SRX

 View Only
  • 1.  Juniper SRX incorrect flow sampling (in Akvorado).

    Posted 12 days ago

    Hello!

    I'm trying to deploy Akvorado with Juniper SRX345 and SRX4100 (Junos 21.4R3-S4.x) following the official documentation, but I am experiencing significant data inaccuracies and inconsistencies.

    My configuration is identical for both devices:

    set forwarding-options sampling instance AKV input rate 1024
    set forwarding-options sampling instance AKV input max-packets-per-second 65535
     
    set forwarding-options sampling instance AKV family inet output flow-server <AKVORADO_IP> port 2055
    set forwarding-options sampling instance AKV family inet output flow-server <AKVORADO_IP> version9 template AKVORADOv9
    set forwarding-options sampling instance AKV family inet output inline-jflow source-address <SOURCE_IP>
     
    set services flow-monitoring version9 template AKVORADOv9 ipv4-template
    set services flow-monitoring version9 template AKVORADOv9 flow-active-timeout 10
    set services flow-monitoring version9 template AKVORADOv9 flow-inactive-timeout 10
    set services flow-monitoring version9 template AKVORADOv9 template-refresh-rate packets 30
    set services flow-monitoring version9 template AKVORADOv9 template-refresh-rate seconds 30
    set services flow-monitoring version9 template AKVORADOv9 option-refresh-rate packets 30
    set services flow-monitoring version9 template AKVORADOv9 option-refresh-rate seconds 30
    set services flow-monitoring version9 template AKVORADOv9 nexthop-learning enable

    The goal is to monitor my VPN and WAN interfaces.

    Notes:

    • VPN tunnels based on st0-interfaces display correctly in Akvorado for both devices;
    • SRX345 - WAN based on irb-interface. No traffic appear at rate = 1024 , only rate = 1 produces a somewhat usable graph.
    • SRX4100 - two WAN based on reth1-interfaces. Main problem. Actual traffic ~ 500 Mbps, but Akvorado shows only 5-7 Mbps. Changing rate makes a little difference. Other reth-interfaces (for LAN/GUEST zones) also show incorrect data, though better than WAN.
    • Both devices perform Source NAT on WAN interfaces. Switching to ipfix kills all monitoring completely (no graphs).

    Are there any knows issues with integrating SRX-devices into Akvorado and are there any fixes for it? 

    Thanks.



    ------------------------------
    Konstantin Sozonov
    ------------------------------


  • 2.  RE: Juniper SRX incorrect flow sampling (in Akvorado).

    Posted 12 days ago

    The only thing that comes to mind is that some traffic may not be subject to sampling. Like if you have PowerMode IPsec enabled on the SRX4100, that traffic won't be sampled. But then again, I doubt that 99% of your traffic is IPsec, so that's probably not it.



    ------------------------------
    Nikolay Semov
    ------------------------------



  • 3.  RE: Juniper SRX incorrect flow sampling (in Akvorado).

    Posted 3 days ago

    The first thing I can say is that although vpn is operating it is taking precedence over your endeavors. It's ruling the show on a very low level. St0 and lo0 are working because the srx operates this way on all models. Service always works. However it wants to believe you are all tunnel traffic because that's the shortest easiest route. So, other services are needing configuration. Find the protocols AKVORADO needs. You are making sure "services" are routing separately. VPN, and what other standard services are you needing? AKVORADO requires what other services? I expect that st0 works much the way sp-0 does. No you don't configure sp-0, but maybe initially. It is expected to be in a default state. But st0 i don't know. Seems irrelevant. Not sure.



    ------------------------------
    Adrian Aguinaga
    B.S.C.M. I.T.T. Tech
    (Construction Management)
    A.A.S. I.T.T. Tech
    (Drafting & Design)
    ------------------------------