniper.net/InfoCenter/index?page=content&id=TSB16366 Junos License Certificate Exp

Re: [j-nsp] JFLOW

2014-03-28 Thread Timh Bergström
That's JFLOW, and as sthaug pointed out, I don't need 10G at all, it barely hits 3% utilization on the NIC's during peaks. //T On Fri, Mar 28, 2014 at 9:14 AM, Gavin Henry wrote: > On 28 Mar 2014 08:10, "Timh Bergström" > wrote: >> >> We have similar traffic-levels (a bit more actually) and sam

Re: [j-nsp] JFLOW

2014-03-28 Thread sthaug
> We have similar traffic-levels (a bit more actually) and sample 1:100 > and handle the analysis on an E3 3.0Ghz/16GB RAM/2x500GB SATA SW-RAID1 > with 10G card with no problems and loads of capacity to spare. For those traffic levels you certainly don't need a dedicated 10G card for the netflow.

Re: [j-nsp] JFLOW

2014-03-28 Thread Gavin Henry
On 28 Mar 2014 08:10, "Timh Bergström" wrote: > > We have similar traffic-levels (a bit more actually) and sample 1:100 > and handle the analysis on an E3 3.0Ghz/16GB RAM/2x500GB SATA SW-RAID1 > with 10G card with no problems and loads of capacity to spare. > > Is that inline JFLOW and IPFIX? Th

Re: [j-nsp] JFLOW

2014-03-28 Thread Timh Bergström
We have similar traffic-levels (a bit more actually) and sample 1:100 and handle the analysis on an E3 3.0Ghz/16GB RAM/2x500GB SATA SW-RAID1 with 10G card with no problems and loads of capacity to spare. //T On Thu, Mar 27, 2014 at 8:04 PM, Keith wrote: > Hi. > > We just picked up some JFLOW lic