Re: [j-nsp] MTU issue between juniper routers

2011-03-28 Thread Pekka Savola
as fragments and dropped in receiver's loopback filters. Even though MTU is high, we've come across unnecessary (IPv6) fragmentation when certain conditions are met - PR/571596 -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems

Re: [j-nsp] general guidelines for installing JUNOS to RE, where HDD and CF are blank

2011-02-11 Thread Pekka Savola
equipment :P -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list juniper-nsp

Re: [j-nsp] Aggregate Routes Revisited

2011-01-14 Thread Pekka Savola
BGP advertise a non-active BGP route as well. But this has no impact in this specific case. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] GRE Bridging, is it possible with a Juniper box ?

2010-06-03 Thread Pekka Savola
it. Then as 'ether type' in GRE header you could put 0x6558 or 0x8100 (IEEE 802.1q VLAN-tagged frames *). The former is also supported in Linux [http://lwn.net/Articles/303062/] *) http://www.iana.org/assignments/ethernet-numbers -- Pekka Savola You each name yourselves king, yet

Re: [j-nsp] M20 FE PIC

2010-03-11 Thread Pekka Savola
it isn't supported, I think, though. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list

Re: [j-nsp] Need suggestions..

2010-02-04 Thread Pekka Savola
, 4 in RIB and 1 in FIB, or something else. I thought the second. A more recent RE could do the trick, but it's a different issue if that's the most sensible approach in the grand scheme of things.. -- Pekka Savola You each name yourselves king, yet the Netcore Oy

Re: [j-nsp] Need suggestions..

2010-02-04 Thread Pekka Savola
On Thu, 4 Feb 2010, sth...@nethelp.no wrote: Not for the M7i/M10i. We have explicitly asked Juniper about a beefier RE for M7i/M10i, and the answer so far has been no plans. Well, I don't know about i's, but FWIW plain old M10 runs e.g. RE-600 (2G memory etc.) just fine. -- Pekka Savola

Re: [j-nsp] vulnerability fix not available for 8.5 ?

2010-01-08 Thread Pekka Savola
, M20). But now I can't find any mention of this in the release notes and I'm pretty sure it was there. In our case, the old non-EFPC seated a I-1OC48-SON-SMIR. I wonder if JNPR brought the support back or something.. -- Pekka Savola You each name yourselves king, yet

Re: [j-nsp] ISIS and BFD

2009-12-28 Thread Pekka Savola
#section-4.1 -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list juniper-nsp@puck.nether.net

Re: [j-nsp] Urgent

2009-12-17 Thread Pekka Savola
On Thu, 17 Dec 2009, Masood Shah wrote: Here you go... http://www.juniper.net/techpubs/software/junos/junos91/swconfig-system-basics/configuring-a-dhcp-server.html According to that doc, DHCP server functionality is only available in J-series, not MX series.

Re: [j-nsp] bfd = busted failure detection :)

2009-12-09 Thread Pekka Savola
of it). Do you have a bug open on this? We did investigate it (on 9.3 though), but the result was it's working as designed, Juniper couldn't replicate the issue and we had to close the case :-(. -- Pekka Savola You each name yourselves king, yet the Netcore Oy

Re: [j-nsp] MX960 JunOS recommendations

2009-11-11 Thread Pekka Savola
, you need to crank it up to 4488.. A thing to keep in mind and/or to monitor using scripts. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] __default_arp_policer__

2009-10-20 Thread Pekka Savola
L2 broadcast traffic that's hitting the RE. 'Family any' L2 policer on loopback would be interesting to test; I've been intending to do that for a while but haven't gotten around to doing so. -- Pekka Savola You each name yourselves king, yet the Netcore Oy

Re: [j-nsp] Compatibilty between FPC and E-FPC

2009-10-19 Thread Pekka Savola
FPC won't run on software newer than 8.5. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing

Re: [j-nsp] Block traceroute and Allow Ping

2009-09-29 Thread Pekka Savola
to support all flavours of traceroute as some of those use the equivalent of ping. Maybe you could match by both TTL and ICMP type/code but that would be hackish. To learn more about how traceroute works, see: http://en.wikipedia.org/wiki/Traceroute -- Pekka Savola You each name

Re: [j-nsp] cannot see hard disk

2009-09-25 Thread Pekka Savola
. There have also been bugs wrt this behaviour, but I recall at least some of them were specific to 8.5 and you were running 8.4. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash

