[j-nsp] Bulk updates to Netscreen 5400

Phil Mayers p.mayers at imperial.ac.uk
Fri Jun 26 07:52:49 EDT 2009


All,

We have a (quite busy) netscreen 5400, which we occasionally need to 
make big policy updates to. It goes very slow if we paste in changes via 
the CLI, and we're not inclined to buy Netscreen Security Manager (or 
whatever it's called these days) because our reseller stiffed us on a 
promised upgrade, and the demo we had was anyway pretty underwhelming.

However - I have it on good authority that NSM merely uses a hidden CLI 
command to start & commit bulk updates "all at once", a bit like SQL

e.g.

set mode bulk
set address Trust ...
...100 more lines
set mode bulk-commit

...or something like that. Does anyone know what those magic commands 
are, if they really exist? Are there any caveats to using them?


More information about the juniper-nsp mailing list