Re: [j-nsp] Breaking an EX cluster?

2015-08-13 Thread Richard Gross
http://forums.juniper.net/t5/Ethernet-Switching/Disable-Virtual-Chasis-on-EX4200/td-p/46663 Specifically: First delete all config under "edit virtual-chassis", but to remove all evidence of vc on it you need to go into the shell: Start shell Delete all files under /config/vchassis rm *.* Remo

Re: [j-nsp] Help needed with IPSEC VPN on J-Series

2013-03-20 Thread Richard Gross
When I had nothing in the proxy-identity the show security ipsec security-associations showed UP but did not pass traffic. show configuration security ipsec vpn test-vpn bind-interface st0.0; vpn-monitor { source-interface lo0.1; destination-ip 192.168.199.146; } ike { gateway test-vpn

[j-nsp] DDOS and MX-240's

2013-01-06 Thread Richard Gross
Dear List, I am seeking advise. If you wanted to block 800K /32's from your inbound pipes, how would you do it? Would you null route? Put up multiple stanza firewall filters? Which way has the least amount of hit on router resources? If you would prefer to reply off-list, that would be supe