Re: [j-nsp] Help with BGP as-path regex

2019-09-13 Thread Andy Litzinger
x rejected kind regards, -andy On Thu, Sep 12, 2019 at 9:20 PM Alexander Arseniev wrote: > Hello, > > Does this help? > > > https://www.juniper.net/documentation/en_US/junos/information-products/topic-collections/release-notes/16.1/m-mx-t-series-toc.html > <https://www.jun

[j-nsp] Help with BGP as-path regex

2019-09-12 Thread Andy Litzinger
: "^1234+ .{0,2}" I think with cisco you can do this with backreferences, but Junos doesn't seem to support those. TIA, -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

[j-nsp] minimum permissions for napalm/pyez user

2019-03-15 Thread Andy Litzinger
ectError(host: ip.address, msg: Unexpected session close IN_BUFFER: ` error: unknown command: xml-mode error: permission denied: netconf `) TIA! -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] source address selection for RE generated traffic addresses to direct neighbors

2019-01-23 Thread Andy Koch
-primary-and-preferred-addresses-and-interfaces.html Hope that helps, Andy Andy Koch Hoyos Consulting LLC ofc: +1 608 616 9950 an...@hoyosconsulting.com http://www.hoyosconsulting.com ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https

Re: [j-nsp] Segment Routing Real World Deployment

2018-07-09 Thread Andy Koch
the switch. Do you have a link to the EoS/EoL notices? Thanks, Andy Andy Koch Hoyos Consulting LLC ofc: +1 608 616 9950 an...@hoyosconsulting.com http://www.hoyosconsulting.com ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https

Re: [j-nsp] Firewall filter with apply-path

2015-07-27 Thread Andy Litzinger
Hi Ross, I essentially use the example straight from here: http://forums.juniper.net/t5/Day-One-Books/Day-One-Book-Securing-the-Routin g-Engine-on-M-MX-and-T-Series/ba-p/92276 and they work great. HTH, -andy On 7/27/15, 2:45 PM, juniper-nsp on behalf of Ross Halliday juniper-nsp-boun

Re: [j-nsp] sip calls through srx fail after approx 15 min

2015-05-29 Thread Andy Litzinger
it go to 50m before we ended it). We'll continue to test and monitor and I'll report back here if we have issues. thanks to everyone for their help! -andy On Thu, May 28, 2015 at 12:10 PM, Andy Litzinger andy.litzinger.li...@gmail.com wrote: Hi Majdi, So are you saying that the sip alg can

Re: [j-nsp] sip calls through srx fail after approx 15 min

2015-05-28 Thread Andy Litzinger
/32; } } } thanks, -andy On Thu, May 28, 2015 at 11:41 AM, Majdi S. Abbas m...@latt.net wrote: On Thu, May 28, 2015 at 11:36:20AM -0700, Andy Litzinger wrote: We're configuring a new sip setup with a phone vendor. The provider pbx sits inside our network and makes connections

[j-nsp] sip calls through srx fail after approx 15 min

2015-05-28 Thread Andy Litzinger
truly disabled? If so, any ideas why calls might be dropping at the 15m mark? The phone doesn't actually disconnect, but the call stops working. many thanks, -andy Here's some relevant config snippets: srx01 show security alg status ALG Status : DNS : Enabled FTP : Enabled H323

Re: [j-nsp] MX80 JFlow Setup

2015-01-15 Thread Andy Litzinger
The flow configuration is working as posted- i was testing this in a legacy setup and forgot there was another firewall in the path between my mx80s and my flow collector. thanks all for the help! -andy On Thu, Jan 15, 2015 at 9:44 AM, Andy Litzinger andy.litzinger.li...@gmail.com wrote: Hi

Re: [j-nsp] MX80 JFlow Setup

2015-01-14 Thread Andy Litzinger
, -andy On Tue, Dec 23, 2014 at 9:16 AM, Levi Pederson levipeder...@mankatonetworks.net wrote: All, Trying to get an MX80 to output Flow to an external collector. I've been reading several pieces of documentation and I keep getting differing views and opinions on how this is supposed

