Monitoring Traffic for All Firewall Filters and Policers That Are Configured on the Switch
Purpose
Perform the following task to monitor the number of packets and bytes that matched
the firewall filters and monitor the number of packets that exceeded policer rate limits:
Action
Use the operational mode command:
user@switch>
show firewall
Filter: egress-vlan-watch-employee
Counters:
Name Bytes Packets
counter-employee-web 3348 27
Filter: ingress-port-voip-class-limit-tcp-icmp
Counters:
Name Bytes Packets
icmp-counter 4100 49
Policers:
Name Packets
icmp-connection-policer 0
tcp-connection-policer 0
Filter: ingress-vlan-rogue-block
Filter: ingress-vlan-limit-guest
Meaning
The
show firewall
command displays the names of all firewall filters, policers, and
counters that are configured on the switch. The output fields show byte and packet
counts for counters and packet count for policers.
Monitoring Traffic for a Specific Firewall Filter
Purpose
Perform the following task to monitor the number of packets and bytes that matched a
firewall filter and monitor the number of packets that exceeded the policer rate limits.
Action
Use the operational mode command:
user@switch>
show firewall filter ingress-vlan-rogue-block
Filter: ingress-vlan-rogue-block
Counters:
Name Bytes Packets
rogue-counter 2308 20
Meaning
The
show firewall filter filter-name
command displays the name of the firewall filter,
the packet and byte count for all counters configured with the filter, and the packet count
for all policers configured with the filter.
Monitoring Traffic for a Specific Policer
Purpose
Perform the following task to monitor the number of packets that exceeded policer rate
limits:
Action
Use the operational mode command:
user@switch>
show policer
tcp-connection-policer
Filter: ingress-port-voip-class-limit-tcp-icmp
Policers:
3085
Copyright © 2010, Juniper Networks, Inc.
Chapter 103: Verifying Firewall Filter Configuration
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...