Services on the QFX Series - Juniper.net
Services on the QFX Series - Juniper.net
Services on the QFX Series - Juniper.net
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
CHAPTER 3<br />
C<strong>on</strong>figurati<strong>on</strong> Examples<br />
• Example: C<strong>on</strong>figuring Port Mirroring for Local Analysis <strong>on</strong> page 13<br />
• Example: C<strong>on</strong>figuring Port Mirroring for Remote Analysis <strong>on</strong> page 17<br />
Example: C<strong>on</strong>figuring Port Mirroring for Local Analysis<br />
Use port mirroring to send traffic to applicati<strong>on</strong>s that analyze traffic for purposes such<br />
as m<strong>on</strong>itoring compliance, enforcing policies, detecting intrusi<strong>on</strong>s, m<strong>on</strong>itoring and<br />
predicting traffic patterns, correlating events, and so <strong>on</strong>. Port mirroring copies packets<br />
entering or exiting an interface or entering a VLAN and sends <strong>the</strong> copies to a local interface<br />
for local m<strong>on</strong>itoring.<br />
This example describes how to c<strong>on</strong>figure port mirroring to copy traffic sent by employee<br />
computers to a switch to an access interface <strong>on</strong> <strong>the</strong> same switch.<br />
• Requirements <strong>on</strong> page 13<br />
• Overview and Topology <strong>on</strong> page 13<br />
• Mirroring All Employee Traffic for Local Analysis <strong>on</strong> page 14<br />
• Mirroring Employee-to-Web Traffic for Local Analysis <strong>on</strong> page 15<br />
• Verificati<strong>on</strong> <strong>on</strong> page 17<br />
Requirements<br />
This example uses <strong>the</strong> following hardware and software comp<strong>on</strong>ents:<br />
• Junos OS Release 11.1<br />
• A switch<br />
Overview and Topology<br />
This topic includes two related examples that describe how to mirror traffic entering<br />
interfaces <strong>on</strong> <strong>the</strong> switch to an access interface <strong>on</strong> <strong>the</strong> same switch. The first example<br />
shows how to mirror all traffic sent by employee computers to <strong>the</strong> switch. The sec<strong>on</strong>d<br />
example includes a filter to mirror <strong>on</strong>ly <strong>the</strong> employee traffic going to <strong>the</strong> Web.<br />
In this example, xe-0/0/0 and xe-0/0/6 serve as c<strong>on</strong>necti<strong>on</strong>s for employee computers.<br />
Interface xe-0/0/47 is c<strong>on</strong>nected to a device running an analyzer applicati<strong>on</strong>.<br />
Copyright © 2013, <strong>Juniper</strong> Networks, Inc.<br />
13