Re: [j-nsp] MX80 JFlow Setup

2015-01-14 Thread Andy Litzinger
Yes I do. Sounds like I need to pole a hole? On Jan 14, 2015, at 6:14 PM, Eduardo Schoedler lis...@esds.com.br wrote: Do you have a firewall in your loopback? -- Eduardo Em quarta-feira, 14 de janeiro de 2015, Andy Litzinger andy.litzinger.li...@gmail.com escreveu: Levi, did

[j-nsp] controlling the source IP for the Dns Proxy feature

2014-10-15 Thread Andy Litzinger
to set up a junos-host zone to untrust zone NAT when going to corp-hq IP space? or is there another clever solution? thanks! -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] controlling the source IP for the Dns Proxy feature

2014-10-15 Thread Andy Litzinger
subnets. I would happily use a simple policy on the ASA side like 'permit ip any SRX side IP subnet SRX side mask' if i was confident I wasn't going to have squirrely issues with connectivity. What do you think? -andy On 10/15/14 3:22 PM, Ben Dale bd...@comlinx.com.au wrote: Hi Andy, I have come

Re: [j-nsp] controlling the source IP for the Dns Proxy feature

2014-10-15 Thread Andy Litzinger
widening it on the cisco side to include every IP subnet ('any'). Not sure if that's allowed. Either way it looks like i've got some good options to try. Thank you! -andy On 10/15/14 3:50 PM, Ben Dale bd...@comlinx.com.au wrote: I've certainly had no issue with stability using route-based VPN

Re: [j-nsp] Drawbacks when using QFX5100 and EX4300 in mixed VCF mode

2014-08-21 Thread Andy Litzinger
+1 regarding input on VCF Does anyone have any practical experience with a VCF either mixed-mode or not? We're evaluating it as a replacement for legacy 6509s. Cisco is pitching a Nexus 6004 + FEX solution. regards, -andy On Tue, Aug 19, 2014 at 8:54 AM, Sebastian Wiesinger juniper

[j-nsp] SRX Active/Passive cluster with redundant route based IPSec - connectivity to AWS VPC

2014-05-05 Thread Andy Litzinger
to an AWS VPC? Any tips or tricks you care to share? regards, -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] SRX Active/Passive cluster with redundant route based IPSec - connectivity to AWS VPC

2014-05-05 Thread Andy Litzinger
? thanks! -andy On Mon, May 5, 2014 at 3:30 PM, Morgan McLean wrx...@gmail.com wrote: Use your loopback and put that in a reth. Thanks, Morgan On Mon, May 5, 2014 at 3:23 PM, Andy Litzinger andy.litzinger.li...@gmail.com wrote: Hi All, Two related questions. I have a pair of SRX 3400s

Re: [j-nsp] SA SSL VPN vulnerable to Heartbleed?

2014-04-08 Thread Andy Litzinger
I opened a JTAC case for the same issue. JTAC said their security team is aware of the CVE and they are waiting for fix/recommendation. -andy On 4/8/14 2:51 PM, David B Funk dbf...@engineering.uiowa.edu wrote: We have a SA4500 SSL VPN box with the JTAC recommended 7.4R8.0 release. Testing

Re: [j-nsp] SA SSL VPN vulnerable to Heartbleed?

2014-04-08 Thread Andy Litzinger
OpenSSL to 1.0.1g, and PR 981148 has been submitted for IVE OS to disable TLS heartbeat. SSL VPN (IVEOS) 7.3, 7.2, and 7.1 are not vulnerable On Apr 8, 2014, at 3:41 PM, Andy Litzinger andy.litzin...@theplatform.com wrote: I opened a JTAC case for the same issue. JTAC said their security

[j-nsp] Least impactful way to migrate from private ASN to public ASN

2014-03-28 Thread Andy Litzinger
in this case? thanks! -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] eBGP neighbor link failure detection

2014-03-14 Thread Andy Litzinger
neighbor state change to Established - rpd[1344]: RPD_BGP_NEIGHBOR_STATE_CHANGED: BGP peer x.x.x.x (External AS Y) changed state from OpenConfirm to Established (event RecvKeepAlive) -andy On Thu, Mar 13, 2014 at 5:17 PM, Payam Chychi pchy...@gmail.com wrote: Are you sure? Ive never seen

Re: [j-nsp] eBGP neighbor link failure detection

2014-03-14 Thread Andy Litzinger
Hi John, you might be spot on- graceful restart is configured for this peer and it does look like my side is respecting it: show bgp neighbor snip Options: Preference HoldTime AuthKey GracefulRestart LogUpDown PeerAS Refresh I'll let you know what I find out -andy On Thu, Mar 13, 2014 at 7

Re: [j-nsp] eBGP neighbor link failure detection

2014-03-14 Thread Andy Litzinger
at BGP session initiation. is it fair to say that if you are directly connected to your neighbor and that interface goes down that the expected behavior of GR is it should abort and routes from that neighbor should immediately be removed? -andy On Fri, Mar 14, 2014 at 8:52 AM, Andy Litzinger

[j-nsp] eBGP neighbor link failure detection

2014-03-13 Thread Andy Litzinger
holdtime, but that appears to be set for 30 seconds. I see that cisco has a feature called 'fast-external-fallover' that bypasses the hold-down timer. Is there an equivalent in JunOS? what is the Juniper best practice to handle link failure between eBGP neighbors? thanks! -andy

Re: [j-nsp] eBGP neighbor link failure detection

2014-03-13 Thread Andy Litzinger
- for example during times when i've deactivated the neighbor config. Am I correct in thinking this is because in this scenario even though the RE is taking awhile to remove the routes from the FIB the actual next hop router is still available and thus the routes are still valid? -andy On Thu, Mar 13

Re: [j-nsp] Multicast/Broadcast Packets going to EX CPU

2014-03-05 Thread Andy Litzinger
, but you need to size it appropriately to allow the multicast required in your network (including things like VRRP). HTH, -andy From: juniper-nsp [juniper-nsp-boun...@puck.nether.net] on behalf of Chris Evans [chrisccnpsp...@gmail.com] Sent: Wednesday, March

Re: [j-nsp] Procedure to add a NPC to SRX HA cluster

2013-11-18 Thread Andy Litzinger
Hi Muhammad, yes, JTAC agrees with you :). We installed the NPCs using the KB procedure today and had no issues. thanks! -andy From: Muhammad Atif Jauhar [mailto:atif.jau...@gmail.com] Sent: Saturday, November 16, 2013 10:54 AM To: Andy Litzinger Cc: juniper-nsp@puck.nether.net Subject: Re: [j

Re: [j-nsp] SRX fab links through EX VC- seeing enumerating MAC addresses

2013-11-18 Thread Andy Litzinger
an update- we finally moved our SRX fab links off of the EX switch and the CPU load on the EX did not change. -andy -Original Message- From: juniper-nsp [mailto:juniper-nsp-boun...@puck.nether.net] On Behalf Of Andy Litzinger Sent: Saturday, October 05, 2013 7:51 AM To: Phil Fagan

[j-nsp] Procedure to add a NPC to SRX HA cluster

2013-11-12 Thread Andy Litzinger
://kb.juniper.net/InfoCenter/index?page=contentid=KB26674 which seems overly complicated and possibly not applicable. It seems to deal with the case of wanting to move a live SPC from one slot to another. They say it applies to an NPC- but I'm not moving a live NPC, I'm inserting a new one. thanks! -andy

Re: [j-nsp] SRX1400 Forward Proxy

2013-10-16 Thread Andy Litzinger
into your OS's trusted certificate store. hth, -andy -Original Message- From: juniper-nsp [mailto:juniper-nsp-boun...@puck.nether.net] On Behalf Of EZ Joe Sent: Wednesday, October 16, 2013 1:46 AM To: juniper-nsp@puck.nether.net Subject: [j-nsp] SRX1400 Forward Proxy Hi, Have anyone

Re: [j-nsp] SRX fab links through EX VC- seeing enumerating MAC addresses

2013-10-05 Thread Andy Litzinger
I believe it was set vlans vlan name disable-Mac-learning Xe-2 is not the backup RE. 1 3 are the primary and backups respectively. -andy On Oct 4, 2013, at 6:59 PM, Phil Fagan philfa...@gmail.commailto:philfa...@gmail.com wrote: What was the syntax to kill the learning? This is indeed

[j-nsp] SRX fab links through EX VC- seeing enumerating MAC addresses

2013-10-04 Thread Andy Litzinger
interfaces fab1 fabric-options { member-interfaces { xe-9/0/1; } } srx01 show configuration interfaces xe-1/0/1 srx01 show configuration interfaces xe-9/0/1 srx01 thanks! -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https

