Re: [j-nsp] Meltdown and Spectre

2018-01-08 Thread Benoit Plessis
Le 08/01/2018 à 10:18, Gert Doering a écrit : > Hi, > > On Mon, Jan 08, 2018 at 10:13:16AM +0100, Thilo Bangert wrote: >>> Only if said person can execute *arbitrary* code. Which you can't on my >>> routers, no matter what sort of account I'm giving you. >> You mean like >> >> $ start shell > This

Re: [j-nsp] SRX and http/https proxy

2017-12-21 Thread Benoit Plessis
On 20/12/2017 23:00, Roger Wiklund wrote: > You can download the latest signature here: > > https://kb.juniper.net/InfoCenter/index?page=content&id=KB27038 > > Try this: > > 1. unzip the file, then gunzip all gz files: gzip -d *.gz > 2. copy all files to the device with scp: scp -r * > root@ip:/var

Re: [j-nsp] ARP Table Timer vs. MAC Table Timer on Juniper

2017-12-20 Thread Benoit Plessis
On 20/12/2017 10:24, Saku Ytti wrote: > On 20 December 2017 at 00:13, NK NSP wrote: > >> "Hardware Resource exhaustion" comes into mind for keeping shorter value >> for MAC Table. Keeping the value high enough can bite you when there is a >> flood of traffic from random sources. > This argument se

Re: [j-nsp] SRX and http/https proxy

2017-12-14 Thread Benoit Plessis
Sorry i lost Roger's mail so this might bork the thread .. > Two options on the top of my head: > > 1. Use Security Director, that will download the signature to the server > and then push it to the device. (SD will also give you lots of other > benefits/visibility) > 2. Download the update to a w

[j-nsp] SRX and http/https proxy

2017-12-12 Thread Benoit Plessis
rectly communicate with the proxy for "https" requests. I tried with 17.3R1.10, 12.1X46-D15.3, 12.3X48-D40.5 with the same result each time. A case is pending openning over juniper support but the support contract of the SRX345 isn't openned yet, so i though of reaching over there, d

Re: [j-nsp] Copper transcievers in QFX5100, EX4600 and ACX5048

2017-12-05 Thread Benoit Plessis
Le 05/12/2017 à 16:40, Alain Hebert a écrit : >     Rofl, > >     That's why!!! > >     We where wondering why 0 & 2 worked but not 0 & 1. Did you mean you were able to plug them in and they didn't work ? ___ juniper-nsp mailing list juniper-nsp@puck.net

Re: [j-nsp] SRX - CPU utilization exceeds

2017-09-19 Thread Benoit Plessis
gt;> wrote: > > On Mon 2017-Sep-18 10:07:36 +0200, Benoit Plessis > mailto:b.ples...@doyousoft.com>> wrote: > > [..] to external conditions ("attacks" / scan / ..) > [..] it kindof look inadequat to your need. > > Do you have

Re: [j-nsp] SRX - CPU utilization exceeds

2017-09-18 Thread Benoit Plessis
Le 16/09/2017 à 07:48, sameer mughal a écrit : > Hi, > > Can anyone please review the mentioned below logs and advice me Is this > issue critical and how can I fix this ? Well your firewall is alerting that it is regurlarly out of ressources. I would check if it's due to something you do (modifyi

Re: [j-nsp] BGP behaviour with Juniper router

2015-06-04 Thread Benoit Plessis
Hi, Here is what i know, and what i've been able to find: I don't think there is automatic grouping of neighbor in junos, you have to make the groups by yourself, example: > show configuration protocols bgp group external-peers { type external; export bgp_public_out; peer-as ...;

Re: [j-nsp] EX4550 apparently dropping IPv6 RA

2014-06-16 Thread Benoit Plessis
Hi, It won't help you i fear but i did see exactly the same defect on some other concurrent platform (cisco 3560G). With the latest IOS software (15.x) a 3560G unit in L3 mode does correctly send RA and reply to RS, but the same unit in L2 mode between a router and a server fail to deliver RA/RS

Re: [j-nsp] Juniper Product against DDoS

2014-02-18 Thread Benoit Plessis
Le 18/02/2014 15:46, Samol a écrit : > Hi Experts, > > Does Juniper provide any DDoS solution ? would you please recommend the > product line for this solution if there is? > > thanks, Hi, No expert here but there is the DDoS Secure appliance on there sales list, something from a company recently