Complete Software Guide for Junos
Related
Documentation
3088
®
OS for EX Series Ethernet Switches, Release 10.3
Configure a smaller filter with fewer terms that does not exceed the amount of
3.
available TCAM space on the switch—for example:
[edit]
user@switch# set firewall family ethernet-switching filter new—filter-ingress-vlan
...
Apply (bind) the new firewall filter to a port, VLAN , or Layer 3 interface—for example:
4.
[edit]
user@switch# set vlans voice-vlan description "filter to block rogue devices on
voice-vlan"
user@switch# set vlans voice-vlan filter input new-filter—ingress-vlan
Commit the operation:
5.
[edit]
user@switch# commit
To apply a new firewall filter and overwrite the existing bind points:
Configure a firewall filter with fewer terms than the original filter:
1.
[edit]
user@switch# set firewall family ethernet-switching filter new-filter-ingress-vlan...
Apply the firewall filter to the port, VLAN, or Layer 3 interfaces to overwrite the bind
2.
points of the original filter—for example:
[edit]
user@switch# set vlans voice-vlan description "smaller filter to block rogue devices
on voice-vlan"
user@switch# set vlans voice-vlan filter input new-filter-ingress-vlan
Commit the operation:
3.
[edit]
user@switch# commit
Only the original bind points, and not the original firewall filter itself, are deleted.
Example: Configuring Firewall Filters for Port, VLAN, and Router Traffic on EX Series
Switches on page 3039
Verifying That Firewall Filters Are Operational on page 3083
Configuring Firewall Filters (CLI Procedure) on page 3063
Configuring Firewall Filters (J-Web Procedure) on page 3069
Copyright © 2010, Juniper Networks, Inc.