Re: [j-nsp] SRX fab links through EX VC- seeing enumerating MAC addresses

2013-10-04 Thread Andy Litzinger
. so I disabled it and let it run for 1 minute (via commit confirm 1). The entries dropped out of the mac-learning-log, but it didn’t have any noticeable impact on my CPU. the mac enumeration still seems like a weird deal though. I’ll report back anything JTAC uncovers. -andy From: Phil Fagan

[j-nsp] expected multicast forwarding behavior with igmp-snooping and local igmp querier

2013-09-17 Thread Andy Litzinger
that subscribe to the same multicast address- not send it to every server in the vlan. does my config seem like a valid way to do this? I don't need to route the multicast across subnets. thanks! -andy here are the relevant config snippets and the iperf and tcpdump commands I'm using: # show

[j-nsp] Framing errors on down interfaces (MX480, 12.3R3.4, MPC4E-3D-32XGE)

2013-09-15 Thread Andy Davidson
explanation ? Andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] trouble setting up link agg between clustered SRX 550 and Cisco 6509

2013-08-19 Thread Andy Litzinger
things back online. Also, although I don't know how reproducible this is for others, it seems like I may have hit a bug somewhere. -andy -Original Message- From: juniper-nsp [mailto:juniper-nsp-boun...@puck.nether.net] On Behalf Of Andy Litzinger Sent: Thursday, August 15, 2013 3

Re: [j-nsp] trouble setting up link agg between clustered SRX 550 and Cisco 6509

2013-08-16 Thread Andy Litzinger
troubleshooting. you'll note that the second interface, 8/2, is also actually shutdown in the config I posted. I have tried setting both to active and both to passive with no luck. -andy -Original Message- From: Per Westerlund [mailto:p...@westerlund.se] Sent: Friday, August 16, 2013 12:54 AM

Re: [j-nsp] trouble setting up link agg between clustered SRX 550 and Cisco 6509

2013-08-16 Thread Andy Litzinger
-group-configuring-cli.html -andy -Original Message- From: Per Westerlund [mailto:p...@westerlund.se] Sent: Friday, August 16, 2013 3:07 PM To: Andy Litzinger Cc: juniper-nsp@puck.nether.net Subject: Re: [j-nsp] trouble setting up link agg between clustered SRX 550 and Cisco 6509

[j-nsp] trouble setting up link agg between clustered SRX 550 and Cisco 6509

2013-08-15 Thread Andy Litzinger
switchport nonegotiate spanning-tree portfast edge trunk end the 6509-B config is identical thanks! -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] Firewall filter -EX4500

2013-07-09 Thread Andy Litzinger
I think your source ip range netmask should be /0, not /32. I.e: 0.0.0.0/0 On Jul 9, 2013, at 6:19 AM, Brijesh Patel brju.pa...@gmail.com wrote: Hi All, EX4500 firewall filter configuration : Connectivity : F5 Load balancer - Ex4500 -- Internet I want to

Re: [j-nsp] Share static routes between routing-instances on EX series

2013-06-20 Thread Andy Litzinger
it? -andy -Original Message- From: juniper-nsp [mailto:juniper-nsp-boun...@puck.nether.net] On Behalf Of Andy Litzinger Sent: Tuesday, June 18, 2013 4:29 PM To: juniper-nsp@puck.nether.net Subject: [j-nsp] Share static routes between routing-instances on EX series I have a network

[j-nsp] Share static routes between routing-instances on EX series

2013-06-18 Thread Andy Litzinger
like to avoid that if possible; it just doesn't seem as clean. thanks in advance! -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

[j-nsp] experience using 10G DAC (twinax) cables between EX and multi-vendor

2013-05-15 Thread Andy Litzinger
fork over the money to use optics? thanks! -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

[j-nsp] QFX vs EX4550 as collapsed core

2013-04-25 Thread Andy Litzinger
caveats? we've also considered collapsing the edge too, but the cost of say an MX-480 with similar port count is about twice that of an MX-80 + QFX/EX thanks! -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net

[j-nsp] SRX upgrade procedure -ready for enterprise?

