Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

Configuring FlowTap and FlowTapLite Security Properties

date_range 18-Dec-24

Enable DTCP on top of the SSH layer and set permissions needed to configure and view FlowTap and FlowTapLite features.

You can add an extra level of security to DTCP transactions between the mediation device and the router by enabling DTCP sessions on top of the SSH layer. To configure, include the flow-tap-dtcp statement at the [edit system services] hierarchy level:

content_copy zoom_out_map
flow-tap-dtcp {
    ssh {
        connection-limit value;
        rate-limit value;
    }
}

To configure client permissions for viewing and modifying flow-tap configurations and for receiving tapped traffic, include the permissions statement at the [edit system login class class-name] hierarchy level:

content_copy zoom_out_map
permissions [ permissions ];

The permissions needed to use FlowTap and FlowTapLite features are as follows:

  • flow-tap—Can view FlowTap and FlowTapLite configuration.

  • flow-tap-control—Can modify FlowTap and FlowTapLite configuration.

  • flow-tap-operation—Can tap flows.

You can also specify user permissions on a RADIUS server, for example:

content_copy zoom_out_map
Bob Auth-Type := Local, User-Password = = “abc123” 
Juniper-User-Permissions = “flow-tap-operation” 
footer-navigation