BTW,
As I see Kentik in the name of the BGP group
The default Kentik DDoS policie "UDP Fragments Attack" match udp port 0 and the
flowspec rule attached to it match is-fragment and first-fragment
So I don't understand why it send filter that match udp port 0 ?
Did you change the default one ?
Maybe this can help you
https://www.juniper.net/documentation/us/en/software/junos/evpn-vxlan/topics/concept/evpn-routing-policies.html
It is not exactly what you want but it will help
Please test it as I hit a bug when I test it long time ago
Nitzan
On Wed, Jan 19, 2022 at 1:12 PM Nathan Ward
Take a look on this KB
https://kb.juniper.net/InfoCenter/index?page=content=KB35676=EX9208=LIST
The default duplicate-mac-detection settings are far to high
Nitzan
On Mon, Jul 19, 2021 at 4:50 PM Cathal Mooney via juniper-nsp <
juniper-nsp@puck.nether.net> wrote:
> In theory when the VRRP
>
>
> An example of configuring the interfaces follows, all follow this
> pattern with more or less IP's.
> > show configuration interfaces irb.810
> proxy-macip-advertisement;
> virtual-gateway-accept-data;
> family inet {
> mtu 9000;
> address 10.19.11.253/22 {
>
Can you show your irb and protocols evpn configuration please
Nitzan
On Tue, Nov 10, 2020 at 3:26 PM Cristian Cardoso <
cristian.cardos...@gmail.com> wrote:
> Does anyone use EVPN-VXLAN in the Centrally-Routed and Bridging topology?
> I have two spine switches and two leaf switches, when I use
You didn't include protocols evpn
Do you have ?
protocols evpn default-gateway no-gateway-community
Nitzan
On Fri, Sep 11, 2020 at 5:52 PM Cristian Cardoso <
cristian.cardos...@gmail.com> wrote:
> Hi
> My 4 switches are model QFX-5120 48Y-8C and are in version 18.4R3-S4.2.
>
> follow spines and
Does any body know if the LC CPU on the MX204 has less power than the one
in MPC7 or in MX10003 LC
I saw some scaling numbers for subscriber management and it looks like some
numbers are very low on the MX204 compared to MX10003 LC
These are control plane tasks that are distributed to the PFE so I
AFAIK VTEP scale is a lot lower at least in EVPN-VxLAN scenario
But please ask your SE for the exact number as it is not public
Nitzan
On Thu, Sep 26, 2019 at 9:59 AM Vincent Bernat wrote:
> ❦ 25 septembre 2019 18:19 +03, Mohammad Khalil :
>
> > Am working with a customer of mine for DC
I dont see these warnings in 17.3R3
It looks like you should configure it under routing-instance type
virtual-switch
https://www.juniper.net/documentation/en_US/junos/topics/concept/evpn-virtual-switch-overview.html
Nitzan
On Mon, Mar 25, 2019 at 12:01 PM Sebastian Wiesinger
wrote:
> * Rob
AFAIK from LNS (but probably the same issue ) in Tomcat you can not use
static route to subscriber
Only via radius
I suspect it is because there is no IFL for the subscriber only flow
but take a look on
Am 28.02.2019 um 23:00 schrieb Nitzan Tzelniker <
> nitzan.tzelni...@gmail.com>:
> >
> > I open TAC case about it few months ago
> > We tried hard with our SE and the JTAC but the developers didnt agreed to
> > add it
> > Maybe if more people will push it
I open TAC case about it few months ago
We tried hard with our SE and the JTAC but the developers didnt agreed to
add it
Maybe if more people will push it they will add it as QFX/SRX/EX ... does
not have craft interface and they support this MIB
BTW you can also try to monitor it with Netconf or
>From what I understand the router will not delete the arp entry immediately
after it expired so it will not queue/drop the packet
Take a look on this output where the arp is expired you the entry is kept
without expiration time for few seconds until the other side answer to the
arp
If we are talking about SSH in Junos
I am waiting for TrustedUserCAKeys support as describe in
https://code.fb.com/security/scalable-and-secure-access-with-ssh/
Nitzan
On Wed, Dec 26, 2018 at 8:39 PM Bjørn Mork wrote:
> Chris Morrow writes:
> > On Sun, 23 Dec 2018 16:15:24 -0500,
> > Melchior
If you cant afford taking down the whole VC do not work with VC
This is my philosophy with VC
Do MC-LAG or EVPN in these environment (even with VC just to increase the
number of ports )
Regarding the host they dont have to be the same unless there is a known
issue
From
AFAIK from few JTAC cases both 16.1R7 and 17.3R3 should be out in the end
of this month or sometime next month
but as always it could be changed
Nitzan
On Mon, Jun 18, 2018 at 9:36 AM Sebastian Becker wrote:
> The ETA for GA was 31-MAY-2018. So hopefully only a matter of days.
>
> —
>
Try to remove the "ingress-node-replication" from the vlans and add " set
protocols evpn multicast-mode ingress replication "
few months ago a TAC engineer told it to me
"This knob will add all the remote VTEPs under the VNIs on local device
even though the remote devices do not have these VNIs
Thanks All,
This RPC command works for me via ansible
I used ansible lookup module to take the license content from a file with
the hostname as filename but more advanced use should be to take it
directly from Juniper bulk activation excel based on the serial number
Nitzan
On Wed, Mar 28,
Not sure I understand you but both can run 17.3R2 (just time of
installation )
On Wed, Mar 28, 2018 at 10:16 PM Vincent Bernat <ber...@luffy.cx> wrote:
> ❦ 28 mars 2018 19:06 GMT, Nitzan Tzelniker <nitzan.tzelni...@gmail.com> :
>
> > The 5100 run 15.1X53-D63 and the 511
t; just a display issue.
> --
> The lunatic, the lover, and the poet,
> Are of imagination all compact...
> -- Wm. Shakespeare, "A Midsummer Night's Dream"
>
> ――― Original Message ―――
> From: Nitzan Tzelniker <nitzan.tzelni...@gmail.com>
Hi,
Just check with 5110 and 5100 and on both I see two next hops
but I am using OSPF for the underlay
I think that you have multipath under BGP from the fact that we see two
paths under inet.0 but do you have forwarding-table policy with
"load-balance per-packet" ?
BTW take a look here
I dont think rpc will be good option as the command "request system license
add " dose not have rpc
May be junos_command will do it but I am not sure
user@switch> request system license add jj | display xml rpc
http://xml.juniper.net/junos/17.3R2/junos;>
xml rpc equivalent of this
We are running MX480 with NG-RE and Junous Fusion and doing basic MPLS on
17.2R2 so far without an issue
We started with 16.1R5 and hit by Fusion issue that force us to upgrade to
17.1R2 where we hit by another Fusion issue
Nitzan
On Wed, Dec 13, 2017 at 5:29 PM, Michael Hare
Check the mac learning history
I saw one event when a EX4500 has high CPU because of that
Try to clear the offending mac address
Nitzan
On Sat, Sep 16, 2017 at 8:07 PM, Rodrigo 1telecom
wrote:
> Nothing . this switchs is only layer2...
> these vlans passthrough
You probably missing
S-MX80-SA-FP
Licenses installed:
License identifier: XX
License version: 4
Features:
subscriber-accounting - Per Subscriber Radius Accounting
permanent
subscriber-authentication - Per Subscriber Radius Authentication
permanent
We are doing using this config and it reduce the amount of drops
IIRC I did the change without any issue
Nitzan
On Tue, May 30, 2017 at 2:26 PM, Chen Jiang wrote:
> Hi! Experts
>
> Sorry for disturbing, we are using QFX5100 virtual-chassis for
> distrubiuting storage
As this is also applied to L2 it might also kill l2 traffic like LACP/ARP
...
Try to add another term with then accept in the end of acl1 like you did in
acl2
Nitzan
On Tue, May 16, 2017 at 11:46 PM, Panny Malialis wrote:
> Hi all,
>
>
> I am trying to configure an input
Currently only sflow
On Fri, Apr 28, 2017 at 4:37 PM, Giuliano C. Medalha wrote:
> People,
>
> Does anyone knows about QFX10002 ... if it is possible to configure some
> kind of flow export ... like NETFLOW or IPFIX ?
>
> Thanks a lot,
>
> Giuliano
>
Did someone test if ddos-protraction for protocol resolve with
flow-detection detect the source IP and drop its requests
Nitzan
On Wed, Apr 5, 2017 at 4:27 PM, Alexander Arseniev
wrote:
> Hello,
>
> If You have control over Your L3 space assignments, have You tried
>
> 2017-03-20 12:15 GMT-03:00 Javier Rodriguez <rodriguezsot...@gmail.com>:
> >
> >> Nitzan, thank you very much, I'll keep that in mind.
> >> Anyway I can not understand how the router "eats" the packets without
> >> being counted That gives me pan
We saw a limitation around 40Gbps when running MX80 with RE based jflow
(inline works good ) we didnt got good explanation why it limit the traffic
so try to disable some features and see if it help
Nitzan
On Mon, Mar 20, 2017 at 6:14 AM, Javier Rodriguez wrote:
>
I think that you should ask your Juniper SE
There is a file they have
Nitzan
On Sat, Mar 18, 2017 at 7:24 PM, harbor235 wrote:
> My google-fu is preventing me from finding performance data on the various
> MS-MPC linecards for the MX router series. I am looking for IPSEC
>
>From 15.1F2 (I test it on 15.1F6 ) changing the flow table size dose not
restart the FPC
Nitzan
On Fri, Nov 4, 2016 at 5:47 AM, Scott Granados
wrote:
> +1, this is how I have set things up as well and yes, changing the table
> sizes will cause an FPC reboot.
>
> > On
You can work based on this blog
http://nextheader.net/2013/07/22/changing-the-configuration-using-event-policy-action/
Thanks
Nitzan
On Wed, Oct 26, 2016 at 8:24 AM, Stefan Stoyanov
wrote:
> Hi Alex,
>
> Try to check if "ip-monitoring" will fits your needs. (
>
Like the EX4300 the 40GE ports cannot be channelized to 4 x 10G
Nitzan
On Wed, Jun 15, 2016 at 4:31 PM, Jim Troutman
wrote:
> Anyone have any experience or opinions on the EX3400 switches?
>
> Can anyone confirm that the software supports breaking out a QSFP+ ports
>
You cant do it
They didnt want to create a switch with 16 x 10G for 5K$ list price
Nitzan
On Wed, May 11, 2016 at 5:30 PM, Paul S. wrote:
> Hi folks,
>
> Do the QSFP+ ports on the EX4300 support channelization (
>
You can take vMX and do subscriber management on it (It is very new so be
careful )
It has license for 1K subscribers and it should be the best for you
http://www.juniper.net/assets/us/en/local/pdf/datasheets/1000522-en.pdf
In the cisco world you can take CSR1K
Nitzan
On Mon, May 9, 2016 at
AFAIK it is mostly VPLS and maybe some OAM feature
btw the QFX5100 with D35 release has a new feature that I dont know if it
available on the ACX5K ECMP for MPLS traffic using firewall filter
Nitzan
On Mon, May 2, 2016 at 8:26 PM, Colton Conor wrote:
> Jerry,
>
> Can
kov...@gamma.co.uk>
wrote:
> > Nitzan Tzelniker
> > Sent: Saturday, April 16, 2016 8:22 PM
> >
> > 1. Same performance 500G
> > 2. Same memory technology (3d memory architecture ) 3. Both use Virtual
> > output Queue 4. Both announce on the same day
> >
> Wel
<s...@ytti.fi> wrote:
> On 16 April 2016 at 20:54, Nitzan Tzelniker <nitzan.tzelni...@gmail.com>
> wrote:
> > QFX10K use almost the same ASIC as the PTX1K so the hardware is capable
> to
> > be P (But the memory is partition differently for data center use cases
QFX10K use almost the same ASIC as the PTX1K so the hardware is capable to
be P (But the memory is partition differently for data center use cases )
So check the feature table and scaling for your needs (256K routes if you
are not using BGP free core ) and dont forget the license for MPLS
If
The new MPC7-10G (Only the 10G version ) support macsec if you need it for
10G
Nitzan
On Mon, Mar 28, 2016 at 12:45 AM, Saku Ytti wrote:
> On 27 March 2016 at 23:44, Alex K. wrote:
> > But as far as Juniper documentation is concerned, MIC-3D-20GE-SFP-E only
BTW
if you have MPC5 or 6 you can use fast-lookup-filter to increase
the performance
http://www.juniper.net/techpubs/en_US/junos15.1/topics/concept/firewall-filter-fast-lookup-filter.html
Nitzan
On Wed, Mar 16, 2016 at 2:23 AM, Saku Ytti wrote:
> On 15 March 2016 at 21:48,
I don't remember if there is a log message but you can write some event
script that disable/enable the port when it become standby
Other vendor solve it with mvrp
age-
> From: juniper-nsp [mailto:juniper-nsp-boun...@puck.nether.net] On Behalf
> Of
> Niall Donaghy
> Sent: 11 December 2015 03:19
> To: david....@orange.com; Nitzan Tzelniker
> Cc: juniper-nsp@puck.nether.net
> Subject: Re: [j-nsp] Firwall Counter IPv6 : MIB
>
>
Hi David,
It works for me on MX80 running 11.4R8.4
snmpwalk -c X -v2c 1.1.1.1
.1.3.6.1.4.1.2636.3.5.2.1.5.28.118.54.45.105.110.98.111.117.110.100.45.102.105.108.116.101.114.45.97.101.48.46.49.48.48.48.45.105.23.105.112.118.54.95.116.114.97.102.102.105.99.45.97.101.48.46.49.48.48.48.45.105.2
Yes it is DS
Nitzan
On Tue, Dec 8, 2015 at 5:18 PM, <david@orange.com> wrote:
> Thank you. In 12.3 it doesn’t work.
