Juniper EX9200 Features Manual page 119

Traffic policers feature guide ex series
Hide thumbs Also See for EX9200:
Table of Contents

Advertisement

Overview
Configuration
Copyright © 2016, Juniper Networks, Inc.
In this example, you configure prefix-specific counting and policing based on the last
octet of the source address field in packets matched by an IPv4 firewall filter.
The single-rate two-color policer named
of 1,000,000 bps and a burst-size limit of 63,000 bytes, discarding any packets in a
traffic flow that exceeds the traffic limits.
Independent of the IPv4 addresses contained in any packets passed from a firewall filter,
the prefix-specific action named
256 counters and policers, numbered from 0 through 255. For each packet, the last octet
of the source address field is used to index into the associated prefix-specific counter
and policer in the set:
Packets with a source address ending with the octet 0x0000 00000 index the first
counter and policer in the set.
Packets with a source address ending with the octet 0x0000 0001 index the second
counter and policer in the set.
Packets with a source address ending with the octet 0x1111 1111 index the last counter
and policer in the set.
The
firewall filter contains a single term that matches all packets
limit-source-one-24
from the
/24
subnet of source address
prefix-specific action
psa-1Mbps-per-source-24-32-256
Topology
In this example, because the filter term matches the
each counting and policing instance in the prefix-specific set is used for only one source
address.
Packets with a source address
Packets with a source address
set.
Packets with a source address
set.
This example shows the simplest case of prefix-specific actions, in which the filter term
matches on one address with a prefix length that is the same as the prefix length specified
in the prefix-specific action for indexing into the set of prefix-specific counters and policers.
For descriptions of other configurations for prefix-specific counting and policing, see
"Prefix-Specific Counting and Policing Configuration Scenarios" on page
The following example requires you to navigate various levels in the configuration
hierarchy. For information about navigating the CLI, see Using the CLI Editor in Configuration
Mode.
Chapter 10: Prefix-Specific Counting and Policing Actions
rate-limits traffic to a bandwidth
1Mbps-policer
psa-1Mbps-per-source-24-32-256
10.10.10.0
, passing these packets to the
.
subnet of a single source address,
/24
index the first counter and policer in the set.
10.10.10.0
10.10.10.1
index the second counter and policer in the
index the last counter and policer in the
10.10.10.255
specifies a set of
107.
101

Advertisement

Table of Contents
loading

Table of Contents