Re: [j-nsp] CVE-2023-4481

2023-08-29 Thread David Sinn via juniper-nsp
A network I operate is going with: bgp-error-tolerance { malformed-route-limit 0; } The thoughts being that there is no real reason to retain the malformed route and the default of 1000 is arbitrary. We haven't really seen a rash of them, so adjusting the logging has

Re: [j-nsp] JunOS RPKI/ROA database in non-default routing instance, but require an eBGP import policy in inet.0 (default:default LI:RI) to reference it.

2023-06-04 Thread David Sinn via juniper-nsp
I'd try the 'notification-rib' chunk in the 'validation' stanza of the routing-instance and see if setting inet.0 there pushes the DB the way you need. Certain versions of JunOS are quite broken going the other way, so I've had to enumerate all of the routing-instances that I want to be sure hav

Re: [j-nsp] QSA modules and DDM/DOM readings

2021-03-05 Thread David Sinn
+1 on a MX10008 as well running 19.4R3.11 using the Mellanox QSA and a 3rd party optic. Xcvr 1NON-JNPR WFEXP96L176 SFP+-10G-LR Physical interface: xe-0/4/1:0 Laser bias current: 39.946 mA Laser output power:

Re: [j-nsp] Spine & leaf

2018-06-27 Thread David Sinn
> On Jun 27, 2018, at 8:40 AM, Thomas Bellman wrote: > > On 2018-06-26 21:38, David Sinn wrote: > >> OSPF scales well to many multiples of 1000's of devices. > > Is that true even for Clos (spine & leaf) networks, and in a single area? Yes for multi-tiered C

Re: [j-nsp] Spine & leaf

2018-06-26 Thread David Sinn
le in my > network. the point being, different use cases, different environments. Always > design your network to allow for forward progression else you will be wasting > more time and dealing with more problems > > On Mon, Jun 25, 2018 at 11:19 AM David Sinn <mailto:ds...@dsinn.

Re: [j-nsp] Spine & leaf

2018-06-25 Thread David Sinn
At most networks scale you won't notice the difference, but OSPF will also converge faster then BGP at very large scale. Adding on top the costs of re-using AS's in a eBGP world, verses mutual-RR with iBGP, having a good summarization plan with OSPF is a bit more trivial and retains a overall n

Re: [j-nsp] Qfabric

2011-02-25 Thread David Sinn
Stefan, Completely agree with you. It's not just financials that want low latency. Two other categories, off the top of my head, are anyone building HPC clusters and anytime you have a virtual element the network is providing the connectivity (disk being a prime example). For HPC, latency is

Re: [j-nsp] DHCP static bindings on J2320

2009-07-16 Thread David Sinn
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I've noticed the same problem on my J's too. Looks to be a uniqueness in the implementation of the DHCP server in JunOS. DHCPd under Linux and Cisco's built-in DHCP server do not exhibit the same behavior. What I've been able to track it to is

Re: [j-nsp] compatible compact flash J6350

2009-06-30 Thread David Sinn
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I'm using a Kingston Elite Pro 4GB on my J2350 for a good while now. Amazon's URL for the item is: http://www.amazon.com/gp/product/B000Y0ZGS2 David ELITE PRO CF CARD On Jun 30, 2009, at 7:35 AM, Patrik Olsson wrote: Hello! I have been using S

Re: [j-nsp] UK adsl config

2009-06-30 Thread David Sinn
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 At least for my DSL setup in the US I needed to set the VCI to be fully qualified: vci 0.35; IIRC when I did just "vci 35" it did not come up. David On Jun 30, 2009, at 6:39 AM, Mike Mainer wrote: Don't know much help this will have but I

Re: [j-nsp] SSH Filter

2009-05-22 Thread David Sinn
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Only thing you might want to consider adding is the "log" keyword to your discard term. Just makes things a little quicker when you add a new protocol that you need the RE to handle that you didn't update your control-plane filter to support (n

Re: [j-nsp] DSL Aggregation - ATM vs. ATM2

2008-12-24 Thread David Sinn
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Dec 23, 2008, at 11:46 PM, Charles Sprickman wrote: interface ATM3/0.1163 point-to-point ip unnumbered Loopback1 atm route-bridged ip SECRET SAUCE HERE pvc 0/1163 encapsulation aal5snap ! The above is what Cisco calls "route bridged

Re: [j-nsp] Junos sticker

2008-12-11 Thread David Sinn
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 When I was last at Juniper EBC in CA they had a stack of them at the entrance. They also made up a new batch that is "I [heart] JUNOS Software" with JUNOS Software in Juniper blue. One was in my copy of JUNOS Enterprise Routing you got free f

Re: [j-nsp] RE/FEB Vitals Monitoring - Cacti

2008-10-02 Thread David Sinn
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 You may also want to check out these: http://forums.cacti.net/about12792.html Works for the J-series I had it pointed at at one point. David On Sep 30, 2008, at 10:24 PM, Nitzan Tzelniker wrote: Hi, If you are tacking about http://forums.cacti.