4-Byte Format; Resolving And Tracking The Analyzer Device's Address; Figure 23: 8-Byte Format Of Vsa 26-59; Figure 24: 4-Byte Format Of Vsa 26-59 - Juniper JUNOSE SOFTWARE FOR E SERIES 11.3.X - POLICY MANAGEMENT CONFIGURATION GUIDE 2010-10-04 Configuration Manual

Software for e series broadband services routers policy management configuration guide
Hide thumbs Also See for JUNOSE SOFTWARE FOR E SERIES 11.3.X - POLICY MANAGEMENT CONFIGURATION GUIDE 2010-10-04:
Table of Contents

Advertisement

JunosE 11.3.x Policy Management Configuration Guide

Resolving and Tracking the Analyzer Device's Address

246
Mirror Identifier = 0x300
Session-ID = 0x90

Figure 23: 8-Byte Format of VSA 26-59

4-Byte Format

To use the 4-byte format of VSA 26-59, you configure the first two most significant bits
of the VSA to a value of 1, which indicates a single word in the VSA. The remaining 30
bits of the word form the Mirror Identifier value. The router then creates the Session-ID
value based on the least significant 32 bits of the Acct-Session-ID (RADIUS attribute
44).
For example, a value of 40000010 for VSA 26-59 configures the following fields in the
mirror header, as shown in Figure 24 on page 246:
MHV = 1
Mirror Identifier = 0x10

Figure 24: 4-Byte Format of VSA 26-59

During the packet mirroring configuration process, you specify the IP address of the
analyzer device to which the mirrored traffic is sent. For CLI-based packet mirroring, you
use the mirror analyzer-ip-address command to specify the IP address. For RADIUS-based
packet mirroring, the RADIUS attribute Med-IP-Address [26-60] is the address of the
analyzer device.
After configuration is complete, the router performs a route lookup to resolve the analyzer
device's address and to ensure that traffic can be forwarded to the analyzer device for
analysis. However, the analyzer device is considered unreachable if the router's analyzer
interface is not in analyzer mode, is not yet created, or if the routes to the analyzer device
are absent
If the analyzer device is unreachable, then the mirror action in the secure policy is disabled,
and no packets are mirrored. The show secure policy-list command output indicates
that the mirror action is disabled and the analyzer device is unreachable.
The router tracks the analyzer device's IP address for any route changes within the router.
This tracking ability provides a degree of failure recovery by enabling you to configure
multiple analyzer interfaces to serve as redundant ports to reach the analyzer device.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.3

Table of Contents