16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 15: Traffic Forwarding and Monitoring <strong>Configuration</strong><br />

• On all routers except the MX Series router, you can configure only one port-mirroring<br />

interface per router. If you include more than one interface in the port-mirroring<br />

statement, the previous one is overwritten. MX Series routers support more than one<br />

port-mirroring interface per router.<br />

• You can configure multiple port-mirroring instances on the M120, M320, and MX Series<br />

routers.<br />

• You can specify both host (cflowd) sampling and port mirroring in the same<br />

configuration. You can perform RE-sampling and port mirroring actions simultaneously.<br />

However, you cannot perform PIC-sampling and port mirroring actions simultaneously.<br />

• In typical applications, you send the sampled packets to an analyzer or a workstation<br />

for analysis, not to another router. If you must send this traffic over a network, you<br />

should use tunnels. For more information about tunnel interfaces, see the Junos OS<br />

Network Interfaces <strong>Configuration</strong> <strong>Guide</strong>.<br />

Configuring Port Mirroring<br />

To configure port mirroring, include the port-mirroring statement at the [edit<br />

forwarding-options] hierarchy level:<br />

[edit forwarding-options]<br />

port-mirroring {<br />

family (ccc | inet | inet6 | vpls) {<br />

output {<br />

interface interface-name {<br />

next-hop address;<br />

}<br />

no-filter-check;<br />

}<br />

input {<br />

maximum-packet-length bytes;<br />

rate number;<br />

run-length number;<br />

}<br />

}<br />

}<br />

Configuring the Port-Mirroring Address Family and Interface<br />

To configure port mirroring, include the port-mirroring statement. To configure the address<br />

family type of traffic to sample, include the family statement. To configure the rate of<br />

sampling, length of sampling, and the maximum size for the mirrored packet, include the<br />

input statement. To specify on which interface to send duplicate packets and the next-hop<br />

address to send packets, include the output statement. To determine whether there are<br />

any filters on the specified interface, include the no-filter-check statement.<br />

For information about the rate and run-length statements, see “Configuring Traffic<br />

Sampling” on page 347.<br />

Configuring Multiple Port-Mirroring Instances<br />

In Junos OS Release 9.5 and later, you can configure multiple port-mirroring instances<br />

on the M120, M320, and MX Series routers. On the M120 router, you can associate each<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

377

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!