Saturday, August 2, 2008

Juniper Networks WXC Project

Hey all,

sorry that i didn't post a lot the last month, but i was traveling for work and had some holiday.

Some post ago i talked about a project with WXC, now i want to show you some figures about the preformance of these devices in real network.

This is from a office to hq in the same country (so no latency problems).









This image clearly show that they don't use object caching, but Molecular Sequence Reduction™ (MSR™) compression and Network Sequence Caching technologies. the first one is in memory, the second on harddisks (MSR can be done by WX, but only NSC can be done by WXC)

why do i say you clearly see it doesn't use object caching? Because when you see the image you see that at 10/07/08 someone is asking a file with a size of +/- 4.5 gig and is compressed by almost 95% (so out of cache), this can also be done by object caching, BUT then someone needs to ask the same file before (which will need to pass the line 1 time compleetly). This is not the case here (you see clearly see in the image that never before there has been a request for a file larger then 500MB.).

Some other figures:

Compression Summary

Peak Data Compression 98,00%
Total Data Compression 86,10%
Total Bytes Into Compression 17,7 GB
Total Bytes Compressed 15,3 GB
Total Bytes Out of Compression 2,5 GB
Effective WAN Capacity 7,20 X


Wow, isn't this nice ! this means that from the 17,7 GB that is asked to pass the line only 2,5 GB Really crossed the line. and i can even say that from that 2,5 GB only 1.4 GB needed to pass the line, because 1.1 GB was bypassed because of license issues! (see below)

Passthrough Data
Category Bytes Packets
No Remote WX 79.253.312
By Filter Rule 675.185.052
Overflow 68.746.046
No Local Reducer 8.299
Non-IP 210.496
License Violation 1.135.001.661

But hey which traffic includes this figures?



Now you have a idea about which traffic it is. OK, i need to be clear about one thing, this is the best figure i have of all my sites :). BUT, still it is real traffic.

Friday, June 6, 2008

Juniper Master of Systems Engineering

Hey All,

I am pretty proud to tell you all I have been rewarded with the Title: Master of System Engineering of Juniper Networks

This reward is given to people that do innovating projects with juniper products.


From left to right: Nico Siebelink, Juniper Systems Engineering Manager & Wim De Smet, SecureLink Consultant

Wednesday, April 23, 2008

Proxy arp

Hi all,

Proxy arp is something that not all people understand well. Some devices are able to do it, other not, and other do it automatic (sometimes), etc....

Here i will give a brief overview of how juniper firewalls handle proxy arp:

As most of you know there are 5 solutions to do NATTING in juniper firewalls:

MIP: one to one (bi-directional)
DIP: many to one (uni-directional)
VIP: one to many (uni-directional)
Destination NAT (policy): one to one, one to many (uni-directional)
Source NAT (policy): many to one, one to one (uni-directional)

So this is a overview of the natting, know when will the firewall to proxy arp for these NAT addresses?

Yes:

-MIP
-VIP

No:

-Dest nat

So you see that when using Destination nat you will have problem. Solution to solve this problem, ... place a static arp entry on higher level router, or when not in same network has the interface ... place a route to cluster ip of the juniper firewall.

Sometimes this isn't a solution, because the upstream router isn't managed by yourself. This means you need to be able to do proxy arp on firewall for these NAT addresses.

Well there is a hidden command "set arp nat-dst", which will do proxy arp for NAT addresses in a certain situation!!

When will he do it or not:

• The Destination NAT policy must be configured using the same source and
destination Layer 3 security zone. However, traffic that matches the policy
can then be sent to any Layer 3 security zone.

• The device does not respond to an ARP request if the Destination NAT IP is
in the same incoming subnet as a secondary IP address.
• In an HA environment, the device only supports the Destination NAT ARP
capability if using NSRP Active/Passive on interfaces that reside in VSD ID
0.
• In ScreenOS 5.0r7 and below, the device does not respond to an ARP request
for a Destination NAT IP that is in the same subnet as the incoming
interface for a Destination NAT policy.

Hope this helps you all.

Wednesday, April 16, 2008

NSM Error ( Failed during updating License info)

Hi,

While playing a bit with NSM (Netscreen Security Manager), i found a nice bug!

you can't use some chars in the name of the firewall members:

for example: _ and [ or ], possible there are more!

the error you will see when trying to do a update is:

Error Code:

Error Text:
Exception caught during Update Device:

Failed during updating License info

Error Details:
Failed to process the database query. No record matched the query and nothing has been done.

Hope this help some of you!

Saturday, March 1, 2008

Comparing WAN Accelleration Products (Juniper WXC vs Riverbed vs Bluecoat)

Hey All,

For some weeks now i am busy with a project that includes Juniper Firewalls (with VPN's), Bluecoat (WAN ACC), Juniper WXC (WAN ACC), Juniper NSM (Management station), Juniper CMS (WAN Management station).

The Firewall/VPN part was difficult, because at HQ they had 2 ISP, but also at the remote side they had 2 ISP. The customer asked full redundancy (so we needed to create 4 VPN tunnel from remote to HQ). This i did before so wasn't to hard! (just play around with Vrouters and everything is up and running).

The real hard part was which WAN Accellerator will they take! So the customer start testing together with me.

Products we tested:

Bluecoat
Juniper WXC
Riverbed

We provider the tests for Bluecoat and Juniper, After these test we saw that on a satelite link bluecoat wasn't doing well (especially when using http!)

Personal i had the feeling that bluecoats proxy kicked in here and didn't do alot of WAN Accell. We also called bluecoat and they came over to do some tweaking, and saw that the customer his webpages wheren't cacheable (and this is the reason it didn't work that well)

After the bluecoat test, they tested Riverbed (which wasn't that bad, and better then Bluecoat).
The last test we came again with Juniper WXC and it seems that this was the fastes solution.

So because of the outstanding Juniper FW/VPN concept (vrouter and routing based vpn's) and the good performance of Juniper WXC, the customer choosed us to build there international Network.

Monday, February 18, 2008

JNCIS-FWV (Juniper Firewall/VPN products and ScreenOS software)

Hi All,

I did my JNCIS-FWV exam today (this shouldn't be to hard, because i work for more then 8 years with these Firewall.)

Passed the exame with 92%.

We needed this exam for the Partner level again. Hope i can get some time now to prepare for the JNCIE-ER (and maybe will do some other exams in between (what do you think about the M/T track :))

Monday, January 14, 2008

Juniper Partner Level Exams

hey all,

So it has been a long time you heared from me... Been busy with some big projects. I also needed to do all those partner exams again for our Partner Level.

Here the list of exams i did: (there pretty easy if you have worked with those products)

JNSS (Pre-Sales) and JNSA (Sales)

Juniper Networks Enterprise Routing Sales Associate – JNSA-R
Juniper Networks Enterprise Routing Sales Specialist – JNSS-R
Juniper Networks Advanced Security Sales Associate 2007 - JNSA-S
Juniper Networks Advanced Security Sales Specialist 2007 - JNSS-S
Juniper Networks Data Center Acceleration Sales Specialist – JNSS-DX
Juniper Networks Access Control Sales Specialist 2007 - JNSS-AC
Juniper Networks Access Control Sales Associate 2007 - JNSA-AC