Meaning
Verify the following information:
•
OSPF session establishment is blocked. OSPF does not use TCP as its transport
protocol. After the
from protocol tcp
match condition is deactivated, OSPF session
establishment is successful.
Verifying the ICMP Firewall Filter
Purpose
Verify that ICMP packets are being policed and counted. Also make sure that ping requests
are discarded when the requests originate from an untrusted source address.
Action
Undo the configuration changes made in previous verification steps.
1.
Reactivate the TCP firewall settings, and delete the 172.16/16 trusted source address.
[edit firewall family inet filter protect-RE term tcp-connection-term]
user@R2#
activate from protocol
user@R2#
activate from tcp-established
[edit policy-options prefix-list trusted-addresses]
user@R2#
delete 172.16.0.0/16
user@R2#
commit
2.
From Device R1, ping the loopback interface on Device R2.
user@R1>
ping 192.168.0.2 rapid count 600 size 2000
PING 192.168.0.2 (192.168.0.2): 2000 data bytes
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
--- 192.168.0.2 ping statistics ---
600 packets transmitted, 536 packets received, 10% packet loss
pinground-trip min/avg/max/stddev = 2.976/3.405/42.380/2.293 ms
3.
From Device R2, check the firewall statistics.
user@R2>
show firewall
Filter: protect-RE
Counters:
Name Bytes Packets
icmp-counter 1180804 1135
Policers:
Name Bytes Packets
icmp-policer 66
tcp-connection-policer 0
4.
From an untrusted source address on Device R1, send a ping request to Device R2’s
loopback interface.
user@R1>
ping 172.16.0.2 source 172.16.0.1
PING 172.16.0.2 (172.16.0.2): 56 data bytes
^C
--- 172.16.0.2 ping statistics ---
14 packets transmitted, 0 packets received, 100% packet loss
Meaning
Verify the following information:
95
Copyright © 2016, Juniper Networks, Inc.
Chapter 9: Filter-Specific Counters and Policers
Summary of Contents for EX9200 Series
Page 8: ...Copyright 2016 Juniper Networks Inc viii Traffic Policers Feature Guide for EX9200 Switches ...
Page 10: ...Copyright 2016 Juniper Networks Inc x Traffic Policers Feature Guide for EX9200 Switches ...
Page 12: ...Copyright 2016 Juniper Networks Inc xii Traffic Policers Feature Guide for EX9200 Switches ...
Page 20: ...Copyright 2016 Juniper Networks Inc 2 Traffic Policers Feature Guide for EX9200 Switches ...
Page 32: ...Copyright 2016 Juniper Networks Inc 14 Traffic Policers Feature Guide for EX9200 Switches ...
Page 34: ...Copyright 2016 Juniper Networks Inc 16 Traffic Policers Feature Guide for EX9200 Switches ...
Page 42: ...Copyright 2016 Juniper Networks Inc 24 Traffic Policers Feature Guide for EX9200 Switches ...
Page 54: ...Copyright 2016 Juniper Networks Inc 36 Traffic Policers Feature Guide for EX9200 Switches ...
Page 56: ...Copyright 2016 Juniper Networks Inc 38 Traffic Policers Feature Guide for EX9200 Switches ...
Page 72: ...Copyright 2016 Juniper Networks Inc 54 Traffic Policers Feature Guide for EX9200 Switches ...
Page 132: ...Copyright 2016 Juniper Networks Inc 114 Traffic Policers Feature Guide for EX9200 Switches ...
Page 152: ...Copyright 2016 Juniper Networks Inc 134 Traffic Policers Feature Guide for EX9200 Switches ...
Page 162: ...Copyright 2016 Juniper Networks Inc 144 Traffic Policers Feature Guide for EX9200 Switches ...
Page 178: ...Copyright 2016 Juniper Networks Inc 160 Traffic Policers Feature Guide for EX9200 Switches ...
Page 186: ...Copyright 2016 Juniper Networks Inc 168 Traffic Policers Feature Guide for EX9200 Switches ...
Page 188: ...Copyright 2016 Juniper Networks Inc 170 Traffic Policers Feature Guide for EX9200 Switches ...
Page 202: ...Copyright 2016 Juniper Networks Inc 184 Traffic Policers Feature Guide for EX9200 Switches ...
Page 212: ...Copyright 2016 Juniper Networks Inc 194 Traffic Policers Feature Guide for EX9200 Switches ...
Page 214: ...Copyright 2016 Juniper Networks Inc 196 Traffic Policers Feature Guide for EX9200 Switches ...
Page 278: ...Copyright 2016 Juniper Networks Inc 260 Traffic Policers Feature Guide for EX9200 Switches ...