[j-nsp] Logging Question for SRX

Jeff Ambern ambernj at comcast.net
Sun Oct 22 10:10:36 EDT 2017


Hi,

   I have a customer that is trying to get more visibility into their NAT addressing.

Question:
The current report includes a timeframe and the public (Nat'd) address. We would like to set up logging so we can identify the internal address and ultimately the mac address of the device. We do log closed nat sessions on our other networks . Is this the best way to obtain the translations or have you come across any other method? 
Do you think the additional logging will impact firewall performance?

Any suggestions how to best accomplish this?

Thanks,
Jeff


More information about the juniper-nsp mailing list