16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 15: Traffic Forwarding and Monitoring <strong>Configuration</strong><br />

• On all routers except the MX Series router, you can configure only one port-mirroring<br />

interface per router. If you include more than one interface in the port-mirroring<br />

statement, the previous one is overwritten. MX Series routers support more than one<br />

port-mirroring interface per router.<br />

• You can configure multiple port-mirroring instances on the M120, M320, and MX Series<br />

routers.<br />

• You can specify both host (cflowd) sampling and port mirroring in the same<br />

configuration. You can perform RE-sampling and port mirroring actions simultaneously.<br />

However, you cannot perform PIC-sampling and port mirroring actions simultaneously.<br />

• In typical applications, you send the sampled packets to an analyzer or a workstation<br />

for analysis, not to another router. If you must send this traffic over a network, you<br />

should use tunnels. For more information about tunnel interfaces, see the Junos OS<br />

Network Interfaces <strong>Configuration</strong> <strong>Guide</strong>.<br />

Configuring Port Mirroring<br />

To configure port mirroring, include the port-mirroring statement at the [edit<br />

forwarding-options] hierarchy level:<br />

[edit forwarding-options]<br />

port-mirroring {<br />

family (ccc | inet | inet6 | vpls) {<br />

output {<br />

interface interface-name {<br />

next-hop address;<br />

}<br />

no-filter-check;<br />

}<br />

input {<br />

maximum-packet-length bytes;<br />

rate number;<br />

run-length number;<br />

}<br />

}<br />

}<br />

Configuring the Port-Mirroring Address Family and Interface<br />

To configure port mirroring, include the port-mirroring statement. To configure the address<br />

family type of traffic to sample, include the family statement. To configure the rate of<br />

sampling, length of sampling, and the maximum size for the mirrored packet, include the<br />

input statement. To specify on which interface to send duplicate packets and the next-hop<br />

address to send packets, include the output statement. To determine whether there are<br />

any filters on the specified interface, include the no-filter-check statement.<br />

For information about the rate and run-length statements, see “Configuring Traffic<br />

Sampling” on page 347.<br />

Configuring Multiple Port-Mirroring Instances<br />

In Junos OS Release 9.5 and later, you can configure multiple port-mirroring instances<br />

on the M120, M320, and MX Series routers. On the M120 router, you can associate each<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

377

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!