Re: [j-nsp] protect ssh and telnet

2016-04-05 Thread Richard Hartmann
Sorry, I assumed a dual-RE setup, not one where you physically swap the RE. This still sounds as if your CMDB would need to detect that, raise a flag, and then push out new config after being updated; in case of planned maintenance, you could even add that info before the swap. Richard _

Re: [j-nsp] protect ssh and telnet

2016-04-05 Thread Richard Hartmann
On Tue, Apr 5, 2016 at 11:45 AM, Saku Ytti wrote: > I wish we could make the compromise and have secret keys > stored in config, so that they would survive RE changes. Isn't a list of valid pubkeys enough? You can toss that into known_hosts or your equivalent automagically and be done with it.

Re: [j-nsp] Cisco ME3600 migration to something with more 10 gig ports

2015-07-14 Thread Richard Hartmann
On Tue, Jul 14, 2015 at 2:54 PM, Phil Mayers wrote: > QFX 5100? My experience with that platform and 14.1 has been very unpleasant. 13.2 does not support MPLS PE. > Juniper cited that to us as a collapsed MPLS L3VPN P/PE and claim pretty > good features. Not tried one yet. Interesting; not for

Re: [j-nsp] Experience with QFX5100 13.2 & 14.1

2015-01-15 Thread Richard Hartmann
On Thu, Jan 15, 2015 at 12:30 PM, Darren O'Connor wrote: > I'm currently running the absolute latest version simply to get the fixes I > need. To make sure, that would be 14.1X53-D15? >From how I read the above, it seems the bugs you speak of do not prevent you from running them in production. I

[j-nsp] Experience with QFX5100 13.2 & 14.1

2015-01-15 Thread Richard Hartmann
Dear all, I was wondering what experience, if any, you have had with QFX5100. Of special interest would be what JunOS version you are running, what features you have enabled, and if you consider them production-ready. This question is open-ended on purpose. Thanks, Richard ___

Re: [j-nsp] Spanning tree RJ45 SFP on QFX5100

2015-01-15 Thread Richard Hartmann
While looking through all relevant lists for QFX5100 real-world experience, I realized this was still open. We configured everything following the official documentation. Said documentation was buggy; TAC told us what to do and the documentation has been fixed for some time now. Still thanks for

[j-nsp] Spanning tree RJ45 SFP on QFX5100

2014-10-20 Thread Richard Hartmann
Dear all, we are not done debugging yet, but as of right now, we are having a rather strange effect... Our setup looks as follows: QFX5100 = CStest sw1 = 2960g sw2 = 2960g sw3 = EX3300 sw4 = 2960g sw5 = 2960S CStest sw1 CStest sw2 CStest sw3 CStest sw4 CStest sw5 The effect we're seeing

Re: [j-nsp] QFX5100 3rd party optic/DAC

2014-09-30 Thread Richard Hartmann
On Tue, Sep 30, 2014 at 3:19 PM, Darren O'Connor wrote: > So maybe this cable is only 1000Base? What makes this even more weird is > that the 4300 sees it as the same, but it comes up as 40Gb: FWIW, I have seen 1G and 10G optics which a QFX5100 rejects as Fibre Channel optics which the EX3300 u

[j-nsp] Best practices for syslog configuration

2014-06-25 Thread Richard Hartmann
Dear all, Juniper's syslog is arguably strange, by default. Point in case, with "any warning": * If I try to log in with an existing user and bad password via ssh, a remote syslog message with username and source IP is logged * If I try to log in with a non-existing user and any via ssh, _no_ re

[j-nsp] Experience with QFX5100?

2014-03-07 Thread Richard Hartmann
Dear all, we are looking at QFX5100 at the moment and would like to know if anyone can tell us about its stability. The platform itself is relatively new, but our initial needs are quite sane: * BGP * OSPF * Static routes * MC-LAG * MPLS P We would likely increase this a bit over time as we bec