Commands And Guidelines - Juniper E320 Configuration Manual

Junose internet software for e-series routing platforms
Hide thumbs Also See for E320:
Table of Contents

Advertisement

Commands and Guidelines

This section lists the commands you use to configure RADIUS-based IP interface
mirroring.
authorization change
!
!
!
ip analyzer
!
!
!
NOTE:
analyzer port. If the analyzer port is an IP over Ethernet interface, you must also
configure a static Address Resolution Protocol (ARP) entry to reach the analyzer
device.
!
!
!
!
!
!
!
!
Use to enable receipt of change-of-authorization messages from the RADIUS
server, which are used during RADIUS-initiated packet mirroring of a user who
is already logged in.
Example
host1(config)#radius dynamic-request server 192.168.5.3
host1(config-radius)#authorization change
Use the no version to disable the creation of new RADIUS-initiated packet
mirroring sessions. Current RADIUS-initiated mirrored sessions continue to be
mirrored.
Use to configure an interface as an analyzer port. The analyzer port directs
mirrored traffic to the specified analyzer device for analysis.
You can configure the interface as the virtual router's default analyzer port. You
cannot configure multiaccess interfaces, such as IP over Ethernet, as default
analyzer ports.
When mirroring an IP interface, the analyzer port must reside in the same
virtual router as the mirrored interface. When mirroring an L2TP interface, the
analyzer port must reside in the default virtual router.
You must configure a static route to reach the analyzer device through the
You can configure any type of IP interface on the E-series router as an analyzer
port, except for special interfaces such as SRP interfaces, null interfaces, and
loopback interfaces.
An interface cannot be both an analyzer port and a mirrored interface at the
same time.
A single analyzer port can support multiple mirrored interfaces.
The receive side of the analyzer port is disabled. All traffic attempting to access
the router through an analyzer port is dropped.
Analyzer ports drop all nonmirrored traffic.
Policies are not supported. When you configure an analyzer port, existing
policies are disabled, and no new policies are accepted.
Example
host1(config-if)#ip analyzer default
Use the no version to remove the analyzer port configuration from the
interface.
Chapter 6: Packet Mirroring
Configuring RADIUS-Based Mirroring
!
171

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Erx-710Erx-310Erx-1440Erx-1410Erx-705

Table of Contents