16.03.2014 Views

Services on the QFX Series - Juniper.net

Services on the QFX Series - Juniper.net

Services on the QFX Series - Juniper.net

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 3: C<strong>on</strong>figurati<strong>on</strong> Examples<br />

Verificati<strong>on</strong><br />

Verifying That <strong>the</strong> Analyzer Has Been Correctly Created<br />

Purpose<br />

Verify that <strong>the</strong> analyzer named employee-m<strong>on</strong>itor or employee-web-m<strong>on</strong>itor has been<br />

created <strong>on</strong> <strong>the</strong> switch with <strong>the</strong> appropriate input interfaces and appropriate output<br />

interface.<br />

Acti<strong>on</strong><br />

You can verify that <strong>the</strong> port mirror analyzer has been c<strong>on</strong>figured as expected using <strong>the</strong><br />

show analyzer command.<br />

user@switch> show analyzer<br />

Analyzer name<br />

: employee-m<strong>on</strong>itor<br />

Output interface<br />

: xe-0/0/47.0<br />

Mirror ratio : 1<br />

Loss priority<br />

: Low<br />

Ingress m<strong>on</strong>itored interfaces : xe-0/0/0.0<br />

Ingress m<strong>on</strong>itored interfaces : xe-0/0/6.0<br />

Egress m<strong>on</strong>itored interfaces : N<strong>on</strong>e<br />

Meaning<br />

This output shows that <strong>the</strong> employee-m<strong>on</strong>itor analyzer:<br />

• Has a ratio of 1 (mirroring every packet, <strong>the</strong> default setting)<br />

• Has a loss priority of low (set this opti<strong>on</strong> to high <strong>on</strong>ly when <strong>the</strong> analyzer output is to a<br />

VLAN)<br />

• Is mirroring <strong>the</strong> traffic entering <strong>the</strong> xe-0/0/0 and xe-0/0/6 interfaces<br />

• Is sending <strong>the</strong> mirrored traffic to <strong>the</strong> xe-0/0/47 interface<br />

Related<br />

Documentati<strong>on</strong><br />

• Understanding Port Mirroring <strong>on</strong> page 3<br />

• C<strong>on</strong>figuring Port Mirroring <strong>on</strong> page 23<br />

Example: C<strong>on</strong>figuring Port Mirroring for Remote Analysis<br />

Use port mirroring to send traffic to applicati<strong>on</strong>s that analyze traffic for purposes such<br />

as m<strong>on</strong>itoring compliance, enforcing policies, detecting intrusi<strong>on</strong>s, m<strong>on</strong>itoring and<br />

predicting traffic patterns, correlating events, and so <strong>on</strong>. Port mirroring copies packets<br />

entering or exiting an interface or entering a VLAN and sends <strong>the</strong> copies ei<strong>the</strong>r to a local<br />

interface for local m<strong>on</strong>itoring or to a VLAN for remote m<strong>on</strong>itoring. This example describes<br />

how to c<strong>on</strong>figure port mirroring for remote analysis.<br />

• Requirements <strong>on</strong> page 18<br />

• Overview and Topology <strong>on</strong> page 18<br />

• Mirroring All Employee Traffic for Remote Analysis <strong>on</strong> page 18<br />

• Mirroring Employee-to-Web Traffic for Remote Analysis <strong>on</strong> page 19<br />

• Verificati<strong>on</strong> <strong>on</strong> page 21<br />

Copyright © 2013, <strong>Juniper</strong> Networks, Inc.<br />

17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!