Download Q S G UICK

Survey
yes no Was this document useful for you?
   Thank you for your participation!

* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project

Document related concepts

Computer network wikipedia , lookup

Piggybacking (Internet access) wikipedia , lookup

Wake-on-LAN wikipedia , lookup

Network tap wikipedia , lookup

List of wireless community networks by region wikipedia , lookup

Airborne Networking wikipedia , lookup

Distributed firewall wikipedia , lookup

Cracking of wireless networks wikipedia , lookup

Zero-configuration networking wikipedia , lookup

Transcript
• Your Juniper Networks FW/VPN devices must support NSRP (see above), and
you must configure NSRP for your Juniper Networks FW/VPN devices as
active/passive.
• You must assign the management interface an IP address:
– If you are using a forwarding interface as a management interface, you
must use a stealth interface for the forwarding interface that does not
connect to the IDP Management Server.
– If you are not using a forwarding interface as a management interface
(the management interface is a dedicated interface), you can use a
stealth interface for all forwarding interfaces on the IDP appliance.
Multicast or Unicast Forwarding [Standalone HA only]
The Standalone HA solution can use two different forwarding options to send and
receive traffic: unicast or multicast. You choose one of these forwarding options
based on your existing network hardware and configuration.
To use a standalone HA solution, review your existing network hardware and use
the table below to determine the best forwarding method to use. You are prompted
to specify the forwarding method for the standalone HA solution during the Sensor
configuration process described in “Configure the IDP Sensor” on page 18.
IF YOUR
NETWORK
SWITCH
SUPPORTS...
IN ROUTER MODE
IN PROXY-ARP MODE
Layer 3 devices (routers, servers) Layer-3 devices (routers, servers)
...can learn
...cannot learn
multicast ARP
multicast ARP
Unicast traffic to YES
YES (Best)
multiple ports
aNot
Multicast traffic YES
to multiple ports
Recommended
...can learn
...cannot learn
multicast ARP
multicast ARP
YES
YES (Best)
YES
aNot
Recommended
a.To use a network switch that supports only multicast (and not unicast) with network devices that
cannot pass multicast ARPs, you must manually configure static ARP entries for devices that cannot
pass multicast ARPs.
You can use the mcasttest utility (available from the Juniper Networks customer
Support Web site) to automatically determine which devices on your network do not
support multicast ARP traffic. From the Sensor command line, type mcasttest -h
for a list of options, or see the mcasttest man page for more details.
When you have chosen a deployment mode, HA solution, and forwarding method (if
necessary) proceed to “Install the IDP Management Server” on page 14.
8 | Juniper Networks, Inc.