[Contents] [Prev] [Next] [Index] [Report an Error]

Configuring DTCP-over-SSH Service for the Flow-Tap Application

The active monitoring flow-tap application requires you to configure the flow-tap DTCP-over-SSH service. Flow-tap enables you to intercept IPv4 packets transiting an active monitoring router and send a copy of matching packets to one or more content destinations, for use in flexible trend analysis of security threats and in lawful intercept of data.

To enable the flow-tap DTCP-over-SSH service, include the following statements at the [edit system services] hierarchy level:

flow-tap-dtcp {
ssh {
<connection-limit limit>;
<rate-limit limit>;
}
}

By default, the router supports a limited number of simultaneous flow-tap DTCP-over-SSH sessions and connection attempts per minute. Optionally, you can include either or both of the following statements to change the defaults:

You must also define user permissions that enable flow-tap users to configure flow-tap services. Specify a login class and access privileges for flow-tap users at the [edit system login class class-name permissions] hierarchy level:

[edit system login class class-name permissions]
(flow-tap | flow-tap-control | flow-tap-operation);

The permission bit for a flow-tap login class can be one of the following:

For more information about how to define login classes, see Defining Login Classes.

You can also specify user permissions through the Juniper-User-Permissions RADIUS attribute. For more information, see Configuring Juniper Networks Vendor-Specific RADIUS Attributes.

To enable the flow-tap DTCP-over-SSH service, you must also include statements at the [edit interfaces] hierarchy level to specify an Adaptive Services PIC that runs the flow-tap service and conveys flow-tap filters from the mediation device to the router. In addition, you must include the flow-tap statement at the [edit services] hierarchy level. For more information, see the JUNOS Services Interfaces Configuration Guide.


[Contents] [Prev] [Next] [Index] [Report an Error]