Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual page 3950

For ex series ethernet switches
Table of Contents

Advertisement

Complete Software Guide for Junos
Step-by-Step
Procedure
Results
3846
®
OS for EX Series Ethernet Switches, Release 10.4
set ethernet-switching-options analyzer employee-web-monitor loss-priority high output vlan
999
set vlans remote-analyzer vlan-id 999
set interfaces ge-0/0/10 unit 0 family ethernet-switching port mode trunk
set interfaces ge-0/0/10 unit 0 family ethernet-switching vlan members 999
set firewall family ethernet-switching filter watch-employee term employee-to-corp from
destination-address 192.0.2.16/28
set firewall family ethernet-switching filter watch-employee term employee-to-corp from
source-address 192.0.2.16/28
set firewall family ethernet-switching filter watch-employee term employee-to-corp then accept
set firewall family ethernet-switching filter watch-employee term employee-to-web from
destination-port 80
set firewall family ethernet-switching filter watch-employee term employee-to-web then analyzer
employee–web-monitor
set ge-0/0/0 unit 0 family ethernet-switching filter input watch-employee
set interfaces ge-0/0/1 unit 0 family ethernet-switching filter input watch-employee
To configure port mirroring of all traffic from the two ports connected to employee
computers to the
remote-analyzer
Configure the
1.
employee-web-monitor
[edit ethernet-switching-options]
user@switch# set interfaces ge-0/0/10 unit 0 family ethernet-switching port mode
trunk
user@switch# set analyzer employee-web-monitor loss-priority high output vlan 999
Configure the VLAN tag ID for the
2.
[edit vlans]
user@switch# set remote-analyzer vlan-id 999
Configure the interface to associate it with the
3.
[edit interfaces]
user@switch# set ge-0/0/10 unit 0 family ethernet-switching vlan members 999
Configure the firewall filter called
4.
[edit firewall family ethernet-switching]
user@switch# set filter watch-employee term employee-to-corp from
destination-address 192.0.2.16/28
user@switch# set filter watch-employee term employee-to-corp from source-address
192.0.2.16/28
user@switch# set filter watch-employee term employee-to-corp then accept
user@switch# set filter watch-employee term employee-to-web from destination-port
80
user@switch# set filter watch-employee term employee-to-web then analyzer
employee-web-monitor
Apply the firewall filter to the employee interfaces:
5.
[edit interfaces]
user@switch# set ge-0/0/0 unit 0 family ethernet-switching filter input watch-employee
user@switch# set ge-0/0/1 unit 0 family ethernet-switching filter input watch-employee
Check the results of the configuration:
[edit]
user@switch# show
interfaces {
VLAN for use from a remote monitoring station:
analyzer:
remote-analyzer
VLAN:
remote-analyzer
:
watch-employee
Copyright © 2010, Juniper Networks, Inc.
VLAN:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents