Sunday, February 7, 2016

Juniper devices configuration for SNMP and Tacacs

Tacacs configuration:

 
set system authentication-order tacplus
set system authentication-order password
set system accounting events login
set system accounting events change-log
set system accounting events interactive-commands
set system tacplus-server 10.56.252.252 secret (Secret key)
set system tacplus-server 10.56.252.252 single-connection
set system tacplus-server 10.10.0.204 secret (Secret key)
set system tacplus-server 10.10.0.204 single-connection
set system accounting destination tacplus server 10.56.252.252 source-address (switch management vlan IP)
set system accounting destination tacplus server 10.10.0.204 source-address (switch management vlan IP)
set system login user remote uid 2002
set system login user remote class super-user
 

SNMP configuration 


set  snmp location "Bangalore"
set  snmp community AnoopL authorization read-only
set  snmp community AnoopL clients default restrict
set  snmp community AnoopL!vv0 clients 10.10.14.192/26
set  snmp community AnoopL!vv0 clients 10.59.247.192/26
set  snmp community AnoopL!vv0 clients 10.13.45.0/26
set  snmp community AnoopL!vv0 clients 10.59.125.192/26
set  snmp community AnoopL!vv0 clients 10.30.5.128/26
set  snmp community AnoopL!vv0 clients 10.53.126.0/26
set  snmp community Anoopfvu! authorization read-write
set  snmp community Anoopfvu! clients default restrict
set  snmp community Anoopfvu! clients 10.10.14.192/26
set  snmp community Anoopfvu! clients 10.59.247.192/26
set  snmp community Anoopfvu! clients 10.13.45.0/26
set  snmp community Anoopfvu! clients 10.59.125.192/26
set  snmp community Anoopfvu! clients 10.30.5.128/26
set  snmp community Anoopfvu! clients 10.53.126.0/26
set  snmp trap-group Anoopfvu! targets 10.59.247.213
set  snmp trap-group Anoopfvu! version v1
set  snmp trap-group AnoopL!vv0 targets 10.59.247.213
set  snmp trap-group AnoopL!vv0 version v1
 

Optimization of fortigate IPS

IPS signature need select according to infrastructure environment  Eg:-  if  we are not have Linux servers this ips signature can disable (d...