The RADIUS-initiated mirroring provided by the subscriber secure policy service runs on the flow-tap service infrastructure. This topic describes the steps to enable flow-tap support for subscriber secure policy mirroring.
![]() |
Note: To configure the subscriber secure policy service, you must have the same privileges that are required to configure the flow-tap service. |
To configure the flow-tap service to support subscriber secure policy mirroring:
- [edit services]
- user@host# set flow-tap interface sp-1/2/0.100
See “Flow-Tap Configuration Guidelines” in the JUNOS Services Interfaces Configuration Guide for details on configuring the flow-tap service.
You can configure a maximum of 2048 mirrored subscriber sessions per chassis.
- [edit chassis]
- user@host# set fpc 4 pic 1 tunnel-services
bandwidth 1g
- [edit interfaces]
- user@host# set vt-4/1/10.0
- user@host# set vt-4/2/10.0
![]() |
Note: If a currently used tunnel interface is deleted from the pool of interfaces, the subscriber secure policy service redistributes the active mirroring sessions from the deleted interface to other tunnel interfaces in the pool. Also, when a new tunnel interface is added into the pool, the service adds the new interface to the list of available interfaces—the new interface is used for new mirroring sessions or for existing sessions transferred from a failed interface. |
- [edit services]
- user@host# set radius-flow-tap interfaces
vt-4/1/10.0
- user@host# set radius-flow-tap interfaces
vt-4/2/10.0
- [edit services]
- user@host# set radius-flow-tap source-ipv4-address
192.168.100.33
If you do not specify a forwarding class, the mirrored packets inherit the forwarding class from the original packet (which is the forwarding class set by default classification that CoS applies to the packet on the ingress interface).
- [edit services]
- user@host# set radius-flow-tap forwarding-class
best-effort