login:
3.
From Device R1, telnet to Device R2.
user@R1>
telnet 192.168.0.2
Trying 192.168.0.2...
telnet: connect to address 192.168.0.2: Operation timed out
telnet: Unable to connect to remote host
4.
On Device R2, deactivate the
from tcp-established
match condition.
[edit firewall family inet filter protect-RE term tcp-connection-term]
user@R2#
deactivate from tcp-established
user@R2#
commit
5.
From Device R1, try again to telnet to Device R2.
user@R1>
telnet 192.168.0.1
Trying 192.168.0.2...
Connected to R2.example.net.
Escape character is '^]'.
R2 (ttyp4)
login:
Meaning
Verify the following information:
•
As expected , the BGP session is established. The
from tcp-established
match condition
is not expected to block BGP session establishment.
•
From Device R2, you can telnet to Device R1. Device R1 has no firewall filter configured,
so this is the expected behavior.
•
From Device R1, you cannot telnet to Device R2. Telnet uses TCP as the transport
protocol, so this result might be surprising. The cause for the lack of telnet connectivity
is the
from tcp-established
match condition. This match condition limits the type of
TCP traffic that is accepted of Device R2. After this match condition is deactivated,
the telnet session is successful.
Using telnet to Verify the Trusted Prefixes Condition in the TCP Firewall Filter
Purpose
Make sure that telnet traffic works as expected.
Action
Verify that the device can establish only telnet sessions with a host at an IP address that
matches one of the trusted source addresses. For example, log in to the device with the
telnet
command from another host with one of the trusted address prefixes. Also, verify
that telnet sessions with untrusted source addresses are blocked.
1.
From Device R1, telnet to Device R2 from an untrusted source address.
user@R1>
telnet 172.16.0.2 source 172.16.0.1
Trying 172.16.0.2...
^C
2.
From Device R2, add 172.16/16 to the list of trusted prefixes.
93
Copyright © 2016, Juniper Networks, Inc.
Chapter 9: Filter-Specific Counters and Policers
Содержание EX9200 Series
Страница 8: ...Copyright 2016 Juniper Networks Inc viii Traffic Policers Feature Guide for EX9200 Switches ...
Страница 10: ...Copyright 2016 Juniper Networks Inc x Traffic Policers Feature Guide for EX9200 Switches ...
Страница 12: ...Copyright 2016 Juniper Networks Inc xii Traffic Policers Feature Guide for EX9200 Switches ...
Страница 20: ...Copyright 2016 Juniper Networks Inc 2 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 32: ...Copyright 2016 Juniper Networks Inc 14 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 34: ...Copyright 2016 Juniper Networks Inc 16 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 42: ...Copyright 2016 Juniper Networks Inc 24 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 54: ...Copyright 2016 Juniper Networks Inc 36 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 56: ...Copyright 2016 Juniper Networks Inc 38 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 72: ...Copyright 2016 Juniper Networks Inc 54 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 132: ...Copyright 2016 Juniper Networks Inc 114 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 152: ...Copyright 2016 Juniper Networks Inc 134 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 162: ...Copyright 2016 Juniper Networks Inc 144 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 178: ...Copyright 2016 Juniper Networks Inc 160 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 186: ...Copyright 2016 Juniper Networks Inc 168 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 188: ...Copyright 2016 Juniper Networks Inc 170 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 202: ...Copyright 2016 Juniper Networks Inc 184 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 212: ...Copyright 2016 Juniper Networks Inc 194 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 214: ...Copyright 2016 Juniper Networks Inc 196 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 278: ...Copyright 2016 Juniper Networks Inc 260 Traffic Policers Feature Guide for EX9200 Switches ...