Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asean Region (Vietnam, Indonesia, Singapore, Malaysia)
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

Technical Documentation

Support
Technical Documentation
Content Explorer New
 
Enterprise MIBs
 
EOL Documentation
 
Feature Explorer Login required New
 
File Format Help
 
Glossary
 
Portable Libraries
 
 
Home > Support > Technical Documentation > JunosE Software > Configuring CLI-Based Packet Mirroring
Print
Rate and give feedback:  Feedback Received. Thank You!
Rate and give feedback: 
Close
This document helped resolve my issue.  Yes No

Additional Comments

800 characters remaining

May we contact you if necessary?

Name:  
E-mail: 
Submitting...
 

Related Documentation

  • Enabling and Securing CLI-Based Packet Mirroring
  • CLI-Based Packet Mirroring Sequence of Events
  • Reloading a CLI-Based Packet-Mirroring Configuration
  • classifier-group
  • ip analyzer
  • ip mirror
  • ip policy
  • mirror
  • mirror analyzer-ip-address
  • mirror disable
  • mirror disable
  • secure ip classifier-list
  • secure ipv6 classifier-list
  • secure ip policy-list
  • secure ipv6 policy-list
  • secure l2tp policy-list
 

Configuring CLI-Based Packet Mirroring

To configure the CLI-based packet-mirroring environment, you must coordinate the mirroring operations of two devices in the network: the E Series router and the analyzer device. The configuration of the analyzer device is mentioned in this section for reference only. The actual configuration procedures depend on the policies and guidelines established by the responsible organizations.

The secure ip policy and secure ipv6 policy commands are visible only to authorized users; the mirror-enable command must be enabled before using secure ip policy or secure ipv6 policy command. If you enter the secure ip policy or secure ipv6 policy command and the policy list does not exist, the router creates a policy list with a default mirror rule that disables mirroring. If you attach this policy list to an interface, there is no packet mirroring. When you use this command to create a secure policy list, statistics-related keywords are not supported.

The secure ip classifier-list command creates or modifies a secure IP classifier control list, which can then be included in a secure policy list.

The secure ipv6 classifier-list command creates or modifies a secure IPv6 classifier control list, which can then be included in a secure policy list.

Note: Do not use the asterisk (*) for the name of a classifier list. The asterisk is used as a wildcard for the classifier-group command.

Except for the following considerations, secure IP classifier lists are created and function the same as standard IP classifier lists—see Classifier Control Lists Overview for information:

  • The secure ip classifier-list and secure ipv6 classifier-list commands are visible only to authorized users—the mirror-enable command must be enabled before using this command.
  • Secure IP classifier lists and secure IPv6 classifier lists are the only types of classifier lists allowed in secure policy lists
  • Secure IP classifier lists and secure IPv6 classifier lists cannot be used in non-secure policy lists.
  • You can associate secure IP and secure IPv6 policy classifier lists with all secure IP and secure IPv6 policies dynamically created by RADIUS. This allows you to selectively identify and drop high load traffic, such as video.

The secure ip policy-list, secure ipv6 policy-list, and secure l2tp policy-list commands create or modify a secure IP, IPv6, or L2TP policy list. These commands are visible only to authorized users—the mirror-enable command must be enabled before using this command. These commands enter Policy List Configuration mode, enabling you to specify the parameters of the secure policy list. If you enter Policy List Configuration mode and then type exit without specifying any parameters, the router creates a policy list with a mirror disable rule. Attaching this policy list to an interface results in no packet mirroring.

Secure IP classifier lists are the only type of classifier lists allowed in secure IP policy lists. Secure L2TP policies do not support classification. Therefore, the only classifier group you can use for secure L2TP policies is classifier-group *. You cannot delete a secure policy list that is currently attached to an interface.

 

Related Documentation

  • Enabling and Securing CLI-Based Packet Mirroring
  • CLI-Based Packet Mirroring Sequence of Events
  • Reloading a CLI-Based Packet-Mirroring Configuration
  • classifier-group
  • ip analyzer
  • ip mirror
  • ip policy
  • mirror
  • mirror analyzer-ip-address
  • mirror disable
  • mirror disable
  • secure ip classifier-list
  • secure ipv6 classifier-list
  • secure ip policy-list
  • secure ipv6 policy-list
  • secure l2tp policy-list
 

Published: 2012-06-21

 
  • About Juniper
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Green Networking
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Developers
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out