Re: [j-nsp] Per Port Per VLAN rate-limiting on EX series

2014-09-02 Thread Michael Gehrmann
On second thoughts I don't like that example. Here's an example for vlans policing: set vlans MIVCC8256006 filter input MIVCC8256006-Limit set firewall family ethernet-switching filter MIVCC8256006-Limit term Limit then policer 100M-Limit set firewall policer 100M-Limit if-exceeding bandwidth-

Re: [j-nsp] Full table in L3VPN

2014-09-02 Thread Daniel Roesen
On Mon, Sep 01, 2014 at 08:53:19PM +0200, Johan Borch wrote: > Is it a good or bad idea to run IP transit (full table ipv4 & ipv6) in a > MPLS L3VPN and rely on the MP-BGP to carry routes around or is it better to > skip the MPLS part and run iBGP between the routers with transit links? I'm very m

Re: [j-nsp] Per Port Per VLAN rate-limiting on EX series

2014-09-02 Thread Michael Gehrmann
You can make use of policers and use them once or many times. Every model should support policers however my experience has been on EX4200 & EX4500. Example from http://www.juniperlab.info/p/interface-rate-limit-on-ex.html: 1. Configure the policer root@juniperlab# set firewall policer Policer

[j-nsp] Juniper, añádeme a tu red de LinkedIn

2014-09-02 Thread Cláudio Duarte via juniper-nsp
Hola, Juniper: Me gustaría conectar contigo en LinkedIn. Cláudio Duarte Analista de Redes Aceptar: http://www.linkedin.com/blink?simpleRedirect=d3wVcPkVcz8MdzkUc3wScz4VdjR4imVLqnhxt6BSrCACmjdMr7h4nPoZumlbp6lOomxP9zwOnT9BoCRBrlZBt6BSrCAZqSkCpnhFtCVFtSlKbnhMpmdzoiRybmRSrCBvrmRLoORIrmkZpSVFqSdxsDgC

Re: [j-nsp] Full table in L3VPN

2014-09-02 Thread Mike Daniels
2 reasons immediately come to mind as to a good reason to run it in a VRF. Firstly no need for RIB-groups!! :) Secondly you can separate your core / manangement routes from public routes, this can act as another line of defence (as well as good firewall filters of course). -Original Mess