[j-nsp] Mpls down qfx 5100

2018-11-10 Thread Rodrigo 1telecom
Hi folks recently we have some trouble with some mpls tunnels sometime these tunnels goes down: Follow out logfiles: Nov 9 20:03:42 PE-REC-A01-BKB-SW-001 jddosd[1769]: DDOS_PROTOCOL_VIOLATION_SET: Warning: Host-bound traffic for protocol/exception TTL:aggregate exceeded its allowed

Re: [j-nsp] Ex4550 sfid process increase cpu

2017-09-17 Thread Rodrigo 1telecom
lear the offending mac address > > Nitzan > >> On Sat, Sep 16, 2017 at 8:07 PM, Rodrigo 1telecom >> wrote: >> Nothing . this switchs is only layer2... >> these vlans passthrough this switch... this is a trunk port >> >> Enviado via iPhone  >&g

Re: [j-nsp] Ex4550 sfid process increase cpu

2017-09-16 Thread Rodrigo 1telecom
Nothing . this switchs is only layer2... these vlans passthrough this switch... this is a trunk port Enviado via iPhone  Grupo Connectoway > Em 16 de set de 2017, às 13:19, Michael Loftis escreveu: > > You don't have GRE or anything do you? As I understand it sfid > basically handles CP

[j-nsp] Ex4550 sfid process increase cpu

2017-09-16 Thread Rodrigo 1telecom
Hi, we have one ex4600 and ex4550 and have a interconnection( vlan) with IX-SP connected on ex4600. this switch is connected on ex4550 and goes to my router my ex4600 have a normal operarion... does not increase any process and cpu have a normal operation. But my ex4550 have a high c

Re: [j-nsp] MX 14.2R7 / PR1177571

2016-10-26 Thread Rodrigo 1telecom
I have use this version on mx480(both re) ... And have the same re(18004x) and does not see this alarm Enviado via iPhone  Grupo Connectoway > Em 26 de out de 2016, às 05:59, Olivier Benghozi > escreveu: > > Yes but with 14.2R6 on re0 and 15.1R4 on re1 (so, during the update). > > Did y

Re: [j-nsp] Suggestion for Junos Version MX104

2016-10-25 Thread Rodrigo 1telecom
When using version 14.1 we had some trouble to run ipfix in sampling 1000:1 ... I have a decrease on interface traffic, when disable it the traffic come up again We change this router, but i have to put on-line again and update to 14.2 Using other mx-104 under j-tac recommended version(

Re: [j-nsp] Suggestion for Junos Version MX104

2016-10-25 Thread Rodrigo 1telecom
Mark, if i want to use flow by ipfix too?! Enviado via iPhone  Grupo Connectoway > Em 25 de out de 2016, às 06:16, Mark Tinka escreveu: > > > >> On 25/Oct/16 10:59, Peter Sikora wrote: >> >> Hi, >> >> currently we have two MX104 running with JUNOS 13.3R8.7 and we want to >> update them so

[j-nsp] Version 14 on mx traffic shape

2016-09-06 Thread Rodrigo 1telecom
Before version 14 i only use firewall policer to limit my customers bandwidth( and use input and output on logical interface policer) , but when i put version 14.2 my router not shape the traffic( only my customer upload is shaped, but download not) I see documentation and talk about to use clas

Re: [j-nsp] Q-in-q on ex4600

2016-05-17 Thread Rodrigo 1telecom
The diferences from my configuration from your configuration is the dot1q-tunneling on vlan Iwill tried to put this Other side i have an ex3300 My ex3300 configurarion is normal... Family ethernet switching etc etc etc. And on vlan i have customers vlan And configured dot1q

Re: [j-nsp] Q-in-q on ex4600

2016-05-17 Thread Rodrigo 1telecom
the one which you reference before? > > HTH, > Graham > > Graham Brown > Twitter - @mountainrescuer > LinkedIn > >> On 17 May 2016 at 09:54, Rodrigo 1telecom wrote: >> >> > Does anyone have some exemple how to configure q-in-q on juniper ex4600 >>

[j-nsp] Q-in-q on ex4600

2016-05-16 Thread Rodrigo 1telecom
> Does anyone have some exemple how to configure q-in-q on juniper ex4600 > switchs?! > Is a different way to configure than 4550 and others... I tried to follow juniper site example but i'm not has sucess On 4550 and 3300 its so easy... > > > __

[j-nsp] Anti-spoofing filter based on apply-path

2015-06-07 Thread Rodrigo 1telecom
Hi folks.. Exists any way to get a route-filter menu existent on my bgp filters using apply-path? I want to get all prefixes list to do a anti-spoofing filter based on my bgp import rules... If my customer have a CIDR 192.168.0.0/20 upto /24 i have to import this prefix by bgp and its will autho

Re: [j-nsp] DDOS_PROTOCOL_VIOLATION_SET: Protocol Reject:aggregate

2014-12-10 Thread Rodrigo 1telecom
Can you put an exame of this configuration Janiszewski?! Enviado via iPhone  Grupo Connectoway > Em 10/12/2014, às 23:54, Wojciech Janiszewski > escreveu: > > Hi, > > Make sure that you have a "discard" next-hop instead of default "reject" in > your aggregate routes. > That should help. >

[j-nsp] Protect-re

2014-11-25 Thread Rodrigo 1telecom
Hi folks... We have some firewall rules to protect our router... But i want to know what kind of rules you guys implement to protec re?! And what you sugest to use?! Enviado via iPhone  Grupo Connectoway ___ juniper-nsp mailing list juniper-nsp@puck