Re: [j-nsp] Miercom Competitive Performance Testing Results: Cisco ASR9000 vs Juniper MX960

2009-09-24 Thread Pekka Savola
will do performance testing in these kind of scenarios as well; I don't recall seeing such a test myself. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] Miercom Competitive Performance Testing Results: Cisco ASR9000 vs Juniper MX960

2009-09-24 Thread Pekka Savola
old, memory/CPU constrained T320 FPCs). But the bad news is that JTAC's response is that this is working as designed. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash

Re: [j-nsp] router protect policy

2009-08-05 Thread Pekka Savola
experience. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list juniper-nsp@puck.nether.net

Re: [j-nsp] Hidden IPv6 Route inside BGP - but why?

2009-07-21 Thread Pekka Savola
route resolution for unresolved could also help. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp

Re: [j-nsp] Rate limit ARP per interface (or JUNOS bug)?

2009-05-15 Thread Pekka Savola
Juniper would have sane defaults but -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing

Re: [j-nsp] Rate limit ARP per interface (or JUNOS bug)?

2009-05-15 Thread Pekka Savola
. It's possible that more load was caused by non-ARP broadcast looped traffic though. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] static route for multicast RPF lookup

2009-04-08 Thread Pekka Savola
-BGP unicast-only routes. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list juniper-nsp

[j-nsp] RPD_MLD_ROUTER_VERSION_MISMATCH message

2009-03-05 Thread Pekka Savola
this fixed internally. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list juniper-nsp

Re: [j-nsp] FPC-Offline on M20 after Upgrade JunOS 8.5 to 9.3

2009-02-08 Thread Pekka Savola
list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] JUNOS resolves indirect next-hops using other BGP routes

2009-02-04 Thread Pekka Savola
feasibility algorithm. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list juniper-nsp

Re: [j-nsp] M10i - %KERN-1-RT_PFE: RT msg op 1 (PREFIX ADD) failed, err 6 (No Memory) / RT msg op 3 (PREFIX CHANGE) failed, err 6 (No Memory)

2009-01-25 Thread Pekka Savola
. It consumes this memory linear to the fib size (regardless of how it's used and on which interfaces). -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] Juniper uRPF implementation

2008-12-03 Thread Pekka Savola
table size. It seems to replicate all the routing tables for its own purposes. This would make little sense (even less than the current dumb algorithm) if it just used routes in PFE. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom

Re: [j-nsp] CoS Marking/Rewrite Theory

2008-10-06 Thread Pekka Savola
/swconfig-cos/assigning-the-rewrite-rules-configuration-to-the-output-logicalinterface.html Pretty annoying. Too bad these kinds of issues seem to crop up more and more, usually after you've already bought the box or a new kind of interface :-/ -- Pekka Savola You each name

Re: [j-nsp] Can't assign requested address ??

2008-08-26 Thread Pekka Savola
an interface was caused problems under certain kind of ip address configurations, AFAIR w/ vrrp or with ipv6 link-locals. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] spmb/ssb/feb/... memory usage details?

2008-05-08 Thread Pekka Savola
On Thu, 8 May 2008, Pekka Savola wrote: You can use the 'show chassis spmb/feb/ssb/...' to view DRAM memory utilization on the switch board. How can you find out what's taking DRAM memory? 'show route summary' on 'vty ssb' (or similar) shows how much your routing table takes but that's all

[j-nsp] spmb/ssb/feb/... memory usage details?

2008-05-07 Thread Pekka Savola
...) Similarly, figuring out the SRAM usage might be interesting. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] NSR, multicast, and VRFs?

2008-05-05 Thread Pekka Savola
will not come up). I guess this persists in 9.1 as well (not tested). We've a case open asking clarification on this but haven't heard back in a while. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security

Re: [j-nsp] redistribute ospf into ISIS

2008-04-23 Thread Pekka Savola
routing protocol preferences (e.g. make IS-IS preferred over OSPF). -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] ifIndex Interface Persistence

2008-04-10 Thread Pekka Savola
reboots and similar events. If you just have one routing engine and it dies (and you replace it with a new one, just copying the config), you will lose the indexes; but the same happens with Cisco unless you copy ifIndex table from NVRAM manually as well. -- Pekka Savola You

Re: [j-nsp] ifIndex Interface Persistence

2008-04-10 Thread Pekka Savola
this these things should be added to the Juniper cluepon wiki -- any volunteers?) -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] JUNOS 9.0 and CF requirement

2008-02-22 Thread Pekka Savola
JTAC case on this but as the card is unsupported and they don't see the problem on their cards, it's closed. I've added this to: http://juniper.cluepon.net/index.php/Flash_compatibility -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom

Re: [j-nsp] atastandbyarmset smartd

2008-02-20 Thread Pekka Savola
. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https

Re: [j-nsp] P-1GE-SFP in standard FPC?

