ANR report with port mirror (aka SPAN)

OneConfig’s Application and Network Risk Report is a pre-sales tool to make demonstrating the Juniper SRX firewall in a customer’s own environment simple and compelling.

The typical deployment for a demonstration SRX using OneConfig’s pre-sales ANR Report is to use the SRX’s “secure-wire” feature to put the SRX inline in a customer’s network. This is simple as it only requires a cable change. However, this change is sometimes seen as complex and posing a potential risk of disruption to user traffic. 

An alternative method is available. It is possible to get a copy of user traffic from the network switches using the port mirror feature (often called “SPAN port”).

 

 

This approach allows the switch to pass traffic to the SRX, thereby avoiding the need to change the production cabling layout.

A video overview of the ANR pre-sales report solution

Configuration Examples

Blocking outbound traffic from SRX towards the switch

Some switches have issues with this setup when the traffic is passed through the SRX and then is sent to the opposite mirror port. To avoid this we can add some low level filtering config to the SRX to have it block outbound traffic on the secure wire ports.

set interfaces ge-0/0/0 unit 0 family bridge filter output block-out
set interfaces ge-0/0/1 unit 0 family bridge filter output block-out
set firewall family bridge filter block-out term block-all then discard
 

Port Mirror configuration - Juniper EX

set ethernet-switching options analyzer trust–monitor input ingress interface ge-0/0/5.0
set ethernet-switching options analyzer trust–monitor input ingress interface ge-0/0/6.0
set ethernet-switching options analyzer trust–monitor output interface ge-0/0/7.0
set ethernet-switching options analyzer untrust–monitor input ingress interface ge-0/0/0.0
set ethernet-switching options analyzer untrust–monitor output interface ge-0/0/8.0

SPAN port configuration - Cisco Nexus

!!!!!!!!!!!!!!!!!!!!!!Cisco Nexus Config
!
!
interface Ethernet1/10
description to Juniper SRX ge-0/0/1 for ANR
switchport monitor
!
interface Ethernet1/11
description to Juniper SRX ge-0/0/2 for ANR
switchport monitor
!
monitor session 1
description SPAN to Juniper SRX550
source interface Ethernet1/1 rx
destination interface Ethernet1/10
no shut
monitor session 2

description SPAN to Juniper SRX550

source interface Ethernet1/1 tx

destination interface Ethernet1/11

no shut