What this configuration is
This is the inline J-Flow configuration of an edge Juniper MX that exports IPFIX to two EdgeWarden servers at the same time. The generic step-by-step guide is How to export IPFIX from a Juniper MX to EdgeWarden. Here the focus is on what each line does and why some values differ from the guide.
The addresses were replaced with documentation addresses: collectors 192.0.2.10 and 192.0.2.11, export source 198.51.100.1. Replace them with your own before pasting.
| Item | Guide | This configuration | Effect |
|---|---|---|---|
| Template active timeout | 60 s | 15 s | Long flows exported every 15 s: earlier detection, more export traffic |
| Template and option refresh | 60 s | 10 s | After a collector restart, data is decoded again within 10 s |
| Sampling | 1:1000 | 1:500 | More accuracy, roughly twice the flows |
| Collectors | 1 | 2 | Both receive a copy of every flow |
| Flow tables (IPv4 and IPv6) | 8 and 4 | 10 and 5 | 2,621,440 IPv4 entries and 1,310,720 IPv6 |
Chassis and FPC
set chassis network-services enhanced-ip
set chassis fpc 0 sampling-instance EDGEWARDEN
set chassis fpc 0 inline-services flow-table-size ipv4-flow-table-size 10
set chassis fpc 0 inline-services flow-table-size ipv6-flow-table-size 5network-services enhanced-ip: the chassis network services mode for Trio MPCs. Ifshow chassis network-servicesalready showsEnhanced-IP, the line just makes the current mode explicit. Changing this mode requires a router reboot.sampling-instance EDGEWARDEN: binds the sampling instance to FPC 0. Without this line the instance stays inactive and nothing is exported. On an MX with several FPCs, repeat it for every FPC that has a sampled interface.flow-table-size: each unit is 256K entries. 10 units give 2,621,440 simultaneous IPv4 flows; 5 give 1,310,720 IPv6. Since Junos 16.1R1 and 15.1F2 the tables start with only 1,024 entries, too few for an attack with spoofed sources, where each source becomes a flow. The per-card maximum is in step 3 of the guide.
Before Junos 16.1R1 and 15.1F2, changing flow-table-size restarts the FPC. On those releases, make the change in a maintenance window.
IPFIX templates
set services flow-monitoring version-ipfix template EDGEWARDEN flow-active-timeout 15
set services flow-monitoring version-ipfix template EDGEWARDEN flow-inactive-timeout 15
set services flow-monitoring version-ipfix template EDGEWARDEN nexthop-learning enable
set services flow-monitoring version-ipfix template EDGEWARDEN template-refresh-rate seconds 10
set services flow-monitoring version-ipfix template EDGEWARDEN option-refresh-rate seconds 10
set services flow-monitoring version-ipfix template EDGEWARDEN ipv4-template
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 flow-active-timeout 15
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 flow-inactive-timeout 15
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 nexthop-learning enable
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 template-refresh-rate seconds 10
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 option-refresh-rate seconds 10
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 ipv6-templateThese are two templates with the same parameters: EDGEWARDEN for IPv4 and EDGEWARDEN-v6 for IPv6.
ipv4-templateandipv6-template: define the set of fields exported for each family (addresses, ports, protocol, interfaces, ASN, next hop, bytes, and packets).flow-active-timeout 15: a flow that stays active, such as an attack, is exported every 15 s. Added to the EdgeWarden analysis cycle (10 s by default), the attack shows up in about 25 s, versus about 70 s with 60 s. The cost: a long flow produces 4 records per minute instead of 1.flow-inactive-timeout 15: a flow with no packets for 15 s is closed and exported, which frees its entry in the flow table.nexthop-learning enable: with ECMP, reports the correct egress interface and next hop. Without it, the MX reports the first path for IPv4 and zeroes the egress interface and next hop for IPv6. Requires Junos 15.1F2 or later.template-refresh-rate seconds 10: resends the template every 10 s. The collector can only decode data after it receives the template; after one of the EdgeWarden servers restarts, the wait is at most 10 s, versus 600 s with the Junos default.option-refresh-rate seconds 10: resends the Options Template, which carries the sampling rate. That is how the EdgeWarden Amostragem (sampling) column shows detectado (detected).
