Description

When configuring an MX or PTX device as a remote device in Corero SmartWall Threat Defense Director (TDD), one of the configuration steps is to enable telemetry in the Junos config, either native telemetry or gRPC. If telemetry is configured and you have confirmed that telemetry traffic is sent, but the vSWA Dashboard still shows "0" telemetry sources, this article explains what you can check.

Solution

Here are steps you can take to verify the configuration.

 

  1. In the vSWA, check the remote devices config to ensure the Telemetry type matches the type that is configured on the MX or PTX (either native or gRPC).
  2. Be sure traffic is traversing a router interface where the CORERO-MITIGATE filter is applied. show firewall filter CORERO-MITIGATE should have incrementing counters.
  3. In the Junos config, be sure the counters defined in the CORERO-MITIGATE and CORERO-MITIGATE6 filters are defined exactly as "Corero-Allowed" and "Corero-Allowed6", respectively.
  4. For the native telemetry method only: if the CORERO-MITIGATE or -MITIGATE6 filter is applied to interfaces in an input-list, be sure to configure the sensor like:  set services analytics sensor Corero-FF-mitigate resource-filter "^[^_].*" rather than the usual string: Corero.*

Modification History

2025-02-26 : Added check for sensor resource-filter string for input-lists (native only)
2025-02-25 : Including PTX
2025-02-24 : Article Created

Related Information

Corero 11.7.2 - Configuring the Juniper Networks MX Series router