Skip to Content
Juniper MX Series, 2nd Edition
book

Juniper MX Series, 2nd Edition

by Douglas Richard Hanks, Harry Reynolds, David Roy
September 2016
Intermediate to advanced
1140 pages
30h 11m
English
O'Reilly Media, Inc.
Content preview from Juniper MX Series, 2nd Edition

Chapter 3. Stateless Filters, Hierarchical Policing, and Tri-Color Marking

This chapter covers stateless firewall filters and policers on MX routers. The MX Series has some special features and hardware that can make firewall filters and policers not only stronger, faster, and smarter, but also, once you get the hang of their operation, easier. So even if you think you know how to protect the Routing Engine, don’t skip this chapter or the next. The MX Series is one awesome piece of iron, and users are always finding new ways to deploy its features for revenue. As critical infrastructure, it’s well worth protecting; after all, the best rock stars have bodyguards these days.

By the way, this chapter is an overview, but is required reading for Chapter 4, where we blast right into case studies of IPv4 and IPv6 Routing Engine protection filters and coverage of the new DDoS policing feature available on Trio platforms. Chapter 4 is not going to pause to go back and reiterate the key concepts found here in Chapter 3.

The topics discussed in this chapter include:

  • Firewall filtering and policing overview

  • Filter operation

  • Policer types and operation

  • Filter and policer application points

  • Transit filtering case study: Bridging with BUM protection

Firewall Filter and Policer Overview

The primary function of a firewall filter is to enhance security by blocking packets based on various match criteria. Filters are also used to perform multifield classification, a process whereby ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

CompTIA Security+ SY0-701

CompTIA Security+ SY0-701

Sari Greene
Juniper MX Series

Juniper MX Series

Douglas Richard Hanks Jr., Harry Reynolds
CCNP and CCIE Enterprise Core ENCOR 350-401, 2nd Edition

CCNP and CCIE Enterprise Core ENCOR 350-401, 2nd Edition

Brad Edgeworth / Brad Riapolov / Vinit Jain
Routing TCP/IP, Volume 1, 2/e

Routing TCP/IP, Volume 1, 2/e

Jennifer Carroll Jeff Doyle

Publisher Resources

ISBN: 9781491932711Errata Page