![Juniper JUNOS OS 10.3 - SOFTWARE Manual Download Page 3104](http://html.mh-extra.com/html/juniper/junos-os-10-3-software/junos-os-10-3-software_manual_20327933104.webp)
For a multicast packet that results in replications, an egress firewall filter is applied to
each copy of the packet based on its corresponding egress VLAN.
For Layer 2 (bridged) unicast packets, the following firewall filter processing points apply:
•
Ingress port firewall filter
•
Ingress VLAN firewall filter
•
Egress port firewall filter
•
Egress VLAN firewall filter
For Layer 3 (routed and multilayer-switched) unicast packets, the following firewall filter
processing points apply:
•
Ingress port firewall filter
•
Ingress VLAN firewall filter (Layer 2 CoS)
•
Ingress router firewall filter (Layer 3 CoS)
•
Egress router firewall filter
•
Egress VLAN firewall filter
Related
Documentation
Firewall Filters for EX Series Switches Overview on page 3001
•
•
Understanding How Firewall Filters Control Packet Flows on page 3008
•
Understanding Bridging and VLANs on EX Series Switches on page 1283
•
Example: Configuring Firewall Filters for Port, VLAN, and Router Traffic on EX Series
Switches on page 3039
Understanding How Firewall Filters Control Packet Flows
Juniper Networks EX Series Ethernet Switches support firewall filters that allow you to
control flows of data packets and local packets.
Data packets
are chunks of data that
transit the switch as they are forwarded from a source to a destination.
Local packets
are chunks of data that are destined for or sent by the switch. Local packets usually
contain routing protocol data, data for IP services such as Telnet or SSH, and data for
administrative protocols such as the Internet Control Message Protocol (ICMP).
You create firewall filters to protect your switch from excessive traffic transiting the
switch to a network destination or destined for the Routing Engine on the switch. Firewall
filters that control local packets can also protect your switch from external incidents
such as denial-of-service (DoS) attacks.
Firewall filters affect packet flows entering in to or exiting from the switch's interfaces:
•
Ingress firewall filters affect the flow of data packets that are received by the switch's
interfaces. The Packet Forwarding Engine (PFE) handles this flow. When a switch
receives a data packet on an interface, the switch determines where to forward the
packet by looking in the forwarding table for the best route (Layer 2 switching, Layer 3
Copyright © 2010, Juniper Networks, Inc.
3008
Complete Software Guide for Junos
®
OS for EX Series Ethernet Switches, Release 10.3
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...