16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 14: Introduction to Traffic Sampling <strong>Configuration</strong><br />

Disabling Traffic Sampling<br />

When you apply a firewall filter to a loopback interface, the filter might block responses<br />

from the Monitoring Services PIC. To allow responses from the Monitoring Services PIC<br />

to pass through for sampling purposes, configure a term in the firewall filter to include<br />

the Monitoring Services PIC’s IP address. For more detailed information about configuring<br />

firewall filters, see “Configuring Standard Firewall Filters” on page 193.<br />

To explicitly disable traffic sampling on the router, include the disable statement at the<br />

[edit forwarding-options sampling] hierarchy level:<br />

[edit forwarding-options sampling]<br />

disable;<br />

Configuring the Output File for Traffic Sampling<br />

You configure traffic sampling results to a file in the /var/tmp directory. To collect the<br />

sampled packets in a file, include the file statement at the [edit forwarding-options<br />

sampling output] hierarchy level:<br />

[edit forwarding-options sampling family family-name output]<br />

file filename filename <br />

;<br />

To configure the period of time before an active flow is exported, include the<br />

flow-active-timeout statement at the [edit forwarding-options sampling output family<br />

(inet | inet6 | mpls)] hierarchy level:<br />

[edit forwarding-options sampling family (inet | inet6 | mpls) output]<br />

flow-active-timeout seconds;<br />

To configure the period of time before a flow is considered inactive, include the<br />

flow-inactive-timeout statement at the [edit forwarding-options sampling output] hierarchy<br />

level:<br />

[edit forwarding-options sampling family (inet | inet6 | mpls) output]<br />

flow-inactive-timeout seconds;<br />

To configure the interface that sends out monitored information, include the interface<br />

statement at the [edit forwarding-options sampling output] hierarchy level:<br />

[edit forwarding-options sampling family (inet | inet6 | mpls) output]<br />

interface interface-name {<br />

engine-id number;<br />

engine-type number;<br />

source-address address;<br />

}<br />

NOTE: This feature is not supported with the version 9 template format. You<br />

must send traffic flows collected using version 9 to a server. For more<br />

information see “Configuring Active Flow Monitoring Using Version 9” on<br />

page 354.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

349

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!