[j-nsp] netflow config clue needed

Pekka Savola pekkas at netcore.fi
Sun Sep 7 17:56:26 EDT 2003


On Sat, 6 Sep 2003, Randy Bush wrote:
> >       firewall {
> >           filter CampusIO {
> >               term all {
> >                   then {
> >                       sample;
> >                       accept;
> >                   }
> >               }
> >           }
> >       }
> 
> this approximates what i changed to and it works.  as i already
> had an edge firewall filter to keep my own address space on the
> right side of the edge, i just added to the ruleset.

That's how we do it too.

> > I've never tried the method you showed below, using a sample stanza
> > within the sub-interface definition.
> 
> came off the juniper web site. :-(

I think the "interface sampling" only works for specific interfaces only, 
namely monitoring services PIC and adaptive services PIC.

Allowing it to be configured on your regular interfaces is likely a bug..

-- 
Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings




More information about the juniper-nsp mailing list