2013-03-08 Thread Andy Litzinger
. It seems a complicated procedure fraught with peril. Anyone out there have any thoughts (positive/negative) on their experience on upgrading an SRX cluster with minimal downtime? thanks! -andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https

Re: [j-nsp] SRX upgrade procedure -ready for enterprise?

2013-03-08 Thread Andy Litzinger
...@gmail.com] Sent: Friday, March 08, 2013 10:11 AM To: Andy Litzinger Cc: juniper-nsp@puck.nether.net Subject: Re: [j-nsp] SRX upgrade procedure -ready for enterprise? I would never, ever follow that KB. It's just asking for a major outage.. With that said, you have two options. 1) ISSU and 2

Re: [j-nsp] SRX upgrade procedure -ready for enterprise?

2013-03-08 Thread Andy Litzinger
ICU sounds interesting. Any idea why it's not supported on the 550? or is that just documentation lag? -Original Message- From: Clay Haynes [mailto:chay...@centracomm.net] Sent: Friday, March 08, 2013 3:08 PM To: Andy Litzinger; juniper-nsp@puck.nether.net Subject: Re: [j-nsp] SRX

[j-nsp] SRX AV cloud vs on-device

2013-03-01 Thread Andy Litzinger
Hi all, we're looking at an SRX 550 and have been posed with the choice between using the cloud based anti-virus or the on-device. Are there any compelling reasons to pick one over the other? thanks! -andy ___ juniper-nsp mailing list juniper-nsp

Re: [j-nsp] MX - DWDM no link

2012-11-07 Thread Andy Harding
checked. As far as I'm aware mx80 doesn't support tuneable optics you have to buy the right dwdm channel. -- Regards Andy Harding Internet Connections Ltd Direct: 020 7531 5656 Mobile: 07813 975459 Reception: 0800 2888 680 Web: www.inetc.co.uk Email: a...@inetc.co.uk Sent from my iPad On 7 Nov

Re: [j-nsp] Suppress particular messages from syslog

2011-12-30 Thread Andy Vance
/juniper-nsp Cheers, Andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] MX480 troubles.

2011-04-13 Thread Andy Vance
Keith, I have operated MX-480 networks installed with DPC's and within the last year have deployed MX-480's with MPC's/MIC's and haven't experienced the hardware issues you have run into. Based on my experiences with Juniper hardware, I would say you've just had unfortunate luck. Cheers, Andy

Re: [j-nsp] SNMP command: request snmp spoof-trap

2011-04-06 Thread Andy Vance
I assume if it is in the logs as a trap, that a trap was indeed sent. Since the trap should have originated from the RE, you should be able to see it leave the router with 'monitor traffic interface interface' on the interface that is the best route back to your NMS. Cheers, Andy -Original

Re: [j-nsp] MX80-48T Fan Speed Variation

2011-04-05 Thread Andy Harding
We have 5x MX80-48T that all do this so I am interested in the answer too... -- Regards Andy Harding Internet Connections Ltd Phone: 020 7531 5655 Mobile: 07813 975 459 Fax: 01538 382596 Web: www.inetc.co.uk Email: a...@inetc.co.uk ___ juniper-nsp

Re: [j-nsp] ifAlias on sub-interfaces

2011-03-15 Thread Andy Vance
be populated. Cheers, Andy -Original Message- From: juniper-nsp-boun...@puck.nether.net [mailto:juniper-nsp-boun...@puck.nether.net] On Behalf Of Serge Vautour Sent: Tuesday, March 15, 2011 9:43 AM To: juniper-nsp@puck.nether.net Subject: Re: [j-nsp] ifAlias on sub-interfaces Sorry about missing

Re: [j-nsp] BFD timers for OSPF - MX80 - 10.3R2.11

2011-03-03 Thread Andy Harding
We are using bfd on mx80 with 300ms timers and no problems. Only 2 or 3 sessions per box however. -- Regards Andy Harding Internet Connections Ltd Phone: 0870 803 1868 Mobile: 07813 975459 Fax: 0870 803 1781 Web: www.inetc.co.uk Email: a...@inetc.co.uk On 3 Mar 2011, at 17:53, David Ball

Re: [j-nsp] Aggregate Routes Revisited

2011-01-12 Thread Andy Vance
? Cheers, Andy Vance, IP Engineer 360networks 2101 4th Ave., Suite 2000 Seattle, WA 98121 253.307.7546 (c) andy.va...@360networks.com www.360networks.com -Original Message- From: juniper-nsp-boun...@puck.nether.net [mailto:juniper-nsp-boun...@puck.nether.net] On Behalf Of Paul Stewart Sent

Re: [j-nsp] Aggregate Routes Revisited

2011-01-12 Thread Andy Vance
is, and will not be used for forwarding. I don't have a lab available to test quickly, I'm going from memory, I could be wrong... Andy -Original Message- From: Smith W. Stacy [mailto:st...@netfigure.com] Sent: Wednesday, January 12, 2011 10:36 AM To: Andy Vance Cc: Paul Stewart; juniper-nsp

Re: [j-nsp] Aggregate Routes Revisited

2011-01-12 Thread Andy Vance
Is ok to disagree as your captures below prove your point and that you are correct. Apologies for the misinfo Andy -Original Message- From: Smith W. Stacy [mailto:st...@acm.org] Sent: Wednesday, January 12, 2011 12:02 PM To: Andy Vance Cc: Paul Stewart; juniper-nsp Subject: Re: [j

[j-nsp] (no subject)

2010-11-02 Thread Andy Yu
___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] Flow accounting on an M7i

2010-08-19 Thread Andy M.
overload: No Thank you to everyone for the assistance. -Andy On Aug 19, 2010, at 12:08 AM, Doan Nguyen wrote: Starting JUNOS a requirement for cflowd to work is to configure NTP as Stefan pointed out a few emails earlier. --- On Wed, 8/18/10, sth...@nethelp.no sth...@nethelp.no wrote

[j-nsp] Flow accounting on an M7i

2010-08-18 Thread Andy M.
I'm trying to enable flow accounting on one of our M7is. JunOS version is 9.1R8. No matter what I do, I can't get a flow to export. I'd appreciate any input to obvious errors, or tips on other things to try. I've also tried removing sampling from the interface and doing it with a

Re: [j-nsp] Flow accounting on an M7i

2010-08-18 Thread Andy M.
=43788, refid=204.152.184.72, reftime=d016a4a1.c6f63e1b Wed, Aug 18 2010 13:27:45.777, poll=6, clock=d016a4d5.07841ed1 Wed, Aug 18 2010 13:28:37.029, state=4, offset=-0.073, frequency=62.639, jitter=2.050, stability=0.004 -Andy On Aug 18, 2010, at 2:28 PM, Stefan Fouant wrote: -Original

Re: [j-nsp] Flow accounting on an M7i

2010-08-18 Thread Andy M.
I tried both layer-3 and layer-2-3 with no effect. I also manually took the PIC offline and brought it back up. -Andy On Aug 18, 2010, at 2:49 PM, Nathan Sipes wrote: Did you set the services for the card under the chassis section.. fpc 1 { pic 2 { adaptive-services

Re: [j-nsp] (H-)VPLS over LDP, documentation?

2010-08-06 Thread Andy Harding
juniper does support LDP for [H-]VPLS, although they don't shout about it. I have done interop testing between juni mx's tellabs 8800's it works fine ~andy -Original Message- From: juniper-nsp-boun...@puck.nether.net [mailto:juniper-nsp- boun...@puck.nether.net] On Behalf Of Felipe

Re: [j-nsp] J series users bitten by the massive memory use increase with flow mode add, please file jtac cases.

2010-07-22 Thread Andy Davidson
and total resource of that this flow-mode presents. I have no issue with flow features being added, looks great for branch office use. This trade wont come back until there is a rebuild of JUNOS sans enhanced services for J. Pretty please with cherry on top ? Andy

Re: [j-nsp] J series users bitten by the massive memory useincrease with flow mode add, please file jtac cases.

