Example: Configuring a Stateless Firewall Filter to Protect Against TCP and ICMP
Floods
This example shows how to create a stateless firewall filter that protects against TCP
and ICMP denial-of-service attacks.
•
•
•
•
Requirements
No special configuration beyond device initialization is required before configuring stateless
firewall filters.
Overview
In this example we create a stateless firewall filter called
protect-RE
to police TCP and
ICMP packets. It uses the policers described here:
•
tcp-connection-policer
—This policer limits TCP traffic to 1,000,000 bits per second
(bps) with a maximum burst size of 15,000 bytes. Traffic exceeding either limit is
discarded.
•
icmp-policer
—This policer limits ICMP traffic to 1,000,000 bps with a maximum burst
size of 15,000 bytes. Traffic exceeding either limit is discarded.
When specifying limits, the bandwidth limit can be from 32,000 bps to 32,000,000,000
bps and the burst-size limit can be from 1,500 bytes through 100,000,000 bytes. Use
the following abbreviations when specifying limits: k (1,000), m (1,000,000), and g
(1,000,000,000).
Each policer is incorporated into the action of a filter term. This example includes the
following terms:
•
tcp-connection-term
—Polices certain TCP packets with a source address of
192.168.0.0/24 or 10.0.0.0/24. These addresses are defined in the
trusted-addresses
prefix list.
Filtered packets include
tcp-established
packets The
tcp-established
match condition
is an alias for the bit-field match condition
tcp-flags “(ack | rst)”
, which indicates an
established TCP session, but not the first packet of a TCP connection.
•
icmp-term
—Polices ICMP packets. All ICMP packets are counted in the
icmp-counter
counter.
NOTE:
You can move terms within the firewall filter by using the
insert
command. See insert in the CLI User Guide.
Copyright © 2016, Juniper Networks, Inc.
86
Traffic Policers Feature Guide for EX9200 Switches
Summary of Contents for EX9200 Series
Page 8: ...Copyright 2016 Juniper Networks Inc viii Traffic Policers Feature Guide for EX9200 Switches ...
Page 10: ...Copyright 2016 Juniper Networks Inc x Traffic Policers Feature Guide for EX9200 Switches ...
Page 12: ...Copyright 2016 Juniper Networks Inc xii Traffic Policers Feature Guide for EX9200 Switches ...
Page 20: ...Copyright 2016 Juniper Networks Inc 2 Traffic Policers Feature Guide for EX9200 Switches ...
Page 32: ...Copyright 2016 Juniper Networks Inc 14 Traffic Policers Feature Guide for EX9200 Switches ...
Page 34: ...Copyright 2016 Juniper Networks Inc 16 Traffic Policers Feature Guide for EX9200 Switches ...
Page 42: ...Copyright 2016 Juniper Networks Inc 24 Traffic Policers Feature Guide for EX9200 Switches ...
Page 54: ...Copyright 2016 Juniper Networks Inc 36 Traffic Policers Feature Guide for EX9200 Switches ...
Page 56: ...Copyright 2016 Juniper Networks Inc 38 Traffic Policers Feature Guide for EX9200 Switches ...
Page 72: ...Copyright 2016 Juniper Networks Inc 54 Traffic Policers Feature Guide for EX9200 Switches ...
Page 132: ...Copyright 2016 Juniper Networks Inc 114 Traffic Policers Feature Guide for EX9200 Switches ...
Page 152: ...Copyright 2016 Juniper Networks Inc 134 Traffic Policers Feature Guide for EX9200 Switches ...
Page 162: ...Copyright 2016 Juniper Networks Inc 144 Traffic Policers Feature Guide for EX9200 Switches ...
Page 178: ...Copyright 2016 Juniper Networks Inc 160 Traffic Policers Feature Guide for EX9200 Switches ...
Page 186: ...Copyright 2016 Juniper Networks Inc 168 Traffic Policers Feature Guide for EX9200 Switches ...
Page 188: ...Copyright 2016 Juniper Networks Inc 170 Traffic Policers Feature Guide for EX9200 Switches ...
Page 202: ...Copyright 2016 Juniper Networks Inc 184 Traffic Policers Feature Guide for EX9200 Switches ...
Page 212: ...Copyright 2016 Juniper Networks Inc 194 Traffic Policers Feature Guide for EX9200 Switches ...
Page 214: ...Copyright 2016 Juniper Networks Inc 196 Traffic Policers Feature Guide for EX9200 Switches ...
Page 278: ...Copyright 2016 Juniper Networks Inc 260 Traffic Policers Feature Guide for EX9200 Switches ...