O'Reilly logo

Juniper Networks® Field Guide and Reference by Juniper Networks®, Cris Morris, Gary Drenan, Aviva Garrett

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Configuring Firewall Filters

To configure firewall filters, include the following statements:

[edit]
firewall {
  policer policer-name {
    if-exceeding {
      bandwidth-limit rate;
      burst-size-limit bytes;
    }
    then {
      policer-action;
    }
  }
  filter filter-name {
    accounting-profile name;
    interface-specific;
    policer policer-name {
      if-exceeding {
        bandwidth-limit rate;
        burst-size-limit bytes;
      }
      then {
        policer-action;
      }
    }
    term term-name {
      from {
        match-conditions;
      }
      then {
        actions;
        action-modifiers;
      }
    }
  }
}
interfaces {
  interface-name {
    unit logical-unit-number {
      family inet {
        filter {
          input filter-name;
          output filter-name;
        }
      }
    }
  }
}

Policing does not use the filter match conditions. Instead, it uses the if-exceeding statement. For more information, see the JUNOS ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required