Sampling instance
The instance defines how much to sample, where to export, and from which source address. First, the rate:
set forwarding-options sampling instance EDGEWARDEN input rate 500
set forwarding-options sampling instance EDGEWARDEN input run-length 0input rate 500: samples 1 in every 500 packets entering interfaces that havesampling input. This 500 goes into the device record in EdgeWarden.input run-length 0: after each selected packet, no extra consecutive packets are sampled. This is the default, stated explicitly. With arun-lengthabove 0, each selection would take several packets in a row and the actual ratio would no longer be 1:500.
IPv4 family
set forwarding-options sampling instance EDGEWARDEN family inet output flow-inactive-timeout 15
set forwarding-options sampling instance EDGEWARDEN family inet output flow-active-timeout 60
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.10 port 2055
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.10 autonomous-system-type origin
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.10 no-local-dump
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.10 version-ipfix template EDGEWARDEN
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.11 port 2055
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.11 autonomous-system-type origin
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.11 no-local-dump
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.11 version-ipfix template EDGEWARDEN
set forwarding-options sampling instance EDGEWARDEN family inet output inline-jflow source-address 198.51.100.1
set forwarding-options sampling instance EDGEWARDEN family inet output inline-jflow flow-export-rate 10output flow-active-timeout 60andflow-inactive-timeout 15: with inline J-Flow, export follows the template timeouts (15 s and 15 s). To leave no doubt about which value applies, remove these two lines or set them to the same values as the template.flow-server ... port 2055: one collector per group of lines. With twoflow-serverentries, the MX sends a copy of each flow to each server; this is not load balancing. If one server goes down, the other keeps receiving everything.autonomous-system-type origin: fills the ASN fields with the AS that originated the prefix (the last one in the AS path), not the neighbor AS (peer). This is what lets EdgeWarden show which network the traffic comes from. It depends on the MX having the BGP routes for those prefixes.no-local-dump: does not write a copy of the flows to a log file on the router. That copy is only useful for debugging and uses Routing Engine disk and CPU.version-ipfix template EDGEWARDEN: exports in IPFIX with the IPv4 template.inline-jflow source-address 198.51.100.1: the source IP of the export packets. This is the IP you register in EdgeWarden, and it counts as one exporter on the license. Use the loopback, with a route to the collectors over the data network: the MX does not export inline flows throughfxp0.inline-jflow flow-export-rate 10: up to 10 thousand export packets per second, a value that applies to the whole FPC. The default is 1, too low for an edge under attack. Here it is set only in theinetfamily; step 2 of the guide repeats it underinet6, and you can do the same.
IPv6 family
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-inactive-timeout 15
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-active-timeout 60
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.10 port 2055
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.10 autonomous-system-type origin
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.10 no-local-dump
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.10 version-ipfix template EDGEWARDEN-v6
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.11 port 2055
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.11 autonomous-system-type origin
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.11 no-local-dump
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.11 version-ipfix template EDGEWARDEN-v6
set forwarding-options sampling instance EDGEWARDEN family inet6 output inline-jflow source-address 198.51.100.1It mirrors the IPv4 family, with two differences that matter:
- The template is
EDGEWARDEN-v6. - Collectors and
source-addressstay IPv4: IPv6 flows travel inside IPv4 packets. With the samesource-addressin both families, the MX takes one license slot and a single device record in EdgeWarden.
Edge interface
set interfaces et-0/0/1 unit 467 description Peer1
set interfaces et-0/0/1 unit 467 vlan-id 467
set interfaces et-0/0/1 unit 467 family inet sampling input
set interfaces et-0/0/1 unit 467 family inet address 203.0.113.17/31
set interfaces et-0/0/1 unit 467 family inet6 sampling input
set interfaces et-0/0/1 unit 467 family inet6 address 2001:db8:467::1/127family inet sampling inputandfamily inet6 sampling input: sample what comes in from the peer, which is where attacks arrive. Without theinet6line, IPv6 traffic goes unseen. Repeat on the other transit and IXP interfaces and, if you want to see attacks leaving customers, on the ingress of their interfaces.- The ifIndex sent in the flow is the one of the logical unit
et-0/0/1.467, not the physical port. EdgeWarden looks up the name of that ifIndex over SNMP and showsPeer1on the Interfaces screen. To check the number:show interfaces et-0/0/1.467 | match "SNMP ifIndex".
