4.
Configure the filter term to match FTP packets.
[edit firewall family inet filter filter-ipv4-with-limits term t-ftp]
user@host#
set then
p-ftp-10p-500k-discard
5.
Enable configuration of a filter term to rate-limit ICMP packets.
[edit firewall family inet filter filter-ipv4-with-limits term t-ftp]
user@host#
up
[edit firewall family inet filter filter-ipv4-with-limits]
user@host#
edit term t-icmp
6.
Configure the filter term for ICMP packets
[edit firewall family inet filter filter-ipv4-with-limits term t-icmp]
user@host#
set from protocol icmp
user@host#
set then
p-icmp-500k-500k-discard
7.
Configure a filter term to accept all other packets without policing.
[edit firewall family inet filter filter-ipv4-with-limits term t-icmp]
user@host#
up
[edit firewall family inet filter filter-ipv4-with-limits]
user@host#
set term catch-all then accept
Results
Confirm the configuration of the firewall filter by entering the
show firewall
configuration
mode command. If the command output does not display the intended configuration,
repeat the instructions in this procedure to correct the configuration.
[edit]
user@host#
show firewall
family inet {
filter filter-ipv4-with-limits {
interface-specific;
term t-ftp {
from {
protocol tcp;
port [ ftp ftp-data ];
}
then
p-ftp-10p-500k-discard;
}
term t-icmp {
from {
protocol icmp;
}
then
p-icmp-500k-500k-discard;
}
term catch-all {
then accept;
}
}
}
p-all-1m-5k-discard {
if-exceeding {
bandwidth-limit 1m;
Copyright © 2016, Juniper Networks, Inc.
70
Traffic Policers Feature Guide for EX9200 Switches
Содержание EX9200 Series
Страница 8: ...Copyright 2016 Juniper Networks Inc viii Traffic Policers Feature Guide for EX9200 Switches ...
Страница 10: ...Copyright 2016 Juniper Networks Inc x Traffic Policers Feature Guide for EX9200 Switches ...
Страница 12: ...Copyright 2016 Juniper Networks Inc xii Traffic Policers Feature Guide for EX9200 Switches ...
Страница 20: ...Copyright 2016 Juniper Networks Inc 2 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 32: ...Copyright 2016 Juniper Networks Inc 14 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 34: ...Copyright 2016 Juniper Networks Inc 16 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 42: ...Copyright 2016 Juniper Networks Inc 24 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 54: ...Copyright 2016 Juniper Networks Inc 36 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 56: ...Copyright 2016 Juniper Networks Inc 38 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 72: ...Copyright 2016 Juniper Networks Inc 54 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 132: ...Copyright 2016 Juniper Networks Inc 114 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 152: ...Copyright 2016 Juniper Networks Inc 134 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 162: ...Copyright 2016 Juniper Networks Inc 144 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 178: ...Copyright 2016 Juniper Networks Inc 160 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 186: ...Copyright 2016 Juniper Networks Inc 168 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 188: ...Copyright 2016 Juniper Networks Inc 170 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 202: ...Copyright 2016 Juniper Networks Inc 184 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 212: ...Copyright 2016 Juniper Networks Inc 194 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 214: ...Copyright 2016 Juniper Networks Inc 196 Traffic Policers Feature Guide for EX9200 Switches ...
Страница 278: ...Copyright 2016 Juniper Networks Inc 260 Traffic Policers Feature Guide for EX9200 Switches ...