Juniper JUNOS OS 10.4 - RELEASE NOTES REV 6 Release Note page 25

Hide thumbs Also See for JUNOS OS 10.4 - RELEASE NOTES REV 6:
Table of Contents

Advertisement

Copyright © 2011, Juniper Networks, Inc.
New Features in Junos OS Release 10.4 for M Series, MX Series, and T Series Routers
fpc 1 {
pic 2 {
adaptive-services {
service-package {
extension-provider {
control-cores 1;
data-cores 1;
object-cache-size 512;
policy-db-size 64;
package jservices-rpm;
syslog daemon any;
}
}
}
}
}
[Services Interfaces]
ALGs using Junos OS Services Framework (JSF) (M Series with Multiservices PICs
and MX Series with MS DPCs)—Application-level gateways (ALGs) intercept and
analyze specified traffic, allocate resources, and define dynamic policies to permit
traffic to pass securely through a device. Beginning with Junos OS Release 10.4 on the
specified routers, you can use JSF ALGs with the following services:
Stateful firewall
Network Address Translation (NAT)
To use JSF to run ALGs, you must configure the jservices-alg package at the
chassis fpc slot pic slot adaptive-services service-package extension-provider package]
hierarchy level. In addition, you must configure the ALG application at the
applications application application-name]
in the stateful firewall rule or the NAT rule in those respective configurations.
[Services Interfaces]
Enhancements to port mirroring with next-hop groups (MX Series only)—Adds
support for binding up to two port-mirroring instances to the same MX Series Packet
Fowarding Engine. This enables you to choose multiple mirror destinations by specifying
different port-mirroring instances in the filters. Filters must include the
port-mirror-instance instance-name
hierarchy level. You must also include the
term-name then]
statement at the
instance-name
FPC to be used.
Inline port mirroring allows you to configure instances that are not bound to the FPC
specified in the firewall filter
you can define the
then next-hop-group
the port-mirror destination from the input parameters, such as rate. While the input
parameters are programmed in the Switch Interface Board (SIB), the next-hop
destination for the mirrored packet is available in the packet itself.
A port-mirroring instance can now inherit input parameters from another instance that
specifies it. To configure this option, include the
hierarchy level, and reference the application
statement at the
[edit firewall filter filter-name term
[edit chassis fpc number]
then port-mirror-instance instance-name
action. Inline port-mirroring aims to decouple
input-parameters-instance
[edit
[edit
port-mirror-instance
hierarchy level to specify the
action. Instead,
25

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents