[edit policy-options prefix-list trusted-addresses]
user@R2#
set 172.16.0.0/16
user@R2#
commit
3.
From Device R1, try again to telnet to Device R2.
user@R1>
telnet 172.16.0.2 source 172.16.0.1
Trying 172.16.0.2...
Connected to R2.example.net.
Escape character is '^]'.
R2 (ttyp4)
login:
Meaning
Verify the following information:
•
From Device R1, you cannot telnet to Device R2 with an unstrusted source address.
After the 172.16/16 prefix is added to the list of trusted prefixes, the telnet request from
source address 172.16.0.1 is accepted.
•
OSPF session establishment is blocked. OSPF does not use TCP as its transport
protocol. After the
from protocol tcp
match condition is deactivated, OSPF session
establishment is not blocked.
Using OSPF to Verify the TCP Firewall Filter
Purpose
Make sure that OSPF traffic works as expected.
Action
Verify that the device cannot establish OSPF connectivity.
1.
From Device R1, check the OSPF sessions.
user@R1>
show ospf neighbor
Address Interface State ID Pri Dead
10.0.0.2 fe-1/2/0.0 Init 192.168.0.2 128 34
2.
From Device R2, check the OSPF sessions.
user@R2>
show ospf neighbor
3.
From Device R2, remove the
from protocol tcp
match condition.
[edit firewall family inet filter protect-RE term tcp-connection-term]
user@R2#
deactivate from protocol
user@R2#
commit
4.
From Device R1, recheck the OSPF sessions.
user@R1>
show ospf neighbor
Address Interface State ID Pri Dead
10.0.0.2 fe-1/2/0.0 Full 192.168.0.2 128 36
5.
From Device R2, recheck the OSPF sessions.
user@R2>
show ospf neighbor
Address Interface State ID Pri Dead
10.0.0.1 fe-1/2/0.0 Full 192.168.0.1 128 39
Copyright © 2016, Juniper Networks, Inc.
94
Traffic Policers Feature Guide for EX9200 Switches
Summary of Contents for EX9200 Series
Page 8: ...Copyright 2016 Juniper Networks Inc viii Traffic Policers Feature Guide for EX9200 Switches ...
Page 10: ...Copyright 2016 Juniper Networks Inc x Traffic Policers Feature Guide for EX9200 Switches ...
Page 12: ...Copyright 2016 Juniper Networks Inc xii Traffic Policers Feature Guide for EX9200 Switches ...
Page 20: ...Copyright 2016 Juniper Networks Inc 2 Traffic Policers Feature Guide for EX9200 Switches ...
Page 32: ...Copyright 2016 Juniper Networks Inc 14 Traffic Policers Feature Guide for EX9200 Switches ...
Page 34: ...Copyright 2016 Juniper Networks Inc 16 Traffic Policers Feature Guide for EX9200 Switches ...
Page 42: ...Copyright 2016 Juniper Networks Inc 24 Traffic Policers Feature Guide for EX9200 Switches ...
Page 54: ...Copyright 2016 Juniper Networks Inc 36 Traffic Policers Feature Guide for EX9200 Switches ...
Page 56: ...Copyright 2016 Juniper Networks Inc 38 Traffic Policers Feature Guide for EX9200 Switches ...
Page 72: ...Copyright 2016 Juniper Networks Inc 54 Traffic Policers Feature Guide for EX9200 Switches ...
Page 132: ...Copyright 2016 Juniper Networks Inc 114 Traffic Policers Feature Guide for EX9200 Switches ...
Page 152: ...Copyright 2016 Juniper Networks Inc 134 Traffic Policers Feature Guide for EX9200 Switches ...
Page 162: ...Copyright 2016 Juniper Networks Inc 144 Traffic Policers Feature Guide for EX9200 Switches ...
Page 178: ...Copyright 2016 Juniper Networks Inc 160 Traffic Policers Feature Guide for EX9200 Switches ...
Page 186: ...Copyright 2016 Juniper Networks Inc 168 Traffic Policers Feature Guide for EX9200 Switches ...
Page 188: ...Copyright 2016 Juniper Networks Inc 170 Traffic Policers Feature Guide for EX9200 Switches ...
Page 202: ...Copyright 2016 Juniper Networks Inc 184 Traffic Policers Feature Guide for EX9200 Switches ...
Page 212: ...Copyright 2016 Juniper Networks Inc 194 Traffic Policers Feature Guide for EX9200 Switches ...
Page 214: ...Copyright 2016 Juniper Networks Inc 196 Traffic Policers Feature Guide for EX9200 Switches ...
Page 278: ...Copyright 2016 Juniper Networks Inc 260 Traffic Policers Feature Guide for EX9200 Switches ...