2008-02-13 Thread Pekka Savola
, this information has been lost. For example, it's also pretty much impossible to find out that Enhanced Plus FPC is required if you want to use P-4GE-TYPE1-SFP-IQ2. [1] http://www.juniper.net/techpubs/hardware/m20/m20-pic/gigabit-ethernet-pic-with-sfp.html -- Pekka Savola You each name

Re: [j-nsp] JunOS Bug list?

2008-02-03 Thread Pekka Savola
://puck.nether.net/mailman/listinfo/juniper-nsp -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp

Re: [j-nsp] out-bound anti-spoofing rules when using community-based routing

2008-01-25 Thread Pekka Savola
of this as longest prefix matching wins every time, if you have the same prefixes with the same length, you select one and the rest are considered feasible. RFC 3704 section 2.3 tries to explain this but probably doesn't make it much better than above. HTH, -- Pekka Savola You each

Re: [j-nsp] out-bound anti-spoofing rules when using community-based routing

2008-01-24 Thread Pekka Savola
the same more specifics to you as well, but use a community to mark them so that you won't readvertise them. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] VRRP with Juniper, what is needed around?

2007-12-15 Thread Pekka Savola
to use that link depending on your BGP path selection and the choice of VRRP primar(y|ies). -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

[j-nsp] GE/10GE link-mode config on M/T-series has no effect

2007-12-11 Thread Pekka Savola
is still be supported but it's a no-op. I wonder if there is a valid deployment scenario where you will want to force full-duplex instead of doing auto-negotiation. Now would probably be a good time to start talking to your local Juniper reps :-) -- Pekka Savola You each

Re: [j-nsp] iBGP impacting eBGP

2007-11-05 Thread Pekka Savola
of the routes you export upstream? - where do you get the routes for those nexthops? -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] apply-path and interface addresses

2007-09-08 Thread Pekka Savola
important feature there. On Fri, 7 Sep 2007, Lei Zhang wrote: Pekka Savola wrote: Apply-path is a nice feature, but for some reason it doesn't seem to work for interface addresses, e.g.: apply-path interfaces lo0 unit 0 family inet address *; This works for me. Use config mode command show

[j-nsp] apply-path and interface addresses

2007-09-07 Thread Pekka Savola
). -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https

[j-nsp] enabling IPv6 traffic statistics throws CMFPC errors

2007-08-30 Thread Pekka Savola
PRs on this. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings ___ juniper-nsp mailing list juniper-nsp

Re: [j-nsp] icmpv4-rate-limit

2007-08-22 Thread Pekka Savola
there is a further limit of 500pps per PFE. There is an ER open for raising the ICMP generation rate-limit as well as making that configurable. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George

Re: [j-nsp] PFE_NH_RESOLVE_THROTTLED Message

2007-08-20 Thread Pekka Savola
of years that we've seen them, I've just filtered them out in syslogs. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings

Re: [j-nsp] Ratelimiting ARP-Requests

2007-06-29 Thread Pekka Savola
juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp ___ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp -- Pekka Savola You each name yourselves

Re: [j-nsp] MAC address accounting on shared L2 IX - can it be done?

2007-03-18 Thread Pekka Savola
On Sun, 18 Mar 2007, Pekka Savola wrote: On Sun, 18 Mar 2007, Phil Sykes wrote: A couple of caveats that may be relevant to people configuring this: - It doesn't work on aggregated Ethernet interfaces - It doesn't work on the fixed-optic Gigabit Ethernet PICs (e.g. P-1GE-SX), only

Re: [j-nsp] BGP Peer Route Table Size OID

2007-03-12 Thread Pekka Savola
if another route were to disappear. InPrefixesRejected is clearly meant to show the filtered routes, but alas, the current implementation does not. -- Pekka Savola You each name yourselves king, yet the Netcore Oykingdom bleeds. Systems. Networks. Security