16.03.2014 Views

Services on the QFX Series - Juniper.net

Services on the QFX Series - Juniper.net

Services on the QFX Series - Juniper.net

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 3: C<strong>on</strong>figurati<strong>on</strong> Examples<br />

user@switch# show e<strong>the</strong>r<strong>net</strong>-switching-opti<strong>on</strong>s<br />

analyzer employee-m<strong>on</strong>itor {<br />

input {<br />

ingress {<br />

interface xe-0/0/0.0;<br />

interface xe-0/0/6.0;<br />

}<br />

}<br />

output {<br />

interface {<br />

xe-0/0/47.0;<br />

}<br />

}<br />

}<br />

}<br />

Mirroring Employee-to-Web Traffic for Local Analysis<br />

To mirror <strong>on</strong>ly traffic sent by employees to <strong>the</strong> Web for local analysis, perform <strong>the</strong> tasks<br />

explained in this secti<strong>on</strong>.<br />

CLI Quick<br />

C<strong>on</strong>figurati<strong>on</strong><br />

To quickly c<strong>on</strong>figure local port mirroring of traffic from employee computers that is<br />

destined for <strong>the</strong> Web, copy <strong>the</strong> following commands and paste <strong>the</strong>m into a switch terminal<br />

window:<br />

[edit]<br />

set e<strong>the</strong>r<strong>net</strong>-switching-opti<strong>on</strong>s analyzer employee–web–m<strong>on</strong>itor output interface xe-0/0/47.0<br />

set firewall family e<strong>the</strong>r<strong>net</strong>-switching filter watch-employee term employee-to-corp from<br />

destinati<strong>on</strong>-address 192.0.2.16/28<br />

set firewall family e<strong>the</strong>r<strong>net</strong>-switching filter watch-employee term employee-to-corp from<br />

source-address 192.0.2.16/28<br />

set firewall family e<strong>the</strong>r<strong>net</strong>-switching filter watch-employee term employee-to-corp <strong>the</strong>n accept<br />

set firewall family e<strong>the</strong>r<strong>net</strong>-switching filter watch-employee term employee-to-web from<br />

destinati<strong>on</strong>-port 80<br />

set firewall family e<strong>the</strong>r<strong>net</strong>-switching filter watch-employee term employee-to-web <strong>the</strong>n analyzer<br />

employee-web-m<strong>on</strong>itor<br />

set interfaces xe-0/0/0 unit 0 family e<strong>the</strong>r<strong>net</strong>-switching filter input watch-employee<br />

set interfaces xe-0/0/6 unit 0 family e<strong>the</strong>r<strong>net</strong>-switching filter input watch-employee<br />

Step-by-Step<br />

Procedure<br />

To c<strong>on</strong>figure local port mirroring of employee-to-web traffic from <strong>the</strong> two ports c<strong>on</strong>nected<br />

to employee computers:<br />

1. C<strong>on</strong>figure <strong>the</strong> output interface:<br />

[edit interfaces]<br />

user@switch# set xe-0/0/47 unit 0 family e<strong>the</strong>r<strong>net</strong>-switching<br />

2. C<strong>on</strong>figure <strong>the</strong> employee-web-m<strong>on</strong>itor analyzer output. (C<strong>on</strong>figure <strong>on</strong>ly <strong>the</strong><br />

output—<strong>the</strong> input comes from <strong>the</strong> filter.)<br />

[edit e<strong>the</strong>r<strong>net</strong>-switching-opti<strong>on</strong>s]<br />

user@switch# set analyzer employee-web-m<strong>on</strong>itor output interface xe-0/0/47.0<br />

3. C<strong>on</strong>figure a firewall filter called watch-employee that includes a term to match<br />

traffic sent to <strong>the</strong> Web and send it to <strong>the</strong> analyzer employee-web-m<strong>on</strong>itor. Traffic<br />

to and from <strong>the</strong> corporate sub<strong>net</strong> (destinati<strong>on</strong> or source address of 192.0.2.16/28)<br />

does not need to be copied, so create ano<strong>the</strong>r term to accept that traffic before it<br />

reaches <strong>the</strong> term that sends Web traffic to <strong>the</strong> analyzer:<br />

Copyright © 2013, <strong>Juniper</strong> Networks, Inc.<br />

15

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!