2.
Configure the first policer.
[edit firewall policer p-all-1m-5k-discard]
user@host#
set
1m
user@host#
set if-exceeding
5k
user@host#
set then discard
3.
Enable configuration of a two-color policer that discards packets that do not conform
to a bandwidth specified as “10 percent” and a burst size of 500,000 bytes.
You apply this policer only to the FTP traffic at the single-tag VLAN logical interface.
You apply this policer as the action of an IPv4 firewall filter term that matches FTP
packets from TCP.
[edit firewall policer p-all-1m-5k-discard]
user@host#
up
[edit]
user@host#
edit firewall policer p-ftp-10p-500k-discard
4.
Configure policing limits and actions.
[edit firewall policer p-ftp-10p-500k-discard]
user@host#
set if-exceeding
10
user@host#
set if-exceeding burst-size-limit 500k
user@host#
set then discard
Because the bandwidth limit is specified as a percentage, the firewall filter that
references this policer must be configured as an interface-specific filter.
NOTE:
If you wanted this policer to rate-limit to 10 percent of the logical
interface configured shaping rate (rather than to 10 percent of the
physical interface media rate), you would need to include the
statement at the
[edit firewall policer
p-all-1m-5k-discard]
hierarchy level. This type of policer is called a
logical-bandwidth policer.
5.
Enable configuration of the IPv4 firewall filter policer for ICMP packets.
[edit firewall policer p-ftp-10p-500k-discard]
user@host#
up
[edit]
user@host#
edit firewall policer p-icmp-500k-500k-discard
6.
Configure policing limits and actions.
[edit firewall policer p-icmp-500k-500k-discard]
user@host#
set if-exceeding bandwidth-limit 500k
user@host#
set if-exceeding burst-size-limit 500k
user@host#
set then discard
Copyright © 2016, Juniper Networks, Inc.
68
Traffic Policers Feature Guide for EX9200 Switches
Summary of Contents for EX9200 Series
Page 8: ...Copyright 2016 Juniper Networks Inc viii Traffic Policers Feature Guide for EX9200 Switches ...
Page 10: ...Copyright 2016 Juniper Networks Inc x Traffic Policers Feature Guide for EX9200 Switches ...
Page 12: ...Copyright 2016 Juniper Networks Inc xii Traffic Policers Feature Guide for EX9200 Switches ...
Page 20: ...Copyright 2016 Juniper Networks Inc 2 Traffic Policers Feature Guide for EX9200 Switches ...
Page 32: ...Copyright 2016 Juniper Networks Inc 14 Traffic Policers Feature Guide for EX9200 Switches ...
Page 34: ...Copyright 2016 Juniper Networks Inc 16 Traffic Policers Feature Guide for EX9200 Switches ...
Page 42: ...Copyright 2016 Juniper Networks Inc 24 Traffic Policers Feature Guide for EX9200 Switches ...
Page 54: ...Copyright 2016 Juniper Networks Inc 36 Traffic Policers Feature Guide for EX9200 Switches ...
Page 56: ...Copyright 2016 Juniper Networks Inc 38 Traffic Policers Feature Guide for EX9200 Switches ...
Page 72: ...Copyright 2016 Juniper Networks Inc 54 Traffic Policers Feature Guide for EX9200 Switches ...
Page 132: ...Copyright 2016 Juniper Networks Inc 114 Traffic Policers Feature Guide for EX9200 Switches ...
Page 152: ...Copyright 2016 Juniper Networks Inc 134 Traffic Policers Feature Guide for EX9200 Switches ...
Page 162: ...Copyright 2016 Juniper Networks Inc 144 Traffic Policers Feature Guide for EX9200 Switches ...
Page 178: ...Copyright 2016 Juniper Networks Inc 160 Traffic Policers Feature Guide for EX9200 Switches ...
Page 186: ...Copyright 2016 Juniper Networks Inc 168 Traffic Policers Feature Guide for EX9200 Switches ...
Page 188: ...Copyright 2016 Juniper Networks Inc 170 Traffic Policers Feature Guide for EX9200 Switches ...
Page 202: ...Copyright 2016 Juniper Networks Inc 184 Traffic Policers Feature Guide for EX9200 Switches ...
Page 212: ...Copyright 2016 Juniper Networks Inc 194 Traffic Policers Feature Guide for EX9200 Switches ...
Page 214: ...Copyright 2016 Juniper Networks Inc 196 Traffic Policers Feature Guide for EX9200 Switches ...
Page 278: ...Copyright 2016 Juniper Networks Inc 260 Traffic Policers Feature Guide for EX9200 Switches ...