Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual page 3397

For ex series ethernet switches
Table of Contents

Advertisement

Applying a Firewall Filter to a Management Interface on a Switch
Copyright © 2010, Juniper Networks, Inc.
user@switch# set ge-0/0/1 description "filter to limit tcp traffic filter at trunk port for
employee-vlan and voice-vlan applied on the interface"
NOTE: Providing the description is optional.
Specify the unit number and family address type for the interface:
2.
[edit interfaces]
user@switch# set ge-0/0/1 unit 0 family ethernet-switching
For firewall filters that are applied to ports, the family address type must be
ethernet-switching
.
To apply a firewall filter to filter packets that are entering a port:
3.
[edit interfaces]
user@switch# set ge-0/0/1 unit 0 family ethernet-switching filter input ingress-port-filter
To apply a firewall filter to filter packets that are exiting a port:
[edit interfaces]
user@switch# set ge-0/0/1 unit 0 family ethernet-switching filter output
egress-port-filter
NOTE: You can apply no more than one firewall filter per port, per direction.
You can configure and apply a firewall filter to a management interface to control traffic
that is entering or exiting the interface on a switch. You can use utilities such as SSH or
Telnet to connect to the management interface over the network and then use
management protocols such as SNMP to gather statistical data from the switch. Similar
to configuring a firewall filter on other types of interfaces, you can configure a firewall
filter on a management interface using any match condition, action, and action modifier
specified in "Firewall Filter Match Conditions and Actions for EX Series Switches" on
page 3233 except for the following action modifiers:
loss-priority
forwarding-class
You can apply a firewall filter to the management Ethernet interface on any EX Series
switch. You can also apply a firewall filter to the virtual management Ethernet (VME)
interface on the EX4200 switch. For more information on the management Ethernet
interface and the VME interface, see "EX Series Switches Interfaces Overview" on page 1239.
To apply a firewall filter on the management interface to filter ingress or egress traffic:
Specify the interface name and provide a meaningful description of the firewall filter
1.
and the interface to which the filter is applied:
[edit interfaces]
Chapter 108: Configuring Firewall Filters
3293

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents