Applying A Firewall Filter To A Management Interface On A Switch - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Complete Software Guide for Junos
Applying a Firewall Filter to a Port on a Switch
3292
®
OS for EX Series Ethernet Switches, Release 10.4
You can specify any of the following action modifiers in a
analyzer analyzer-name
that is connected to a protocol analyzer application. An
configured under the
Port Mirroring to Analyze Traffic (CLI Procedure)" on page 3849.
count counter-name
NOTE: We recommend that you configure a counter for each term in
a firewall filter, so that you can monitor the number of packets that
match the conditions specified in each filter term.
forwarding-class class
loss-priority priority
policer policer-name
If you omit the
statement or do not specify an action, packets that match all the
then
conditions in the
statement are accepted. However, you must always explicitly
from
configure an action and/or action modifier in the
more than one action statement, but you can use any combination of action modifiers.
For an action or action modifier to take effect, all conditions in the
must match.
NOTE: Implicit discard is also applicable to a firewall filter applied to the
loopback interface,
You can apply a firewall filter to a port on a switch to filter ingress or egress traffic on the
switch. When you configure the firewall filter, you can specify any match condition, action,
and action modifiers specified in "Firewall Filter Match Conditions and Actions for EX
Series Switches" on page 3233. The action specified in the match condition indicates the
action for the matched packets in the ingress or egress traffic.
To apply a firewall filter to a port to filter ingress or egress traffic:
NOTE: For applying a firewall filter to a management interface, see "Applying
a Firewall Filter to a Management Interface on a Switch" on page 3293
Specify the interface name and provide a meaningful description of the firewall filter
1.
and the interface to which the filter is applied:
[edit interfaces]
—Mirror port traffic to a specified destination port or VLAN
family address type. See "Configuring
ethernet-switching
—Count the number of packets that pass this filter term.
—Classify packets in a forwarding class.
—Set the priority of dropping a packet.
—Apply rate-limiting to the traffic.
then
.
lo0
statement:
then
analyzer
must be
statement. You can include no
statement
from
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents