Re: [j-nsp] LAN encription

2015-12-14 Thread Jeff McAdams
Last I checked (a month or so ago?) there is only a single MIC (20x1gbps maybe) that can do MacSec on the MX. I think the plan is for future MPCs to support it with any enet MICs connected, but it's not there, yet. I don't know for the full QFX line, but the EX4600s I have supposedly can do lin

Re: [j-nsp] Site-To-Site VPN woes again

2014-05-06 Thread Jeff McAdams
You might consider (at least as a workaround) using lt- interfaces as "additional loopbacks". I've had success using lt- ints as holders of a gateway IP when, for reasons like what you mentioned, I didn't want them on a physical interface and couldn't make it work on a loopback (not being able t

Re: [j-nsp] SRX MPLSoGREoIPSec

2014-04-15 Thread Jeff McAdams
I've got a fair sized setup going with a bunch of these. Shipping SRX100's to partner organizations connecting back to SRX650s running the IPSec and MX240s running the GRE tunnels and MPLS. I'm using VPLS primarily, but did some proof-of-concept setups with l2circuit/ccc. Truthfully, I haven't d