[j-nsp] QFX5100 routing engine filter eats customer l2circuit packets

Chris Wopat me at falz.net
Tue Jan 17 17:38:57 EST 2017


On 01/14/2017 02:25 AM, nebu thomas wrote:
> Hi Chris,
> Per your email , I understand it is this specific payload coming thru the L2ckt which is reporting this issue .
>
> Hence my earlier suggestion to test with14.1X53-D40 , and verify whether it helps in your case .

We were able to do some lab testing on D40 today and it is indeed acting 
quite differently than D35 was.

* Previously 'monitor traffic interface <l2circuitiface>' would 
consistently show some types of the tunneled traffic hitting the RE 
(eigrp, ospf were tested).

* On D35 I could make many adjustments to the QFX's lo0 filter to get 
that traffic to drop. on D40 I am no longer able to, as expected.

Interesting as there were no fixes listed related to this. Perhaps the 
"LDP on IRB" change up also fixed this behavior.

If you (or anyone here?) is aware of the PR# related to this, I'd love 
to know what it was.

--Chris



More information about the juniper-nsp mailing list