Re: [j-nsp] Config ordering of security address-book and address-set members

2014-03-07 Thread Ge Moua
or maybe use 'sort -u' to only see unique matches; 'sort' by itself would contain hit count per unique entry though . . . . but you get the idea :-) Regards, Ge Moua moua0...@umn.edu University of Minnesota Alumnus -- On 3/7/14, 6:16 AM, Ge Moua wrote: quick & dirt

Re: [j-nsp] Config ordering of security address-book and address-set members

2014-03-07 Thread Ge Moua
could put a shell / script wrapper around this for more elegant automation * traditional srx junos style config with stanza would require multiple line parsing * set-style config is easier to pars due to flat parameter I like to hear of how others do this natively inside srx_shell too; thx !!

Re: [j-nsp] Juniper replacement for Microsoft ISA/TMG?

2013-10-20 Thread Ge Moua
This comes as standard feature on the SRX firewall; albeit with at the expense of cutting throughput by half per platform. https://www.juniper.net/techpubs/en_US/junos12.1/topics/reference/general/security-feature-utm-support.html -- Regards, Ge Moua Univ of Minn Alumnus -- On 10/20/2013 08

Re: [j-nsp] Connecting two spanning-tree domains

2013-08-27 Thread Ge Moua
This is a juniper forum so I apologize ahead of time for the vendor-C reference below (but standards-based L2 works mostly the same across all vendor implementations): https://supportforums.cisco.com/thread/344842 -- Regards, Ge Moua Univ of Minn Alumnus -- On 08/27/2013 08:16 AM, Johan

Re: [j-nsp] Connecting two spanning-tree domains

2013-08-27 Thread Ge Moua
IIRC once joined, the MST and r-pvst L2 domains will speak CST (as a common denominator). You may want to consider pruning vlans where only needed (esp if you have a high vlan count on either or). -- Regards, Ge Moua Univ of Minn Alumnus -- On 08/27/2013 03:56 AM, Johan Borch wrote: Hi! I

Re: [j-nsp] Tricks for killing L2 loops in VPLS and STP "BPDU-less" situations?

2012-08-17 Thread Ge Moua
What about TRILL? Not sure if Juniper has jumped on the TRILL bandwagon yet. -- Regards, Ge Moua Univ of Minn Alumnus -- On 08/17/2012 11:06 AM, Wayne Tucker wrote: On Fri, Aug 17, 2012 at 8:08 AM, Clarke Morledge wrote: We have had the unfortunate experience of having users plug in small

[j-nsp] order of operations for NAT & zone policy enforcement / SRX

2012-07-06 Thread Ge Moua
ated. -- -- Regards, Ge Moua Univ of Minn Alumnus -- ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp