Juniper JUNOS OS 10.3 - SOFTWARE Manual page 3648

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

Complete Software Guide for Junos
Step-by-Step
Procedure
Results
3552
®
OS for EX Series Ethernet Switches, Release 10.3
set ethernet-switching-options analyzer employee-web-monitor loss-priority high output vlan
999
set vlans remote-analyzer vlan-id 999
set interfaces ge-0/0/10 unit 0 family ethernet-switching port mode trunk
set interfaces ge-0/0/10 unit 0 family ethernet-switching vlan members 999
set firewall family ethernet-switching filter watch-employee term employee-to-corp from
destination-address 192.0.2.16/28
set firewall family ethernet-switching filter watch-employee term employee-to-corp from
source-address 192.0.2.16/28
set firewall family ethernet-switching filter watch-employee term employee-to-corp then
accept
set firewall family ethernet-switching filter watch-employee term employee-to-web from
destination-port 80
set firewall family ethernet-switching filter watch-employee term employee-to-web then
analyzer employee–web-monitor
set ge-0/0/0 unit 0 family ethernet-switching filter input watch-employee
set interfaces ge-0/0/1 unit 0 family ethernet-switching filter input watch-employee
To configure port mirroring of all traffic from the two ports connected to employee
computers to the
remote-analyzer
Configure the
employee-web-monitor
1.
[edit ethernet-switching-options]
user@switch# set interfaces ge-0/0/10 unit 0 family ethernet-switching port mode
trunk
user@switch# set analyzer employee-web-monitor loss-priority high output vlan 999
Configure the VLAN tag ID for the
2.
[edit vlans]
user@switch# set remote-analyzer vlan-id 999
Configure the interface to associate it with the
3.
[edit interfaces]
user@switch# set ge-0/0/10 unit 0 family ethernet-switching vlan members 999
Configure the firewall filter called
4.
[edit firewall family ethernet-switching]
user@switch# set filter watch-employee term employee-to-corp from
destination-address 192.0.2.16/28
user@switch# set filter watch-employee term employee-to-corp from source-address
192.0.2.16/28
user@switch# set filter watch-employee term employee-to-corp then accept
user@switch# set filter watch-employee term employee-to-web from destination-port
80
user@switch# set filter watch-employee term employee-to-web then analyzer
employee-web-monitor
Apply the firewall filter to the employee interfaces:
5.
[edit interfaces]
user@switch# set ge-0/0/0 unit 0 family ethernet-switching filter input
watch-employee
user@switch# set ge-0/0/1 unit 0 family ethernet-switching filter input
watch-employee
Check the results of the configuration:
VLAN for use from a remote monitoring station:
analyzer:
VLAN:
remote-analyzer
remote-analyzer
:
watch-employee
Copyright © 2010, Juniper Networks, Inc.
VLAN:

Advertisement

Table of Contents
loading

Table of Contents