Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asean Region (Vietnam, Indonesia, Singapore, Malaysia)
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

Technical Documentation

Support
Technical Documentation
Content Explorer New
 
Enterprise MIBs
 
EOL Documentation
 
Feature Explorer Login required New
 
File Format Help
 
Glossary
 
Portable Libraries
 
 
Home > Support > Technical Documentation > JunosE Software > RADIUS-Based Mirroring Sequence of Events
Print
Rate and give feedback:  Feedback Received. Thank You!
Rate and give feedback: 
Close
This document helped resolve my issue.  Yes No

Additional Comments

800 characters remaining

May we contact you if necessary?

Name:  
E-mail: 
Submitting...
 

Related Documentation

  • Configuring RADIUS-Based Packet Mirroring
  • RADIUS-Based Mirroring Overview
 

RADIUS-Based Mirroring Sequence of Events

Figure 1 shows the sequence of events that take place during RADIUS-based mirroring. The tables after the figure describe the events indicated by the numbers and letters in the figure. Table 1 describes the configuration process; Table 2 describes the flow of traffic during a mirroring operation that is initiated when the user logs in; and Table 3 describes the flow of traffic when mirroring a user who is already logged in.

Figure 1: RADIUS-Based Packet Mirroring

RADIUS-Based Packet Mirroring

To create a RADIUS-based packet-mirroring environment, you must complete the processes listed in Table 1.

Table 1: Setting Up the RADIUS-Based Packet-Mirroring Environment

Process

Description

A

The authorized individual requests packet mirroring of the user’s traffic and configures the analyzer device to receive mirrored traffic.

B

The ISP administration configures VSAs in the user’s RADIUS record.

C

The E Series router administrator configures RADIUS server information and the analyzer interface connection to the analyzer device.

Table 2 indicates the sequence of steps for a packet mirroring operation that takes place when a user starts a new session.

Table 2: RADIUS-Based Mirroring During Session Start (User-Initiated)

Step

Description

1

A user logs in to an E Series router, requesting authentication by the RADIUS server. Attributes in the logon request are examined to determine whether any match a configured trigger. The first match starts the packet mirroring session for the user.

2

  • The RADIUS server authenticates the user and sends packet mirroring VSAs and any other configured VSAs to the router.
  • The router creates a secure policy based on the VSAs and starts mirroring the user’s traffic.

3

The router sends the user’s original traffic to its intended destination.

4

The router sends the mirrored traffic to analyzer device.

5

The analyzer device provides information for the requesting individual.

Table 3 indicates the sequence of steps for a packet mirroring operation that is configured for a currently running session.

Table 3: RADIUS-Based Mirroring of Currently Running Session (RADIUS-Initiated)

Step

Description

1

A user logs in to the E Series router; no mirroring action is configured.

2

  • Packet mirroring is enabled on the RADIUS server.
  • Authenticated users are examined to determine whether any match a configured trigger. The first match determines the router to which to send change-of-authorization messages.
  • The RADIUS server sends change-of-authorization messages containing packet mirroring VSAs to the router.
  • The router creates a secure policy based on the VSAs and starts mirroring the user’s traffic.

3

The router sends the user’s original traffic to its intended destination.

4

The router sends mirrored traffic to the analyzer device.

5

The analyzer device provides information for the requesting individual.

 

Related Documentation

  • Configuring RADIUS-Based Packet Mirroring
  • RADIUS-Based Mirroring Overview
 

Published: 2012-06-21

 
  • About Juniper
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Green Networking
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Developers
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out