Two lines that are not part of the export
These lines often show up next to the flow configuration. Neither of them changes the export to EdgeWarden:
set services inline-monitoring template EDGEWARDEN template-refresh-rate 10: inline monitoring is a different Junos feature, which exports packet snippets in IPFIX instead of flows and has its own instances. The inline J-Flow template is the one underservices flow-monitoring; this line does not change it and can be removed.set chassis alarm management-ethernet link-down ignore: only silences the alarm for a disconnected management port.
Device record in EdgeWarden
Repeat on each of the two servers:
- Under Configurações → Rede → Dispositivos (Settings → Network → Devices), add the MX with Endereço IP (IP address)
198.51.100.1, Taxa de Amostragem de Flow (flow sampling rate)500, and the SNMP settings. - With
option-refresh-rateat 10 s, the Amostragem column shows detectado with 1:500 a few seconds after flows start arriving. - Follow the guide's verification on the router and in EdgeWarden to validate the export and the rate.
Anyone who can reach 2055/UDP can inject forged flows and poison detection. On both servers, restrict the port to your routers' IPs.
Full configuration
To paste in one go, without the two lines that are not part of the export. Replace the addresses, interface, and FPC with your own, paste in configuration mode, and run commit check and commit confirmed 10 before commit.
set chassis network-services enhanced-ip
set chassis fpc 0 sampling-instance EDGEWARDEN
set chassis fpc 0 inline-services flow-table-size ipv4-flow-table-size 10
set chassis fpc 0 inline-services flow-table-size ipv6-flow-table-size 5
set services flow-monitoring version-ipfix template EDGEWARDEN flow-active-timeout 15
set services flow-monitoring version-ipfix template EDGEWARDEN flow-inactive-timeout 15
set services flow-monitoring version-ipfix template EDGEWARDEN nexthop-learning enable
set services flow-monitoring version-ipfix template EDGEWARDEN template-refresh-rate seconds 10
set services flow-monitoring version-ipfix template EDGEWARDEN option-refresh-rate seconds 10
set services flow-monitoring version-ipfix template EDGEWARDEN ipv4-template
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 flow-active-timeout 15
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 flow-inactive-timeout 15
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 nexthop-learning enable
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 template-refresh-rate seconds 10
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 option-refresh-rate seconds 10
set services flow-monitoring version-ipfix template EDGEWARDEN-v6 ipv6-template
set forwarding-options sampling instance EDGEWARDEN input rate 500
set forwarding-options sampling instance EDGEWARDEN input run-length 0
set forwarding-options sampling instance EDGEWARDEN family inet output flow-inactive-timeout 15
set forwarding-options sampling instance EDGEWARDEN family inet output flow-active-timeout 60
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.10 port 2055
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.10 autonomous-system-type origin
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.10 no-local-dump
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.10 version-ipfix template EDGEWARDEN
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.11 port 2055
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.11 autonomous-system-type origin
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.11 no-local-dump
set forwarding-options sampling instance EDGEWARDEN family inet output flow-server 192.0.2.11 version-ipfix template EDGEWARDEN
set forwarding-options sampling instance EDGEWARDEN family inet output inline-jflow source-address 198.51.100.1
set forwarding-options sampling instance EDGEWARDEN family inet output inline-jflow flow-export-rate 10
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-inactive-timeout 15
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-active-timeout 60
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.10 port 2055
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.10 autonomous-system-type origin
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.10 no-local-dump
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.10 version-ipfix template EDGEWARDEN-v6
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.11 port 2055
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.11 autonomous-system-type origin
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.11 no-local-dump
set forwarding-options sampling instance EDGEWARDEN family inet6 output flow-server 192.0.2.11 version-ipfix template EDGEWARDEN-v6
set forwarding-options sampling instance EDGEWARDEN family inet6 output inline-jflow source-address 198.51.100.1
set interfaces et-0/0/1 unit 467 description Peer1
set interfaces et-0/0/1 unit 467 vlan-id 467
set interfaces et-0/0/1 unit 467 family inet sampling input
set interfaces et-0/0/1 unit 467 family inet address 203.0.113.17/31
set interfaces et-0/0/1 unit 467 family inet6 sampling input
set interfaces et-0/0/1 unit 467 family inet6 address 2001:db8:467::1/127Next steps
To choose other rate and timeout values, see NetFlow and IPFIX sampling and timeouts without missing attacks. If flows don't show up, work through the checklist No flows showing up in EdgeWarden?. The full step-by-step guide, with SNMP and the MX pitfalls, is How to export IPFIX from a Juniper MX to EdgeWarden.