Juniper EX9200 Features Manual page 111

Traffic policers feature guide ex series
Hide thumbs Also See for EX9200:
Table of Contents

Advertisement

Meaning
Purpose
Action
Copyright © 2016, Juniper Networks, Inc.
login:
From Device R1, telnet to Device R2.
3.
user@R1> telnet 192.168.0.2
Trying 192.168.0.2...
telnet: connect to address 192.168.0.2: Operation timed out
telnet: Unable to connect to remote host
On Device R2, deactivate the
4.
[edit firewall family inet filter protect-RE term tcp-connection-term]
user@R2# deactivate from tcp-established
user@R2# commit
From Device R1, try again to telnet to Device R2.
5.
user@R1> telnet 192.168.0.1
Trying 192.168.0.2...
Connected to R2.example.net.
Escape character is '^]'.
R2 (ttyp4)
login:
Verify the following information:
As expected , the BGP session is established. The
is not expected to block BGP session establishment.
From Device R2, you can telnet to Device R1. Device R1 has no firewall filter configured,
so this is the expected behavior.
From Device R1, you cannot telnet to Device R2. Telnet uses TCP as the transport
protocol, so this result might be surprising. The cause for the lack of telnet connectivity
is the
from tcp-established
TCP traffic that is accepted of Device R2. After this match condition is deactivated,
the telnet session is successful.
Using telnet to Verify the Trusted Prefixes Condition in the TCP Firewall Filter
Make sure that telnet traffic works as expected.
Verify that the device can establish only telnet sessions with a host at an IP address that
matches one of the trusted source addresses. For example, log in to the device with the
command from another host with one of the trusted address prefixes. Also, verify
telnet
that telnet sessions with untrusted source addresses are blocked.
From Device R1, telnet to Device R2 from an untrusted source address.
1.
user@R1> telnet 172.16.0.2 source 172.16.0.1
Trying 172.16.0.2...
^C
From Device R2, add 172.16/16 to the list of trusted prefixes.
2.
Chapter 9: Filter-Specific Counters and Policers
match condition.
from tcp-established
from tcp-established
match condition. This match condition limits the type of
match condition
93

Advertisement

Table of Contents
loading

Table of Contents