Re: [j-nsp] Strange Log about GRE Keepalive

2016-01-04 Thread Alireza Soltanian
extension-provider syslog daemon critical > > HTH, > Niall > > > -Original Message- > > From: juniper-nsp [mailto:juniper-nsp-boun...@puck.nether.net] On Behalf > Of > > Alireza Soltanian > > Sent: 04 January 2016 12:02 > > To: juniper-nsp@puck.nethe

Re: [j-nsp] Strange Log about GRE Keepalive

2016-01-04 Thread Niall Donaghy
12:02 > To: juniper-nsp@puck.nether.net > Subject: Re: [j-nsp] Strange Log about GRE Keepalive > > Thanks for the explanation. > > > > I don't have public IP address on this router. I installed some 10GE PICs on other > FPCs(2,3,4). Source of the GRE tunnels is

Re: [j-nsp] Strange Log about GRE Keepalive

2016-01-04 Thread Alireza Soltanian
Thanks for the explanation. I don't have public IP address on this router. I installed some 10GE PICs on other FPCs(2,3,4). Source of the GRE tunnels is IP addresses of those PICs. But GRE tunnel itself is configured on PIC in FPC0 or FPC1. Anyway Keepalive mechanism works fine and reacts to l

Re: [j-nsp] Strange Log about GRE Keepalive

2016-01-04 Thread Roland Dobbins
On 4 Jan 2016, at 18:24, Alireza Soltanian wrote: I did not understand what are saying. I'm trying to say that, PIC or no PIC, you might want to check the config to ensure no tunnels are configured, and also ensure that you've deployed iACLs so that random hosts on the Internet can't send pa

Re: [j-nsp] Strange Log about GRE Keepalive

2016-01-04 Thread Alireza Soltanian
Hi I did not understand what are saying. Anyway I personally installed the modules on the chassis so I am sure there is no PIC Tunnel on FPC2,3,4. GRE source destinations are on Interfaces which reside on other FPCs but GRE tunnel interface is on FPC0 or FPC1. Also I must mention FPC type is dif

Re: [j-nsp] Strange Log about GRE Keepalive

2016-01-04 Thread Roland Dobbins
On 4 Jan 2016, at 18:15, Roland Dobbins wrote: Have you checked the configuration to ensure that there is in fact no tunnel on those FPCs? And have you analyzed the traffic to/from that box to ensure that it isn't speaking GRE on the relevant IP(s)? And have you deployed iACLs to ensure that

Re: [j-nsp] Strange Log about GRE Keepalive

2016-01-04 Thread Roland Dobbins
On 4 Jan 2016, at 18:08, Alireza Soltanian wrote: The point is we don't have Tunnel PIC on these FPCs but we have on FPC0 and FPC1. Have you checked the configuration to ensure that there is in fact no tunnel on those FPCs? And have you analyzed the traffic to/from that box to ensure that i

[j-nsp] Strange Log about GRE Keepalive

2016-01-04 Thread Alireza Soltanian
Hi On our M320 we always have this log: fpc2 pfe doesn't support GRE Keepalives fpc4 pfe doesn't support GRE Keepalives fpc3 pfe doesn't support GRE Keepalives The point is we don't have Tunnel PIC on these FPCs but we have on FPC0 and FPC1. Also GRE keepalive was configured for tunnels