Re: [j-nsp] system archival configuration and filenames

2014-04-01 Thread Victor Sudakov
Ben Dale wrote: > > This was discussed here a little while back - in short there is no > way to archive them unzipped them except to have a server-side > script monitoring the directory you FTP to and doing it for you. > It's inconvenient enough that a TFTP server cannot be used to store configs

Re: [j-nsp] Best device to fit for a project

2014-04-01 Thread Per Granath
The smaller SRX100/SRX210 have external power supply, so you can always consider using a single SRX but install a spare power supply at each site. ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper

Re: [j-nsp] Best device to fit for a project

2014-04-01 Thread Ben Dale
I've always felt that clusters in the branch isn't much of an advantage availability-wise when you only have a single WAN service. You still you have to have a way of delivering a single carrier port into two physical boxes, which generally involves more hardware (switches) to try and move the

Re: [j-nsp] Best device to fit for a project

2014-04-01 Thread Morgan McLean
As already mentioned, run an SRX220 cluster (two devices) at each branch, and then use something like an SRX1400 for the core. Could even run two of them at the core in a cluster and be super fancy :). Thanks, Morgan On Tue, Apr 1, 2014 at 3:40 PM, Ben Dale wrote: > Check out AutoVPN as well:

Re: [j-nsp] Admin Password change issue !!

2014-04-01 Thread Samol
In Junos, username as lower case and upper case are different, ADMIN is one user and admin is another user. 2014-03-29 1:33 GMT+07:00 Harri Makela : > Hi There > > I am trying to change Admin password on our devices. Problem is that even > after changing the admin password, I am still able to lo

[j-nsp] SRX PPPoE experience and scaling values.

2014-04-01 Thread Шепелев Андрей
Good day everyone. so far i was thinking about using SRX model as cheap PPPoE subscriber device, with radius authorization and accounting, so have anyone tried using it like this? any experience or options? thx. ___ juniper-nsp mailing list juniper-nsp@

Re: [j-nsp] MX80-48T rear slot and 2XGE MIC

2014-04-01 Thread Шепелев Андрей
http://paste.ubuntu.com/7189026/ http://paste.ubuntu.com/7189039/ on This url`s you can see that there an additional mic in the chassiss and it works. so we can get 6XGE in 48T, which can give us lower price for each port i think ) 2014-04-01 14:52 GMT+06:00 Шепелев Андрей : > One my friend put

Re: [j-nsp] system archival configuration and filenames

2014-04-01 Thread Ben Dale
Hi Victor, This was discussed here a little while back - in short there is no way to archive them unzipped them except to have a server-side script monitoring the directory you FTP to and doing it for you. As for the naming, that is odd - the standard format for these files is: router-name_jun

Re: [j-nsp] Best device to fit for a project

2014-04-01 Thread Ben Dale
Check out AutoVPN as well: http://www.juniper.net/techpubs/en_US/junos12.1x44/topics/concept/security-autovpn-spoke-authentication-understanding.html It's hub-and-spoke (as opposed to full-mesh) and a little simpler than GDOI, but you do take the overhead of having to managing PKI across your fl

[j-nsp] system archival configuration and filenames

2014-04-01 Thread Victor Sudakov
Dear Colleagues, I have configured the following: admin@sw-us-parabel> show configuration system archival configuration { transfer-on-commit; archive-sites { "ftp://cfg@10.14.140.125/ " password "$9$WqR8X-4oGiHm24"; ## SECRET-DATA } } on an EX4200 with JUNOS 12.3R3.4. The fi

Re: [j-nsp] maximum BGP multipath ECMP supported on M7i or M10i routers?

2014-04-01 Thread Yucong Sun
Thanks, that's what I mean by consistent hashing :-D But just to clarify, were you talking about juniper routing device that has this feature or are you referring to security device? On Tue, Apr 1, 2014 at 4:26 AM, Vitkovský Adam wrote: > > if i started with pre flow 8 ecmp route to a single /3

Re: [j-nsp] maximum BGP multipath ECMP supported on M7i or M10i routers?

2014-04-01 Thread Vitkovský Adam
> if i started with pre flow 8 ecmp route to a single /32, later removed one > route, would packets all be redistributed over 7 route? this would break in > flight tcp sessions to the vip. Well flows utilizing the failed path would be spread across the remaining 7 paths. But any particular flow

Re: [j-nsp] Best device to fit for a project

2014-04-01 Thread R S
2 x SRX1k or 2k could be a good idea but it's not what I was asked for... I'll try a poll from the price list seems cheaper SRX6k or SRX14k than MX5... GDOI works just with single box ? and what about SSG ? regards > Subject: Re: [j-nsp] Best device to fit for a project > From: p...@weste

Re: [j-nsp] Best device to fit for a project

2014-04-01 Thread R S
the hub have to support the sum of all the branches, hence definetely more than 1 Gbs... you're arrived to my same conclusion, I'd a look to MX but it's a bit more expensive... tks > From: bd...@comlinx.com.au > To: dim0...@hotmail.com > CC: juniper-nsp@puck.nether.net > Subject: Re: [j-nsp] Be

Re: [j-nsp] MX80-48T rear slot and 2XGE MIC

2014-04-01 Thread Шепелев Андрей
One my friend put 2XGE MIC in a rear slot of MX80-AC router and it was shown in sh cha hard output ) so i `m thinking it will do the trick, but i`m not shure about MX80-48T model 2014-04-01 14:47 GMT+06:00 Jayaraj Shantharam : > Hi, > > What I understand is the rear slot is for the services card

[j-nsp] MX80-48T rear slot and 2XGE MIC

2014-04-01 Thread Шепелев Андрей
Hello everybody ) I`ve been thinking about very interesting thing. All MX80 Routers have rear slot for MS MIC, even MX80-48T. MX80-48T have a fixed structure but, we can put a 2XGE MIC in a rear slot i think. And Got 6XGE router. Any one have some thoughts or experience on this? Thx ^) _

Re: [j-nsp] maximum BGP multipath ECMP supported on M7i or M10i routers?

2014-04-01 Thread Krasimir Avramski
The security devices have consistent hashing, but here ecmp seems limited to 16. Not sure for high end routing line Krasi On 1 April 2014 11:08, Yucong Sun w

Re: [j-nsp] Best device to fit for a project

2014-04-01 Thread Per Westerlund
Another possibility is a cluster of units to take care of the dual PSU requirement. For the low end you can mount 2 SRX100 in a 1U tray, and make them a cluster. Will not handle 100Mbps IPsec, but will do 10 Mbps easily, perhaps 50 Mbps depending on how you count and configure (50 bidir is actu

Re: [j-nsp] maximum BGP multipath ECMP supported on M7i or M10i routers?

2014-04-01 Thread Yucong Sun
Thanks, do you have any insight on the consistent hashing? if i started with pre flow 8 ecmp route to a single /32, later removed one route, would packets all be redistributed over 7 route? this would break in flight tcp sessions to the vip. Cheers. On Tuesday, April 1, 2014 12:59:50 AM, Krasimi

Re: [j-nsp] maximum BGP multipath ECMP supported on M7i or M10i routers?

2014-04-01 Thread Krasimir Avramski
Hi, Two types of balancing supported: per prefix (bgp multipath) and per flow (ECMP next-hop including bgp multipath) Up to 64 ECMP next-hops on MX(DPC, MPC), M120, M10i(Enhanced CFEB), M320( FPC dependent), T(FPC dependent) for RSVP, LDP, ISIS(ipv4/6), OSPF(ipv4/6), IBGP(ipv4/6), EBGP(ipv4/6). Sy

Re: [j-nsp] Best device to fit for a project

2014-04-01 Thread Ben Dale
SRX550 is pretty much your only option in the branch if you require dual power supply, but is in every other way overspecced (and thus priced) for the remainder of your branch requirements. If you can do without the RPS, then I'd go with either an SRX220 or 240, which will easily handle the rem