Saturday, October 3, 2015

BGP Path selection For Cisco devices.



Note referenced by http://www.ciscozine.com/bgp-best-path-selection


Basic configuration for Juniper Qfx Switches

{master:0}[edit]
root# run show configuration |display set |no-more
set version 13.2X51-D35.3
set system host-name S
set system no-multicast-echo
set system no-ping-record-route
set system no-ping-time-stamp
set system arp aging-timer 5
set system internet-options tcp-drop-synfin-set
set system root-authentication encrypted-password
set system login user w uid 2000
set system login user w class super-user
set system login user w authentication encrypted-password Gva8RCKITh1wEGOZ8R7k18DxeAYa"
set system login password minimum-length 8
set system login password maximum-length 22
set system login password minimum-numerics 1
set system login password minimum-upper-cases 1
set system login password minimum-lower-cases 1
set system login password minimum-punctuations 1
set system login password format sha1
set system services ssh protocol-version v2
set system services telnet
set system commit synchronize
set system processes app-engine-virtual-machine-management-service traceoptions level notice
set system processes app-engine-virtual-machine-management-service traceoptions flag all
set chassis redundancy graceful-switchover
set chassis aggregated-devices ethernet device-count 30
set interfaces xe-0/0/46 description "Connected to YBLDRSRVCSW01-Rack 9 - Port - Xe-0/0/38"
set interfaces xe-0/0/46 unit 0 family ethernet-switching interface-mode trunk
set interfaces xe-0/0/46 unit 0 family ethernet-switching vlan members 417
set interfaces xe-0/0/46 unit 0 family ethernet-switching vlan members 428
set interfaces xe-0/0/47 unit 0 family ethernet-switching interface-mode trunk
set interfaces xe-0/0/47 unit 0 family ethernet-switching vlan members 417
set interfaces xe-0/0/47 unit 0 family ethernet-switching vlan members 428
set interfaces xe-1/0/47 unit 0 family ethernet-switching interface-mode trunk
set interfaces xe-1/0/47 unit 0 family ethernet-switching vlan members 417
set interfaces xe-1/0/47 unit 0 family ethernet-switching vlan members 428
set interfaces vme unit 0 family inet address 10.224.252.80/24
set forwarding-options storm-control-profiles default all
set forwarding-options storm-control-profiles sc all bandwidth-level 15000
set routing-options nonstop-routing
set protocols lldp interface all disable
set protocols lldp-med interface all
set protocols igmp-snooping vlan default
set protocols layer2-control nonstop-bridging
set protocols layer2-control bpdu-block disable-timeout 60
set protocols rstp interface xe-0/0/46
set protocols rstp interface xe-0/0/47
set protocols rstp interface xe-1/0/47
set virtual-chassis preprovisioned
set virtual-chassis no-split-detection
set virtual-chassis member 0 role routing-engine
set virtual-chassis member 0 serial-number VF371
set virtual-chassis member 1 role routing-engine
set virtual-chassis member 1 serial-number VF37
set virtual-chassis member 2 role line-card
set virtual-chassis member 2 serial-number PE37
set vlans HSD vlan-id 428
set vlans Management-monitoring vlan-id 417
set vlans default vlan-id 1
set vlans default l3-interface irb.0

Optimization of fortigate IPS

IPS signature need select according to infrastructure environment  Eg:-  if  we are not have Linux servers this ips signature can disable (d...