[Contents] [Prev] [Next] [Index] [Report an Error]

Defining Services for Mirroring on JUNOS Routing Platforms

Figure 13 illustrates the services in the sample data that mirror subscriber traffic from JUNOS routing platforms to an IDP sensor and shows the routers on which the services are activated. In this example, the DN for subscriber profiles is routerName= default@JunoseB, <DN of Router Profiles>.

Figure 13: Services to Mirror Traffic to an IDP Sensor

Image g015763.gif

The Surveillance Director passes the value for the subrSubnet parameter to the aggregate service; the aggregate service then passes the value of the parameter to the router fragment services. For example, in Figure 14 the Surveillance Director passes value 111.2.1.6/31 for the CIDR subnet, to the aggregate service. The aggregate service passes the value for the CIDR subnet to the router fragment services.

Figure 14: Sample Values for SubrSubnet Parameter in Services for Mirroring

Image g015764.gif

Before you configure services to mirror subscriber traffic to an IDP sensor:

To configure services to mirror subscriber traffic to an IDP sensor:

  1. Configure a policy to mirror traffic for a set of subscribers (selected by Surveillance Director) to the IDP sensor. The subrSubnet parameter (for a specified CIDR subnet) includes the source IP addresses designated for traffic sent by these subscribers.

    For a mirroring policy, you specify policy rules for traffic sent to and received from the subscriber subnet (the value of the subrSubnet parameter) that have the action Port Mirror.

    For a sample policy that implements mirroring, see policyGroupName=mirrorToIdp, ou=idp, o=Policies, o=umc in the sample data.

  2. Create a service, which is a router fragment service in this configuration; set the type to normal; and specify the policy group configured in Step 1. This service is activated once for each JUNOS routing platform in a specified POP.

    For a sample service, see servicename=RouterFragment, l=IDP-JunosPop, o=Scopes, o=umc in the sample data.

  3. Create an aggregate service; add the service configured in Step 2 to the aggregate service; and in the Service Fragment dialog box specify:

    For a sample aggregate service, see serviceName=CheckForAttacks, l=IDP-JunosPop, o=Scopes, o=umc in the sample data.


[Contents] [Prev] [Next] [Index] [Report an Error]