Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

mirror port on srx240

Posted on 2015-01-07
3
Medium Priority
?
355 Views
Last Modified: 2015-01-18
I have several srx240 and I'd like to monitor my WAN port with Wireshark. I am new to Juniper. So I am just wondering if anybody can provide some guidance in configuring the mirror port on my srx240.

This is what I intend to setup:
Internet <--ge-0/0/0-->srx240<--ge-0/0/1-->internal network
                                         |
                                 ge-0/0/2 (this is where my PC with Wireshark is connected to)

Thanks
0
Comment
Question by:leblanc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 26

Accepted Solution

by:
Fred Marshall earned 2000 total points
ID: 40536960
Juniper Networks provides the configuration entries necessary to do this at:
http://kb.juniper.net/InfoCenter/index?page=content&id=KB21833
0
 
LVL 1

Author Comment

by:leblanc
ID: 40537005
That looks complex. I see the Security section and I am not sure I understand the implication of it. My FW is in a production environment and I don't want to compromise the security. Does this section mean that it will allow everything to go through the FW?

security {
    policies {
        default-policy {
            permit-all;
        }
    }
    zones {
        security-zone trust {
            host-inbound-traffic {
                system-services {
                    all;
                }
                protocols {
                    all;
                }
            }
            interfaces {
                all;

Open in new window

0
 
LVL 26

Assisted Solution

by:Fred Marshall
Fred Marshall earned 2000 total points
ID: 40537070
In some sense, such is the structure of a JUNOS configuration.

You said you wanted to mirror the "WAN" port.  
That means you want to mirror the public side / a port in the untrust zone.
So, *of course* the firewall will let everything through because that's the essential port being firewalled otherwise.
That's what mirroring is supposed to do.
But this is not to say that the firewall will let everything from the Untrust zone to the Trust zone at all.

Perhaps we should talk about normal mirror ports.
Usually they are disconnected from all other ports.
Usually you would connect to them with a separate NIC that may have NO TCP/IP protocol installed because all you're going to do with it is *watch* the traffic and not interact with it.

I do essentially the same thing by mirroring the same port where it enters a switch.  Then I set up a mirror port on the switch.  It's a lot easier than dealing with JUNOS code.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Monitor input from a computer is usually nothing special.  In this instance it prevented anyone from using the computer.  This was a preconfiguration that didn't work.
This article shows how to use a free utility called 'Parkdale' to easily test the performance and benchmark any Hard Drive(s) installed in your computer. We also look at RAM Disks and their speed comparisons.
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
This tutorial will teach you the special effect of super speed similar to the fictional character Wally West aka "The Flash" After Shake : http://www.videocopilot.net/presets/after_shake/ All lightning effects with instructions : http://www.mediaf…
Suggested Courses

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question