Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual page 57

For ex series ethernet switches
Table of Contents

Advertisement

Chapter 107
Chapter 108
Chapter 109
Copyright © 2010, Juniper Networks, Inc.
Understanding How Firewall Filters Control Packet Flows . . . . . . . . . . . . . . . . . 3232
Understanding How Firewall Filters Are Evaluated . . . . . . . . . . . . . . . . . . . . . . . 3253
Understanding Firewall Filter Match Conditions . . . . . . . . . . . . . . . . . . . . . . . . . 3255
Filter Match Conditions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3255
Numeric Filter Match Conditions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3255
Interface Filter Match Conditions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3256
IP Address Filter Match Conditions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3256
MAC Address Filter Match Conditions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3257
Bit-Field Filter Match Conditions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3257
Understanding the Use of Policers in Firewall Filters . . . . . . . . . . . . . . . . . . . . . 3259
Examples of Firewall Filters Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . 3261
Example: Configuring Firewall Filters for Port, VLAN, and Router Traffic on EX
Series Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3261
Device on EX Series Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3280
Example: Configuring a Firewall Filter on a Management Interface on an EX
Series Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3284
Configuring Firewall Filters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3289
Configuring Firewall Filters (CLI Procedure) . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3289
Configuring a Firewall Filter . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3289
Applying a Firewall Filter to a Port on a Switch . . . . . . . . . . . . . . . . . . . . . . 3292
Applying a Firewall Filter to a VLAN on a Network . . . . . . . . . . . . . . . . . . . 3294
Configuring Firewall Filters (J-Web Procedure) . . . . . . . . . . . . . . . . . . . . . . . . . 3296
Configuring Policers to Control Traffic Rates (CLI Procedure) . . . . . . . . . . . . . 3300
Configuring Policers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3301
Specifying Policers in a Firewall Filter Configuration . . . . . . . . . . . . . . . . . . 3302
Assigning Multifield Classifiers in Firewall Filters to Specify Packet-Forwarding
Behavior (CLI Procedure) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3303
Configuring Routing Policies (J-Web Procedure) . . . . . . . . . . . . . . . . . . . . . . . . 3304
Verifying Firewall Filter Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3311
Verifying That Firewall Filters Are Operational . . . . . . . . . . . . . . . . . . . . . . . . . . . 3311
Verifying That Policers Are Operational . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3312
Monitoring Firewall Filter Traffic . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3312
Monitoring Traffic for All Firewall Filters and Policers That Are Configured
on the Switch . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3313
Monitoring Traffic for a Specific Firewall Filter . . . . . . . . . . . . . . . . . . . . . . . 3313
Monitoring Traffic for a Specific Policer . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3313
Table of Contents
lvii

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents