I am having trouble configuring J-Flow sensors for my Juniper SRX-210 firewall. When I define a J-Flow sensor I can specify an "interface" which according to the terse documentation must be expressed simply as "a number". What number?
I did an auto-discovery on the device, and while RMON sensors were auto-configured (and numbered 1-28), there are also an RMON Port Numbers which was picked up (509 to 536 in my case). These are RMON sensors but the port numbers agree with the SNMP Interface number. The interfaces that were picked up all correspond to physical interfaces, not logical interfaces. The SRX series allows the configuration of "logical interfaces" numbered st0.0, st0.1 etc. that are then used in routing rules for VPN tunnels. They also have SNMP interface numbers assigned. One physical interface can have multiple logical st0.x logical interfaces defined. I know the SNMP interface numbers for all interfaces - logical and physical.
So which numbers do I use for a J-Flow sensor to specify the interface? A sequential # beginning with 1 corresponding to the # assigned to the auto-discovered RMON sendor, an SNMP interface number, or something else? Also can I track the SRX VPN tunnel logical interfaces at all?
Add comment