Skip to Content
Juniper MX Series, 2nd Edition
book

Juniper MX Series, 2nd Edition

by Douglas Richard Hanks, Harry Reynolds, David Roy
September 2016
Intermediate to advanced content levelIntermediate to advanced
1140 pages
30h 11m
English
O'Reilly Media, Inc.
Book available
Content preview from Juniper MX Series, 2nd Edition

Chapter 3. Stateless Filters, Hierarchical Policing, and Tri-Color Marking

This chapter covers stateless firewall filters and policers on MX routers. The MX Series has some special features and hardware that can make firewall filters and policers not only stronger, faster, and smarter, but also, once you get the hang of their operation, easier. So even if you think you know how to protect the Routing Engine, don’t skip this chapter or the next. The MX Series is one awesome piece of iron, and users are always finding new ways to deploy its features for revenue. As critical infrastructure, it’s well worth protecting; after all, the best rock stars have bodyguards these days.

By the way, this chapter is an overview, but is required reading for Chapter 4, where we blast right into case studies of IPv4 and IPv6 Routing Engine protection filters and coverage of the new DDoS policing feature available on Trio platforms. Chapter 4 is not going to pause to go back and reiterate the key concepts found here in Chapter 3.

The topics discussed in this chapter include:

  • Firewall filtering and policing overview

  • Filter operation

  • Policer types and operation

  • Filter and policer application points

  • Transit filtering case study: Bridging with BUM protection

Firewall Filter and Policer Overview

The primary function of a firewall filter is to enhance security by blocking packets based on various match criteria. Filters are also used to perform multifield classification, a process whereby ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Juniper MX Series

Juniper MX Series

Douglas Richard Hanks Jr., Harry Reynolds
CCNP and CCIE Enterprise Core ENCOR 350-401, 2nd Edition

CCNP and CCIE Enterprise Core ENCOR 350-401, 2nd Edition

Brad Edgeworth / Brad Riapolov / Vinit Jain

Publisher Resources

ISBN: 9781491932711Errata Page