顯示具有 Juniper 標籤的文章。 顯示所有文章
顯示具有 Juniper 標籤的文章。 顯示所有文章

2020年2月9日

BGP Looking Glass Server

日常的工作需要Looking Glass 加快查修問題的速度,除了BGP網路外,還有一般的專線跟上網線路,都會需要類似BGP Looking Glass Server的功能,想把它整合成統一的Ping Server,目前使用了Open Source的BGP Looking Glass程式,再稍微修改一下程式後,就可以達到想要的功能,以下為在CentOS上面建置的方式

Step 1:先到https://github.com/Cougar/lg ,先照網站上面的介紹,捉取程式
yum install git
git config --global url."https://".insteadOf git://
git clone https://github.com/Cougar/lg.git

Step 2:安裝必要的環境程式
yum install wget perl-Net-Telnet perl-Net-Telnet-Cisco perl-XML-Parser httpd
yum install gcc* perl-CPAN
yum install perl*
yum install mtr
yum install perl-DB_File
安裝perl的外掛,要用cpanm 安裝,後面CGI程式會到用,沒安裝會無法執行主程式,會一直跳Perl執行錯的error log
cpanm Net::SSH::Perl
cpanm Net::Telnet::Perl

Step 3:將git捉下來的程式放到WEB執行的目錄,並設定好對應的Apache的權限
mkdir /var/www/html/lg
cd /var/www/html/lg
cp /root/lg-1.9/lg.cgi .
cp /root/lg-1.9/favicon.ico .
cp /root/lg-1.9/lg.conf .

(繼續閱讀...)

2019年10月5日

Juniper 高階SRX Cluster Login Other RE方式

適用於高階SRX 的型號如3000系列或是5000系列
{primary:node0}
user@SRX01-LAB-DC> start shell 
% rlogin -Jk -T node1
 
--- JUNOS 15.1X49-D170.4 built 2019-02-22 23:02:01 UTC
{secondary:node1}
user@SRX02-LAB-DC> 
適用於一般低階SRX 的型號(通用指令)
{primary:node0}
user@SRX01-LAB-DC> request routing-engine login node 1          
 
--- JUNOS 15.1X49-D170.4 built 2019-02-22 23:02:01 UTC
{secondary:node1}
user@SRX02-LAB-DC> 
(繼續閱讀...)

2019年7月21日

Juniper OSPF traceoptions

set protocols ospf traceoptions file ospf.log
set protocols ospf traceoptions flag database-description
set protocols ospf traceoptions flag event
set protocols ospf traceoptions flag error
set protocols ospf traceoptions flag lsa-request

(繼續閱讀...)

2019年6月27日

Juniper SRX Monitor Traffic

Host:
root# run monitor traffic interface ge-0/0/x matching "host 10.130.38.94" no-resolve

Protocol:
root# run monitor traffic interface ge-0/0/x matching arp

Port:
root# run monitor traffic interface ge-0/0/x matching "port 22"

IP address:
root# run monitor traffic interface ge-0/0/x matching "host 10.130.38.94" no-resolve detail

A network:
root# run monitor traffic interface ge-0/0/x matching "net 225.1.1.0/24" no-resolve detail

TCP port 179:
root# run monitor traffic interface ge-0/0/x matching "tcp port 179"

(繼續閱讀...)

2017年11月19日

Juniper BGP 調整特定國家路由優先權

針對國別調整BGP優先權
一、先用https://ipinfo.io/countries/cn 找出要調整的國家的全部AS Number,將這些AS Number做利用正規化表示法設定成一組國別清單

set policy-options as-path China-AS-Path ".* 4134 |.* 4538 |.* 4611 |.* 4808 |.* 4809 |.* 4812 |.* 4813 |.* 4815 |.* 4816 |.* 4835 |.* 4837 |.* 4847 |.* 4859 |.* 7497 |.* 7549 |.* 7638 |.* 7640 |.* 7641 |.* 9298 |.* 9306 |.* 9308 |.* 9389 |.* 9391 |.* 9394 |.* 9395 |.* 9401 |.* 9535 |.* 9801 |.* 9802 |.* 9803 |.* 9805 |.* 9807 |.* 9808 |.* 9809 |.* 9810 |.* 9811 |.* 9812 |.* 9814 |.* 9929 |.* 9939 |.* 10206 |.* 10212 |.* 17428 |.* 17429 |.* 17430 |.* 17431 |.* 17490 |.* 17621 |.* 17622 |.* 17623 |.* 17633 |.* 17638 |.* 17739 |.* 17775 |.* 17781 |.* 17785 |.* 17799 |.* 17816 |.* 17883 |.* 17897 |.* 17962 |.* 17964 |.* 17966 |.* 17968 |.* 17969 |.* 18011 |.* 18118 |.* 18239 |.* 18241 |.* 18242 |.* 18243 |.* 18244 |.* 18245 |.* 18257 |.* 18344 |.* 23650 |.* 23724 |.* 23771 |.* 23839 |.* 23840 |.* 23841 |.* 23842 |.* 23844 |.* 23848 |.* 23851 |.* 23853 |.* 23910 |.* 23911 |.* 24059 |.* 24133 |.* 24134 |.* 24137 |.* 24138 |.* 24139 |.* 24141 |.* 24143 |.* 24147 |.* 24151 |.* 24311 |.* 24400 |.* 24404 |.* 24406 |.* 24409 |.* 24413 |.* 24414 |.* 24416 |.* 24420 |.* 24422 |.* 24424 |.* 24427 |.* 24428 |.* 24429 |.* 24430 |.* 24444 |.* 24445 |.* 24489 |.* 24490 |.* 24495 |.* 24547 |.* 24575 |.* 37937 |.* 37940 |.* 37941 |.* 37942 |.* 37943 |.* 37957 |.* 37958 |.* 37963 |.* 37965 |.* 37970 |.* 37981 |.* 38019 |.* 38027 |.* 38057 |.* 38238 |.* 38283 |.* 38339 |.* 38340 |.* 38341 |.* 38342 |.* 38345 |.* 38346 |.* 38353 |.* 38357 |.* 38358 |.* 38363 |.* 38364 |.* 38365 |.* 38366 |.* 38367 |.* 38370 |.* 38372 |.* 38375 |.* 38378 |.* 38379 |.* 38380 |.* 38381 |.* 38792 |.* 45057 |.* 45058 |.* 45061 |.* 45062 |.* 45064 |.* 45069 |.* 45070 |.* 45071 |.* 45075 |.* 45079 |.* 45080 |.* 45083 |.* 45084 |.* 45086 |.* 45087 |.* 45090 |.* 45093 |.* 45095 |.* 45100 |.* 45101 |.* 45102 |.* 45110 |.* 45113 |.* 45587 |.* 45888 |.* 55439 |.* 55461 |.* 55468 |.* 55515 |.* 55786 |.* 55956 |.* 55958 |.* 55960 |.* 55963 |.* 55966 |.* 55967 |.* 55971 |.* 55973 |.* 55982 |.* 55986 |.* 55988 |.* 55990 |.* 55992 |.* 55994 |.* 55996 |.* 55998 |.* 56000 |.* 56001 |.* 56002 |.* 56003 |.* 56005 |.* 56006 |.* 56008 |.* 56012 |.* 56013 |.* 56015 |.* 56019 |.* 56040 |.* 56041 |.* 56042 |.* 56044 |.* 56046 |.* 56047 |.* 56048 |.* 56282 |.* 56292 |.* 58416 |.* 58448 |.* 58461 |.* 58466 |.* 58517 |.* 58518 |.* 58519 |.* 58520 |.* 58536 |.* 58539 |.* 58540 |.* 58541 |.* 58542 |.* 58543 |.* 58563 |.* 58571 |.* 58593 |.* 58741 |.* 58811 |.* 58844 |.* 58845 |.* 58850 |.* 58852 |.* 58854 |.* 58864 |.* 58866 |.* 58879 |.* 58962 |.* 58997 |.* 58998 |.* 59008 |.* 59009 |.* 59010 |.* 59011 |.* 59015 |.* 59019 |.* 59023 |.* 59025 |.* 59028 |.* 59029 |.* 59034 |.* 59037 |.* 59045 |.* 59049 |.* 59050 |.* 59063 |.* 59065 |.* 59067 |.* 59072 |.* 59073 |.* 59074 |.* 59077 |.* 59078 |.* 59083 |.* 59089 |.* 63530 |.* 63531 |.* 63534 |.* 63535 |.* 63540 |.* 63541 |.* 63545 |.* 63548 |.* 63549 |.* 63554 |.* 63555 |.* 63558 |.* 63561 |.* 63570 |.* 63571 |.* 63580 |.* 63582 |.* 63583 |.* 63616 |.* 63617 |.* 63620 |.* 63621 |.* 63631 |.* 63634 |.* 63646 |.* 63655 |.* 63659 |.* 63677 |.* 63678 |.* 63679 |.* 63680 |.* 63689 |.* 63690 |.* 63691 |.* 63696 |.* 63697 |.* 63707 |.* 63711 |.* 63725 |.* 63835 |.* 63838 |.* 131325 |.* 131450 |.* 131477 |.* 131486 |.* 131503 |.* 131519 |.* 131524 |.* 131535 |.* 132058 |.* 132203 |.* 132510 |.* 132525 |.* 132719 |.* 133111 |.* 133118 |.* 133119 |.* 133151 |.* 133194 |.* 133219 |.* 133465 |.* 133475 |.* 133478 |.* 133513 |.* 133514 |.* 133626 |.* 133774 |.* 133775 |.* 133776 |.* 133865 |.* 133952 |.* 134103 |.* 134238 |.* 134417 |.* 134418 |.* 134419 |.* 134420 |.* 134542 |.* 134543 |.* 134755 |.* 134756 |.* 134761 |.* 134762 |.* 134763 |.* 134764 |.* 134765 |.* 134766 |.* 134768 |.* 134769 |.* 134771 |.* 134772 |.* 134810 |.* 135006 |.* 135061 |.* 135357 |.* 135363 |.* 135365 |.* 135577 |.* 135629 |.* 136011 |.* 136180 |.* 136189 |.* 136190 |.* 136390 |.* 136421 |.* 136559 |.* 136758"

(繼續閱讀...)

