Configuring A Firewall Filter - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Complete Software Guide for Junos
Example: Configuring a Firewall Filter on a Management Interface on an EX Series
Switch
Requirements
Overview and Topology
3284
®
OS for EX Series Ethernet Switches, Release 10.4
You can configure a firewall filter on a management interface on an EX Series switch to
filter ingress or egress traffic on the management interface on the switch. You can use
utilities such as SSH or Telnet to connect to the management interface over the network
and then use management protocols such as SNMP to gather statistical data from the
switch.
This example discusses how to configure a firewall filter on a management interface to
filter SSH packets egressing from an EX Series switch:
Requirements on page 3284
Overview and Topology on page 3284
Configuration on page 3285
Verification on page 3286
This example uses the following hardware and software components:
One EX Series switch and one management PC
Junos OS Release 10.4 or later for EX Series switches
In this example, a management PC establishes an SSH connection with the management
interface on a switch to remotely manage the switch. The IP address configured for the
management interface is 10.204.33.103/20. A firewall filter is configured on the
management interface to count the number of packets egressing from a source SSH
port on the management interface. When the management PC establishes the SSH
session with the management interface, the management interface returns SSH packets
to the management PC to confirm that the session is established. These SSH packets
are filtered based on the match condition specified in the firewall filter before they are
forwarded to the management PC. As these packets are generated from the source SSH
port on the management interface, they fulfill the match condition specified for the
management interface. The number of matched SSH packets provides a count of the
number of packets that have traversed the management interface. A system administrator
can use this information to monitor the management traffic and take any action if required.
Figure 87 on page 3285 shows the topology for this example in which a management PC
establishes an SSH connection with the switch.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents