[j-nsp] Which BOGON filter strategy you would recommend IPv4 and IPv6

2016-02-15 Thread Alexander Marhold
Hi ! My customer is a bigger company with customers around the world, which recently connected directly to 4 upstream providers and 1 IX via MX router and BGP Now by searching the internet and googling I do not know which method to use to have up-to date BOGON filtering for IPv4 AND IPV6

Re: [j-nsp] Anyone tried ThreatStop on Juniper integration?

2016-02-15 Thread Chuck Anderson
On Mon, Feb 15, 2016 at 12:46:15PM -0500, Phil Shafer wrote: > Chuck Anderson writes: > >I assume by "ephemeral" database, you mean "configure dynamic" to edit > >the dynamic-db? > > Yup, exactly. > > >Unfortunately, it appears that dynamic-db only works > >for BGP policies, not firewall

Re: [j-nsp] Anyone tried ThreatStop on Juniper integration?

2016-02-15 Thread Phil Shafer
Chuck Anderson writes: >I assume by "ephemeral" database, you mean "configure dynamic" to edit >the dynamic-db? Yup, exactly. >Unfortunately, it appears that dynamic-db only works >for BGP policies, not firewall filters. Also, a bigger problem IMO is >that the dynamic database is not

Re: [j-nsp] Anyone tried ThreatStop on Juniper integration?

2016-02-15 Thread Chuck Anderson
On Fri, Jan 15, 2016 at 03:51:02PM -0500, Phil Shafer wrote: > But most of these issues can be mitigated. For example, they change > config using "cat command-file | cli" which churns the change bits > in the database even when nothing changes; using "load update" will > solve that. In addition,