16.03.2014 Views

Services on the QFX Series - Juniper.net

Services on the QFX Series - Juniper.net

Services on the QFX Series - Juniper.net

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CHAPTER 4<br />

C<strong>on</strong>figurati<strong>on</strong> Tasks<br />

C<strong>on</strong>figuring Port Mirroring<br />

• C<strong>on</strong>figuring Port Mirroring <strong>on</strong> page 23<br />

• C<strong>on</strong>figuring DHCP and BOOTP Relay <strong>on</strong> page 26<br />

You use port mirroring to copy packets and send <strong>the</strong> copies to a device running an<br />

applicati<strong>on</strong> such as a <strong>net</strong>work analyzer or intrusi<strong>on</strong> detecti<strong>on</strong> applicati<strong>on</strong> so that you can<br />

analyze traffic without delaying it. You can mirror traffic entering or exiting a port or<br />

entering a VLAN, and you can send <strong>the</strong> copies to a local access interface or to a VLAN<br />

through a trunk interface.<br />

We recommend that you disable port mirroring when you are not using it. To avoid creating<br />

a performance issue If you do enable port mirroring, we recommend that you select<br />

specific input interfaces instead of using <strong>the</strong> all keyword. You can also limit <strong>the</strong> amount<br />

of mirrored traffic by using a firewall filter.<br />

NOTE: If you want to create additi<strong>on</strong>al analyzers without deleting an existing<br />

analyzer, first disable <strong>the</strong> existing analyzer using <strong>the</strong> disable analyzer<br />

analyzer-name command.<br />

NOTE: You must c<strong>on</strong>figure port mirroring output interfaces as family<br />

e<strong>the</strong>r<strong>net</strong>-switching.<br />

• C<strong>on</strong>figuring Port Mirroring for Local Analysis <strong>on</strong> page 23<br />

• C<strong>on</strong>figuring Port Mirroring for Remote Analysis <strong>on</strong> page 24<br />

• Filtering <strong>the</strong> Traffic Entering an Analyzer <strong>on</strong> page 25<br />

C<strong>on</strong>figuring Port Mirroring for Local Analysis<br />

To mirror interface traffic to a local interface <strong>on</strong> <strong>the</strong> switch:<br />

1. If you want to mirror traffic that is ingressing or egressing specific interfaces, choose<br />

a name for <strong>the</strong> port-mirroring c<strong>on</strong>figurati<strong>on</strong> and c<strong>on</strong>figure what traffic should be<br />

mirrored by specifying <strong>the</strong> interfaces and directi<strong>on</strong> of traffic:<br />

Copyright © 2013, <strong>Juniper</strong> Networks, Inc.<br />

23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!