Configuring Cli-Based Mirroring; Table 49: Cli-Based User-Specific Mirroring During Session Start; Table 50: Cli-Based Mirroring Of Currently Running Session - Juniper JUNOSE SOFTWARE FOR E SERIES 11.3.X - POLICY MANAGEMENT CONFIGURATION GUIDE 2010-10-04 Configuration Manual

Software for e series broadband services routers policy management configuration guide
Hide thumbs Also See for JUNOSE SOFTWARE FOR E SERIES 11.3.X - POLICY MANAGEMENT CONFIGURATION GUIDE 2010-10-04:
Table of Contents

Advertisement

JunosE 11.3.x Policy Management Configuration Guide

Configuring CLI-Based Mirroring

224
Table 49 on page 224 indicates the sequence of steps for a packet-mirroring operation
that takes place when a user starts a new session.

Table 49: CLI-Based User-Specific Mirroring During Session Start

Step
Description
1
The user logs in to an E Series router, requesting authentication by AAA.
2
AAA authenticates the user, and the router starts mirroring the user's traffic.
3
The router sends the user's original traffic to the intended destination.
4
The router sends the mirrored traffic to the analyzer device.
5
The analyzer device provides information to the requesting individual.
Table 50 on page 224 indicates the sequence of steps for a packet-mirroring operation
that is configured for an interface or for a user who is already logged in.

Table 50: CLI-Based Mirroring of Currently Running Session

Step
Description
1
For user-specific mirroring, the user logs in to the E Series router; no mirroring action is
configured.
2
CLI-based packet mirroring is configured and enabled on the router.
For interface-specific mirroring, the router starts mirroring all traffic for the interface.
For user-specific mirroring, AAA verifies that the mirrored user is already logged in,
then starts mirroring all subsequent traffic to or from the user.
3
The router sends the original traffic to its intended destination.
4
The router sends mirrored traffic to the analyzer device.
5
The analyzer device provides information for the requesting individual.
To configure the CLI-based packet-mirroring environment, you must coordinate the
mirroring operations of two devices in the network: the E Series router and the analyzer
device. The configuration of the analyzer device is mentioned in this section for reference
only. The actual configuration procedures depend on the policies and guidelines
established by the responsible organizations.
The secure ip policy and secure ipv6 policy commands are visible only to authorized
users; the mirror-enable command must be enabled before using secure ip policy or
secure ipv6 policy command. If you enter the secure ip policy or secure ipv6 policy
command and the policy list does not exist, the router creates a policy list with a default
mirror rule that disables mirroring. If you attach this policy list to an interface, there is no
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.3

Table of Contents