Junos OS

Expand all | Collapse all

Port Mirroring

Jump to Best Answer
  • 1.  Port Mirroring

    Posted 08-21-2020 01:36

    Hi

    Considering Port Mirroring feature, I have some questions:

    1- Can we apply the ingress policy on Multiple 100GE interfaces?

    2- Can we apply ingress policy on AE interface?

    3- Is it mandatory to configure destination IP address for SPAN packet receiver?

    Thank you



  • 2.  RE: Port Mirroring
    Best Answer

    Posted 08-21-2020 01:55

    Hello,

    Assuming You talk about MX series, then

     


    @Asoltanian wrote:

     

    1- Can we apply the ingress policy on Multiple 100GE interfaces?

     


     

    I believe You mean FW filter with "then port-mirror" action, and not a JUNOS policy statement - then yes,

    You can. Beware that Your port-mirror output interface BW must be enough to send all mirrored traffic out.

     


    @Asoltanian wrote:

     

    2- Can we apply ingress policy on AE interface?

     



    Yes You can.

     

     


    @Asoltanian wrote:

     

    3- Is it mandatory to configure destination IP address for SPAN packet receiver?

     


     

    The short answer is yes , for L3/IP mirroring, and no for L2 mirroring.

    The long answer is if You mean "next-hop 10.10.6.1" in this example https://kb.juniper.net/InfoCenter/index?page=content&id=KB33488

    then this is NOT a "destination IP address", the mirrored packet' dst.IP in the original IP header is not overwritten.

    It is a nexthop IP and You also need a static IP entry for it - unfortunately, the static ARP bit is missing from this KB.

    This nexthop IP is not required for L2 mirroring https://www.juniper.net/documentation/en_US/junos/topics/example/layer-2-services-port-mirroring-firewall-filter-logical-interface-example.html 

    HTHY

    Thx

    Alex