SRX

last person joined: yesterday 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
  • 1.  Exporting policy configuration from a device to an XML-compliant spreadsheet

    Posted 03-17-2014 05:34

    Hi All,

     

    I am trying to export the policy configuration from Juniper SRX 650 to the excel sheet but I want clarification about the output in Excel Sheet.

     

    I have taken the output of following command

     

    "show configuration | display xml| no-more"

     

     

    In the output on the top header, I can see following.

    to-zone-name inactive2 name source-address destination-address application ipsec-vpn pair-policy deny session-init session-close reject

     

    I have observed that the action permit, deny, reject is not updated in each policy in the excel sheet. Same is the case with Log output in the policies.

     

    Also, I am getting 2 entries for each polices in the excel sheel.

     

     I am running junos version 11.4R6.6

     

    Hostname: srx650-n0
    Model: srx650
    JUNOS Software Release [11.4R6.6]

     

    Is this a correct way of taking output in xml format?

     

    Regards

    Sanjay Sehgal

     



  • 2.  RE: Exporting policy configuration from a device to an XML-compliant spreadsheet

     
    Posted 03-17-2014 19:37

    For exporting policies in XML format, you could refer below KB:

     

    http://kb.juniper.net/InfoCenter/index?page=content&id=KB28419

     

    Command used by you seems to be correct, troubleshooting should be done to understand why you get two entries for each of the policies.

     

    Would it be possible for you to attach RSI(request support information)?

     

    Regards,

    Raveen



  • 3.  RE: Exporting policy configuration from a device to an XML-compliant spreadsheet
    Best Answer

    Posted 03-20-2014 05:13

    I don't think posting the output of an RSI on a production device to the public internet is a good idea.  There is a lot of detail information in there that would not be good to have out in the world.  And the volume of informaiton is such that it would be difficult to sanitize it before posting.

     

    The RSI should be shared via private channels in my opinion.