>
>
>
> Does your interface is a dual stack interface ?
>
>
>
> David
>
>
>
>
>
> *De :* Nitzan Tzelniker [mailto:nitzan
Regarding CGNAT the MX104 can have MS-MIC that can do all of the
PBA/NAPT/ALG/EIM features for near 10G
Nitzan
On Mon, Nov 30, 2015 at 4:06 PM, Payam Chychi wrote:
> Asr1000 line are solid if needed for nat
>
> --
> Payam Chychi
> Solution Architect
>
>
> On Monday,
Did you try vrrp-inherit-from
https://www.juniper.net/documentation/en_US/junos12.1/topics/task/configuration/vrrp-inheritance-for-a-group-configuring.html
Nitzan
On Thu, Nov 26, 2015 at 7:25 PM, "Rolf Hanßen" wrote:
> Hi,
>
> just ran into that issue after creating a
mbers of prefixes for filtering purposes
> without having to churn the unit with a typical commit operation and it’s
> associated churn. I’d hate to have to migrate to MX because EX can’t/won’t
> do it.
>
>
>
> Cheers!
>
>
>
> Dan
>
>
>
> *From:* Nitzan T
Dan,
AFAIK dynamic-db is for routing policy only
it dose not work for firewall filters
Nitzan
On Mon, Oct 26, 2015 at 7:29 PM, Dan Farrell wrote:
> Howdy List,
>
> I can't seem to get a dynamic-db prefix-list to work correctly on either
> an ex3200 or ex2200 on JUNOS 12.3
The default limit is 3 but you can change it to 5
http://www.juniper.net/techpubs/en_US/junos14.2/topics/task/configuration/interfaces-mpls-maximum-labels.html
I heard something about increasing this limit probably for segment routing
(but it was two years ago )
BTW
I didn't find a reference
:04 +0300), Nitzan Tzelniker wrote:
Hey,
The default limit is 3 but you can change it to 5
http://www.juniper.net/techpubs/en_US/junos14.2/topics/task/configuration/interfaces-mpls-maximum-labels.html
I heard something about increasing this limit probably for segment
routing
AFAIK The second RE is spawn only during the upgrade and shutdown after the
upgrade
Nitzan
On Sat, Mar 21, 2015 at 4:45 PM, Octavio Alfageme
octavio.alfag...@gmail.com wrote:
Hello everyone,
Soon I'm gonna have to configure a virtual-chassis of two QFX5100s. I'd be
grateful if you could
My view
EX9200 has better qos features, larger buffers 100G interfaces , better L2
features (QinQ,Vlan per port ... ) ,VxLAN routing
BTW to prevent SP from using the 9200 as P router it doesn't support RSVP
For most cases QFX will do the job but if you want MX for your DC but
80/104 is to small
Hi,
This is an example I got from the TAC before it is supported from
13.2x51-D25
set vlans v10 interface ge-0/0/1.10
set vlans v10 interface ge-0/0/2.10
set vlans v99 interface ge-0/0/2.99
set vlans v99 vlan-id 99 l3-interface irb.99
set interfaces irb unit 99 family inet address
From what I understand EX4600 will have some unique features compared to
the QFX5100 (e.g. 802.1x if I remember correctly ).
BTW The cost of AFL license for the EX4600 is two times the cost of AFL
license for the QFX5100 so that the price difference is almost nothing if
you need AFL
Nitzan
http://www.juniper.net/techpubs/en_US/junos13.3/topics/reference/mibs/mib-jnx-firewall.txt
Nitzan
On Wed, Jul 9, 2014 at 3:56 PM, Chris Adams c...@cmadams.net wrote:
Once upon a time, Fahad Khan fahad.k...@gmail.com said:
Hi Team,
Is there a MIB available for a Policer (in Junos) to be
Where is your PPPoE configuration (access dynamic-profiles ... ) ?
