Page MenuHomePhabricator

Junos: use mgmt_junos for syslog and ntp
Closed, ResolvedPublic

Description

Similar to T317175

See https://apps.juniper.net/feature-explorer/feature-info.html?fKey=8739&fn=System%20logging%20over%20management%20VRF%20(mgmt_junos)

MX routers now support sending syslog through mgmt_junos which seems more appropriate than the production interface.

Similarly for NTP, see https://www.juniper.net/documentation/us/en/software/junos/junos-getting-started/topics/topic-map/management-interface-in-non-default-instance.html

NTP would allow us to remove the loopback rules allow_ntp_src4/6 and allow_ntp_dst4/6

The mgmt firewalls ACLs might need to be updated accordingly.

Details

Event Timeline

ayounsi triaged this task as Low priority.
Restricted Application added a subscriber: Aklapper. · View Herald Transcript
ayounsi renamed this task from Junos: send syslog through mgmt_junos to Junos: use mgmt_junos for syslog and ntp.Oct 7 2022, 12:53 PM
ayounsi updated the task description. (Show Details)

Change 920311 had a related patch set uploaded (by Ayounsi; author: Ayounsi):

[operations/homer/public@master] Configure mgmt_junos on L2 switches

https://gerrit.wikimedia.org/r/920311

Change 920311 merged by jenkins-bot:

[operations/homer/public@master] Configure mgmt_junos on L2 switches

https://gerrit.wikimedia.org/r/920311

ayounsi claimed this task.

All done where possible.