Re: [j-nsp] IPv4 Filter for ECN/CWR tcp bit (RFC3168)

2015-11-27 Thread Daniel Verlouw
Hi Jonas, On Fri, Nov 27, 2015 at 2:20 PM, Jonas Frey (Probe Networks) wrote: > Does anybody have any idea if its possible to filter for such traffic? have you looked at the firewall flexible match conditions? (avail in 14.2 for MX/MPC). https://www.juniper.net/techpubs/en_US/junos14.2/topics/c

Re: [j-nsp] Suggestions on management of dual-RE devices

2015-11-27 Thread Michael Loftis
On Wed, Nov 25, 2015 at 7:14 AM, Mike Williams wrote: > Thanks to all those who responded. > master-only is mostly what I wanted! > > > Rather confusingly, Juniper do specify setting lo0 per RE. > https://www.juniper.net/techpubs/en_US/junos12.3/topics/task/configuration/routing-engine-dual-initia

[j-nsp] IPv4 Filter for ECN/CWR tcp bit (RFC3168)

2015-11-27 Thread Jonas Frey (Probe Networks)
Hello, i am trying to filter IPv4 traffic based on the tcp-options, in detail i am looking to filter for traffic with options CWR and ECN set (RFC3168). It seems this is not possible on current MX gear running 14.2. From the docs juniper only lists 6 of the current 8 tcp-options available to filt

Re: [j-nsp] Where and how to inject the default route in DFZ

2015-11-27 Thread Damian Holdcroft
Could you use a script to check CPU utilization and kill the default while the box is crunching the feed? If CPU @ 98% or higher, don't announce? Or similar. On Fri, Nov 27, 2015, 19:10 Stepan Kucherenko wrote: > I just use a generated 0/0 route which is active only if I receive > specific pref

Re: [j-nsp] Where and how to inject the default route in DFZ

2015-11-27 Thread Stepan Kucherenko
I just use a generated 0/0 route which is active only if I receive specific prefixes from upstream(s). If you don't want 0/0 in FIB then just add no-install. Not perfect but better than no delay at all. I wish I could say something like "thos route is active when there are X routes received