2017年9月16日

Juniper SRX QoS 設定 ( Class of Service)

Key Components
Interface Egress Queues – When a physical interface tries to send more traffic than its bandwidth permits, packets are queued in one of a few different numbered queues

Interface Bandwidth Definition – You should manually define the bandwidth of an interface if it is lower than the line speed. For example, a 1gbit interface connected to a 200mbit fibre ethernet line needs to be defined as being 200mbit else it will assume 1gbit and QoS will not work

Forwarding Classes – These effectively assign a name to a numbered queue, for example assured-forwarding

Assignment of traffic to a forwarding class – This can be done in a number of ways:
Classifiers – These observe DSCP, Inet Precedence or other marker types to assign ingress traffic to forwarding classes
Firewall Rules – Ingress traffic can be matched with firewall rules and assigned to forwarding classes

Drop Profiles – A drop profile defines the probability of packets being dropped when a queue reaches a certain size

Schedulers – These define how differently queued egress traffic is prioritized

Scheduler Maps – These link forwarding classes to schedulers

(繼續閱讀...)

2016年9月30日

常見路由器設備商的Administrative distance / Route preference 預設值比較


(繼續閱讀...)

2016年9月17日

Juniper Router BGP路徑選擇

BGP路徑選擇的步驟如下所示:
第一步:各個路徑的 Next-Hop屬性在本地路由表必須是可達的,如果不可達,本地路由器,會丟棄該路徑。

第二步:路由器會選擇具有最佳(高)Local-Preference 屬性值的路徑

第三步:路由器會選擇具有最短 AS Path 長度的路徑
(繼續閱讀...)

2016年8月6日

IPv6 LAB 進階實作

Mikrotik_RouterOS設定
[admin@Mikrotik_RouterOS] > /export 
/interface ethernet
set [ find default-name=ether1 ] name=ether1_MGMT speed=1Gbps
set [ find default-name=ether2 ] name=ether2_WAN
set [ find default-name=ether3 ] name=ether3_LAN
/ip address
add address=192.168.88.30/24 interface=ether1_MGMT network=192.168.88.0
add address=192.168.98.254/24 interface=ether3_LAN network=192.168.98.0
/ipv6 address
add address=2001:b034:700:480::254/80 advertise=no interface=ether3_LAN
add address=2001:b034:700:400::1:1/112 advertise=no interface=ether2_WAN
/ipv6 route
add check-gateway=ping distance=1 dst-address=2001:b034:700:480::/64 gateway=2001:b034:700:480::253
/system identity
set name=Mikrotik_RouterOS
(繼續閱讀...)

2015年12月27日

Juniper SRX自動備份

設定有修改設定檔commit就自動備份
root@888# show  system archival | display set
set system archival configuration transfer-on-commit
set system archival configuration archive-sites "ftp://帳號@192.168.88.1/路徑" password "ftp密碼"

(繼續閱讀...)

2015年11月29日

Juniper SRX Cluster HA設定

Juniper SRX Cluster HA












(繼續閱讀...)

2015年11月1日

Juniper SRX traceoptions

設定相關Filter做Debug Mode使用
root@junos-SRX> show configuration security flow | display set
set security flow traceoptions file tracetest
set security flow traceoptions flag basic-datapath
set security flow traceoptions packet-filter ICMP-Filter protocol icmp
set security flow traceoptions packet-filter ICMP-Filter source-prefix 192.168.88.0/24
set security flow traceoptions packet-filter ICMP-Filter destination-prefix 168.95.1.1/32

root@junos-SRX> show configuration security flow
traceoptions {
    file tracetest;
    flag basic-datapath;
    packet-filter ICMP-Filter {
        protocol icmp;
        source-prefix 192.168.88.0/24;
        destination-prefix 168.95.1.1/32;
    }
}
(繼續閱讀...)

2015年10月11日

Juniper SRX 常用命令

rollback
set interface
set routing-options static
set system login user admin class super-user
set system login user admin authentication plain-text-password 输入密码
set system services ssh
set security zones security-zone untrust host-inbound-traffic system-services ssh/ping
set security zones security-zone untrust interfaces ge-0/0/0.0 host-inbound-traffic system-services ssh /telnet/ping
set security zones security-zone trust host-inbound-traffic system-services ssh /telnet /ping
set security zones security-zone trust interfaces ge-0/0/1.0 host-inbound-traffic system-services ssh /telnet/ping
set security zones security-zone untrust interfaces ge-0/0/0 (不定義區域,無法配置NAT)
set security zones security-zone trust interfaces ge-0/0/1
set security zones security-zone trust interfaces ge-0/0/1 ???
set interfaces interface-range interfaces-trust member ge-0/0/1  ????

(繼續閱讀...)

Copyright © 2009 New Life in Taipei All rights reserved. Theme by Laptop Geek. | Bloggerized by FalconHive.