2010-07-22 Thread Andy Davidson
*to* the router, e.g. bgp sessions. Ergo the memory-pit transcends reboots. Best wishes Andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] M20 JunOS Recommendation

2010-07-21 Thread Andy Vance
We currently have all of our M20's on 8.5S4 and have had no issues whatsoever, we upgraded from 7.5-daily. 8.5S4 is an extended release and if you're not chasing features, I'd look into utilizing it. Cheers, Andy Vance Sr. Network Engineer Speakeasy Direct 206.971.5144 . Fax 206.728.1500

Re: [j-nsp] MAC Sticky on EX

2010-07-02 Thread Andy Davidson
with ethernet-switching-options secure-access-port interface blah mac-limit 1 action shutdown. A mac acl can be used as you describe too. Ideally, I would like this mac-limit feature for trunk ports too. Andy ___ juniper-nsp mailing list juniper-nsp

Re: [j-nsp] RE-400 memory upgrade

2010-07-01 Thread Andy Davidson
empirical evidence that 2x512GB certainly would work, or certainly would not work. Best wishes, Andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] RE-400 memory upgrade

2010-07-01 Thread Andy Harding
Andy Davidson wrote: On 30 Jan 2010, at 15:41, Kevin Wormington wrote: 陈江 wrote: RE400 is a standard PC running on Intel Celeron400 and 82443BX mainboard. Your could check SPEC of Intel 82443BX how much DRAM it supported. And I don't think there is any limitation in JUNOS. I took a quick

Re: [j-nsp] ISSU

2010-03-29 Thread andy
in the upgrade. 5. The upgrade will take place for both routing-engines whilst in service. Cheers -- andya...@shady.org --- Never argue with an idiot. They drag you down to their level, then beat you with experience. CCIP, JNCIP #959

Re: [j-nsp] local switching l2circuit not passing traffic

2010-03-12 Thread Andy Harding
to see what is going on? The VLAN numbers at both ends of the l2circuit need to be the same for it to work. This is a very poorly documented limitation of the l2circuit feature. -- Regards Andy Harding Internet Connections Ltd Phone: 020 7531 5655 Mobile: 07813 975 459 Fax: 01538 382596 Web

Re: [j-nsp] local switching l2circuit not passing traffic

2010-03-12 Thread Andy Harding
David Coulson wrote: Is there an alternative method of doing this without having consistent VLAN IDs? On 3/12/2010 9:44 AM, Andy Harding wrote: The VLAN numbers at both ends of the l2circuit need to be the same for it to work. This is a very poorly documented limitation of the l2circuit

Re: [j-nsp] L3VPN advertises the directly connected subnet - why?

2010-01-26 Thread Andy Vance
Without config snapshots of the VRF, the import policy and the export policy, it is difficult to say why you see this behavior, I have some ideas but I don't want to guess. Can you provide config snapshots? I don't want to assume and head down some road that may not be relevant. Cheers, Andy

Re: [j-nsp] IPv6

2010-01-25 Thread Andy Davidson
a straightforward process - Support on Juniper is more uniformly good than on many other technology families, and for this we should be grateful to Juniper. Best wishes Andy Davidson // www.netsumo.com ___ juniper-nsp mailing list juniper-nsp

Re: [j-nsp] How to delete the BGP Route for IPVPN

2010-01-21 Thread Andy Vance
; } term out { from protocol [ direct static ]; then { community add vpn-andy-router1; accept; } } term reject { then reject; Cheers, Andy Vance Sr. Network Engineer Speakeasy Direct 206.971.5144

[j-nsp] junos-jseries-7.4R2.6

2010-01-20 Thread Andy Vance
Does anyone happen to have the 7.4R2.6 jinstall for the J-series laying around? I need a copy and have yet to find one. Cheers, Andy Vance Sr. Network Engineer Speakeasy Direct 206.971.5144 * Fax 206.728.1500 Email ava...@hq.speakeasy.netmailto:ava...@hq.speakeasy.net * Web

Re: [j-nsp] JUNOS

2010-01-08 Thread Andy Davidson
- does this mean it's fixed in this version ? Andy ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp

Re: [j-nsp] Compatible RAM for RE

2009-12-03 Thread Andy Harding
This is the part we normally buy however Crucial no longer list it on their site and the above link doesn't seem to want to ship to the UK... -- Regards Andy Harding Internet Connections Ltd Phone: 020 7531 5655 Mobile: 07813 975 459 Fax: 01538 382596 Web: www.inetc.co.uk Email: a...@inetc.co.uk

Re: [j-nsp] Compatible RAM for RE

2009-12-03 Thread Andy Harding
config as 32Mx8bit which is incompatible with the Intel BX440 chipset used in the RE. It's quite likely that only 50% of the RAM would show up or not work at all. I take your's worked fine? Was this a RE-400 (m7i)? -- Regards Andy Harding Internet Connections Ltd Phone: 020 7531 5655 Mobile: 07813

Re: [j-nsp] Slot zero on the ERX chassis

2009-09-01 Thread Andy Vance
None that I'm aware of, can you shoot a show hard and a show ver from that chassis with the card in? We have GE cards in slot 0 but I don't recall any card type limitation. Cheers, Andy Vance Sr. Network Engineer Speakeasy Direct 206.971.5144 * Fax 206.728.1500 Email ava

Re: [j-nsp] Broken Per-Flow load sharing

2009-08-21 Thread Andy
] family inet there is also: [edit forwarding options hash key] family multiservice http://www.juniper.net/techpubs/software/junos/junos95/swconfig-layer-2/id-load-link-sec.html This is used to layer-2 links can also look at the layer-3 and layer-4 information. Cheers, -Andy On Fri, Aug 21

Re: [j-nsp] DPC-R-40GE-SFP and Transition Media Converter

2009-04-09 Thread Andy Vance
I've seen this in the past with media converters and was able to work around it using gigether-options { no-auto-negotiation; Hope that helps, Andy -Original Message- From: juniper-nsp-boun...@puck.nether.net [mailto:juniper-nsp-boun...@puck.nether.net] On Behalf Of Ozgur

Re: [j-nsp] JUNOSe and ECMP

2008-01-28 Thread Andy
To enable ECMP load balancing: routing-options { forwarding-table { export load-balancing-policy; } } policy-options { policy-statement load-balancing-policy { then { load-balance per-packet; } } On Jan 28, 2008 8:54 AM, Sven Juergensen (KielNET)

Re: [j-nsp] New to Juniper (re-try)

2007-12-27 Thread Andy
[edit] show | compare On Dec 27, 2007 2:06 PM, Wayne Lansdowne [EMAIL PROTECTED] wrote: Hello all, I apologize..my first posting attempt did not come through correctly. I'm new to the Juniper routers having previously worked with Riverstone. Within the Riverstone CLI I had the ability to

Re: [j-nsp] Measuring Fast Reroute

2007-11-13 Thread Andy Lamontagne
flag packets file show /var/log/rsvp.log Hope this helps. -Andy On Nov 13, 2007 1:49 PM, Imran Moin [EMAIL PROTECTED] wrote: Hello everyone, I have a situation where I need to remove Fast Reroute through the RSVP signalled MPLS backbone. However, before doing that, I would like to know how

Re: [j-nsp] load balancing between juniper routers for unequal cost path

2007-11-08 Thread Andy Lamontagne
, you will have 2 equals paths going in 1 direction, and a single path in the other. If you need to move more traffic, then simply add a 3rd, 4th, etc LSP. Please let me know if you need further explanation/configuration samples. -Andy On 11/8/07, Hamid Ahmed [EMAIL PROTECTED] wrote: Hi, Its

Re: [j-nsp] mlppp

2007-08-01 Thread Andy Lamontagne
Yes, this is definitely possible. We have done it using SSG-20 with 2xADSL mini-PIMs at the Customer end, and an ERX on the provider end. On 8/1/07, mixalis mixailidis [EMAIL PROTECTED] wrote: hello Can I aggregate two ADSL lines to act as one thus achiving more bandwidth using mlppp? **

Re: [j-nsp] JunOS Litterature

2007-06-04 Thread Andy Lamontagne
Hi Jad, There is some free training available on Junipers website - http://www.juniper.net/training/technical_education/#web - that may be of help. -Andy On 6/4/07, Jad KAROUT [EMAIL PROTECTED] wrote: Hi everyone, i am a newcomer to the world of Juniper routers. I've tried to self-train so

[j-nsp] runaway MAC interrupt count

2007-04-25 Thread andy
): runaway MAC interrupt count (101) This appears on the console. The hardware is M10i, softawre is 8.2R2.4 thanks -- andy[EMAIL PROTECTED] --- Never argue with an idiot. They drag you down to their level, then beat you with experience

Re: [j-nsp] iBGP convergence time

2007-02-19 Thread andy
-- andy[EMAIL PROTECTED] --- Never argue with an idiot. They drag you down to their level, then beat you with experience. --- ___ juniper-nsp mailing list