Meaning
Verify the following information:
•
OSPF session establishment is blocked. OSPF does not use TCP as its transport
protocol. After the
from protocol tcp
match condition is deactivated, OSPF session
establishment is successful.
Verifying the ICMP Firewall Filter
Purpose
Verify that ICMP packets are being policed and counted. Also make sure that ping requests
are discarded when the requests originate from an untrusted source address.
Action
Undo the configuration changes made in previous verification steps.
1.
Reactivate the TCP firewall settings, and delete the 172.16/16 trusted source address.
[edit firewall family inet filter protect-RE term tcp-connection-term]
user@R2#
activate from protocol
user@R2#
activate from tcp-established
[edit policy-options prefix-list trusted-addresses]
user@R2#
delete 172.16.0.0/16
user@R2#
commit
2.
From Device R1, ping the loopback interface on Device R2.
user@R1>
ping 192.168.0.2 rapid count 600 size 2000
PING 192.168.0.2 (192.168.0.2): 2000 data bytes
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
.
!
!
!
!
!
!
!
!
--- 192.168.0.2 ping statistics ---
600 packets transmitted, 536 packets received, 10% packet loss
pinground-trip min/avg/max/stddev = 2.976/3.405/42.380/2.293 ms
3.
From Device R2, check the firewall statistics.
user@R2>
show firewall
Filter: protect-RE
Counters:
Name Bytes Packets
icmp-counter 1180804 1135
Policers:
Name Bytes Packets
icmp-policer 66
tcp-connection-policer 0
4.
From an untrusted source address on Device R1, send a ping request to Device R2’s
loopback interface.
user@R1>
ping 172.16.0.2 source 172.16.0.1
PING 172.16.0.2 (172.16.0.2): 56 data bytes
^C
--- 172.16.0.2 ping statistics ---
14 packets transmitted, 0 packets received, 100% packet loss
Meaning
Verify the following information:
95
Copyright © 2016, Juniper Networks, Inc.
Chapter 9: Filter-Specific Counters and Policers
Содержание EX9200 Series
Страница 8: ...Copyright 2016 Juniper Networks Inc viii Traffic Policers Feature Guide for EX9200 Switches ...
Страница 10: ...Copyright 2016 Juniper Networks Inc x Traffic Policers Feature Guide for EX9200 Switches ...
Страница 12: ...Copyright 2016 Juniper Networks Inc xii Traffic Policers Feature Guide for EX9200 Switches ...
Страница 20: ...Copyright 2016 Juniper Networks Inc 2 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 32: ...Copyright 2016 Juniper Networks Inc 14 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 34: ...Copyright 2016 Juniper Networks Inc 16 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 42: ...Copyright 2016 Juniper Networks Inc 24 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 54: ...Copyright 2016 Juniper Networks Inc 36 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 56: ...Copyright 2016 Juniper Networks Inc 38 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 72: ...Copyright 2016 Juniper Networks Inc 54 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 132: ...Copyright 2016 Juniper Networks Inc 114 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 152: ...Copyright 2016 Juniper Networks Inc 134 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 162: ...Copyright 2016 Juniper Networks Inc 144 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 178: ...Copyright 2016 Juniper Networks Inc 160 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 186: ...Copyright 2016 Juniper Networks Inc 168 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 188: ...Copyright 2016 Juniper Networks Inc 170 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 202: ...Copyright 2016 Juniper Networks Inc 184 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 212: ...Copyright 2016 Juniper Networks Inc 194 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 214: ...Copyright 2016 Juniper Networks Inc 196 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 278: ...Copyright 2016 Juniper Networks Inc 260 Traffic Policers Feature Guide for EX9200 Switches ...