16.03.2014 Views

Services on the QFX Series - Juniper.net

Services on the QFX Series - Juniper.net

Services on the QFX Series - Juniper.net

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<str<strong>on</strong>g>Services</str<strong>on</strong>g> <strong>on</strong> <strong>the</strong> <strong>QFX</strong> <strong>Series</strong><br />

NOTE: Multiple ports mirrored to <strong>on</strong>e interface can cause buffer overflow<br />

and dropped packets.<br />

Figure 1 <strong>on</strong> page 14 shows <strong>the</strong> <strong>net</strong>work topology for this example.<br />

Figure 1: Network Topology for Local Port Mirroring Example<br />

xe-0/0/47 xe-0/0/6 xe-0/0/0<br />

Server running traffic analyzer<br />

Employee computers<br />

g040596<br />

Mirroring All Employee Traffic for Local Analysis<br />

To c<strong>on</strong>figure port mirroring for all traffic sent by employee computers for local analysis,<br />

perform <strong>the</strong> tasks explained in this secti<strong>on</strong>.<br />

CLI Quick<br />

C<strong>on</strong>figurati<strong>on</strong><br />

To quickly c<strong>on</strong>figure local port mirroring for ingress traffic to <strong>the</strong> two ports c<strong>on</strong>nected to<br />

employee computers, copy <strong>the</strong> following commands and paste <strong>the</strong>m into a switch<br />

terminal window:<br />

[edit]<br />

set interfaces xe-0/0/0 unit 0 family e<strong>the</strong>r<strong>net</strong>-switching<br />

set interfaces xe-0/0/6 unit 0 family e<strong>the</strong>r<strong>net</strong>-switching<br />

set interfaces xe-0/0/47 unit 0 family e<strong>the</strong>r<strong>net</strong>-switching<br />

set e<strong>the</strong>r<strong>net</strong>-switching opti<strong>on</strong>s analyzer employee-m<strong>on</strong>itor input ingress interface xe-0/0/0.0<br />

set e<strong>the</strong>r<strong>net</strong>-switching opti<strong>on</strong>s analyzer employee-m<strong>on</strong>itor input ingress interface xe-0/0/6.0<br />

set e<strong>the</strong>r<strong>net</strong>-switching opti<strong>on</strong>s analyzer employee-m<strong>on</strong>itor output interface xe-0/0/47.0<br />

Step-by-Step<br />

Procedure<br />

To c<strong>on</strong>figure an analyzer called employee-m<strong>on</strong>itor and specify <strong>the</strong> input (source) interfaces<br />

and <strong>the</strong> output interface:<br />

1. C<strong>on</strong>figure <strong>the</strong> interfaces c<strong>on</strong>nected to employee computers as input interfaces for<br />

<strong>the</strong> port-mirror analyzer employee-m<strong>on</strong>itor:<br />

[edit e<strong>the</strong>r<strong>net</strong>-switching-opti<strong>on</strong>s]<br />

user@switch# set analyzer employee-m<strong>on</strong>itor input ingress interface xe–0/0/0.0<br />

user@switch# set analyzer employee-m<strong>on</strong>itor input ingress interface xe–0/0/6.0<br />

2. C<strong>on</strong>figure <strong>the</strong> output analyzer interface for <strong>the</strong> employee-m<strong>on</strong>itor analyzer. This will<br />

be <strong>the</strong> destinati<strong>on</strong> interface for <strong>the</strong> mirrored packets:<br />

[edit e<strong>the</strong>r<strong>net</strong>-switching-opti<strong>on</strong>s]<br />

user@switch# set analyzer employee-m<strong>on</strong>itor output interface xe-0/0/47.0<br />

Results<br />

Check <strong>the</strong> results of <strong>the</strong> c<strong>on</strong>figurati<strong>on</strong>:<br />

[edit]<br />

14<br />

Copyright © 2013, <strong>Juniper</strong> Networks, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!