May be you can start with this document
http://www.juniper.net/techpubs/en_US/junos13.3/information-products/pathway-pages/subscriber-access/mpls/subscriber-management-mpls.pdf
Nitzan
On Mon, Jun 2, 2014 at 5:45 PM, Brijesh
There is a very detailed day one book
Securing the Routing Engine on M, MX, and T Series
http://www.juniper.net/us/en/community/junos/training-certification/day-one/fundamentals-series/securing-routing-engine/
Nitzan
On Tue, Jan 14, 2014 at 8:07 PM, joel jaeggli joe...@bogus.com wrote:
On
Hi,
The problem with the MX80 is not the FIB size but the slow RE
The time it take to receive full routing table is long and to put it into
the FIB is even worst
Nitzan
On Tue, Sep 24, 2013 at 10:21 AM, Krasimir Avramski kr...@smartcom.bgwrote:
Agree.. other elements like counters, filters,
There was a bug in 12.2R3 which cause VC cable not to forward traffic
should be fixed in R4 (look in the list archive for the PSN )
Now I am working with 12.2R3 and R4 without VC
Nitzan
On Wed, Jul 24, 2013 at 10:38 AM, Nick Kritsky nick.krit...@gmail.comwrote:
I have several running
Another use case is for DPI or other transparent devices when your traffic
is not symmetrical (more downstream than upstream )
you are installing the DPI between two vrf on the same router and use
switch as port extender
This way you are using less ports on the router for almost the same amount
of
We had case with vc on 12.2R3
The vc cable didnt forwared traffic in one of the directions
I think it is PSN 2013-03-868
Nitzan
On Sun, Mar 24, 2013 at 12:32 PM, Tore Anderson t...@fud.no wrote:
* Timh Bergström
That's interesting, have you seen any other 'gotchas' with 12.2R3? I'm
The case with the 4550 in VC is PSN 2013-03-868
Nitzan
On Fri, Mar 1, 2013 at 7:58 PM, Amos Rosenboim a...@oasis-tech.net wrote:
We have deployed a mixed mode 4500/4200 small VC as a part of mobile
network core and it is running smoothly so far.
We don't have significant throughput, and we
try the script i send to the cacti forums
http://forums.cacti.net/about32000.html
Nitzan
On Wed, Mar 21, 2012 at 16:53, Shiva S Narayana sshankar...@yahoo.comwrote:
I meant:
how to decode the probe name and each test under the probe, as they are
encoded
There must be a easy and scalable
Not in the router but you can use
http://code.google.com/p/samplicator/
On Tue, Aug 9, 2011 at 20:14, Emmanuel Halbwachs
emmanuel.halbwa...@obspm.fr wrote:
Hello,
I would like to run more than one collector software on the same
host. The use case is:
- benchmarking different tools with
Hi
Try to use classification-override you can match bgp community and set it to
forwarding-class
http://www.juniper.net/techpubs/software/junos/junos93/swconfig-cos/overriding-the-input-classification.html#id-10946761
Nitzan
What version are you running on the EX ?
In the past I see a version when you couldn't disable autoneg (you can but
it didn't disable it )
Nitzan
On Sun, Jul 11, 2010 at 04:04, Chuck Anderson c...@wpi.edu wrote:
On Sat, Jul 10, 2010 at 08:55:36PM -0400, Chuck Anderson wrote:
On Sun, Jul 11,
Hi
do you have firewall filter on lo0 ?
I see similar issue when I did it
Thanks
Nitzan
On Wed, Jun 24, 2009 at 04:41, Ross Vandegrift r...@kallisti.us wrote:
On Tue, Jun 23, 2009 at 05:30:38PM -0700, Cord MacLeod wrote:
I had this issue adding members to an existing VC. Did you upgrade
Hi
I have a case about this issue it should be fixed in the next version 9.3R4
9.4R3 9.5R2
Nitzan
On Tue, Jun 9, 2009 at 15:48, Bjørn Tore b...@paulen.net wrote:
We are trying out some EX 4200 switches running 9.5R1.8. Anyone managed to
actually lock the port to 1000Fdx? Seems that this is
I see smiler problem on M120 with 9.1R2.1 take a look on PR312098
Nitzan
On Tue, Dec 30, 2008 at 21:48, Joerg Staedele j...@tnib.de wrote:
No, i only got the version (from August 2008) from the J Website ... I read
the PSN again and don't think that this is my problem.
Meanwhile i just
As far as I know you can use it as one STM-1 port but you can't use
the *non-concatenated
feature to cut it to 16 * STM1 but you can cut it to 4 * STM4
Nitzan
*
On Tue, Oct 28, 2008 at 20:46, Marlon Duksa [EMAIL PROTECTED] wrote:
Does anyone know if this PIC supports channelization down to
Hi,
If you are tacking about http://forums.cacti.net/about11320.html
Try to remove these lines from the XML
-jnxFruType
- nameFRU Type/name
- methodwalk/method
- sourcevalue/source
-
74 matches
Mail list logo