16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

multiple firewall filters to the incoming traffic on an interface. You use an output list to<br />

apply multiple firewall filters to the outbound traffic on an interface. You can include up<br />

to 16 filters in an input or an output list.<br />

See Table 24 on page 186 for a detailed description of each supported application point,<br />

the types of firewall filters supported by each application point, and any limitations.<br />

Table 24: Firewall Filter Application Points<br />

Application Point<br />

Filter Type<br />

Supported Hierarchy<br />

Comments<br />

Physical interface—Filter<br />

affects packets for all logical<br />

interfaces configured on the<br />

physical interface.<br />

Hierarchical policer you<br />

define at the [edit firewall<br />

hierarchical-policer<br />

hierarchical-policer-name]<br />

hierarchy level.<br />

[edit interfaces interface-name<br />

layer2-policer inputhierarchical-policer]<br />

Supported only on Gigabit<br />

Ethernet intelligent queuing<br />

(IQ2) PICs on the M120,<br />

M320 and T Series routers<br />

and on Enhanced Queuing<br />

Dense Port Concentrators<br />

(EQ DPC) on MX Series<br />

routers.<br />

Logical interface—Filter<br />

affects all protocol families<br />

configured on the logical<br />

interface.<br />

Firewall filter you define for<br />

the protocol family any at the<br />

[edit firewall] hierarchy level.<br />

• [edit interfaces interface-name<br />

unit unit-number filter input<br />

filter-name]<br />

• [edit interfaces interface-name<br />

unit unit-number output<br />

filter-name]<br />

Supported only on M320<br />

and T Series routers, on M7i<br />

and M10i routers with the<br />

enhanced CFEB (CFEB-e)<br />

and on 10-Gigabit Ethernet<br />

Modular Port Concentrator<br />

(MPC), 60-Gigabit<br />

Ethernet MPC, 60-Gigabit<br />

Ethernet Queuing MPC, and<br />

60-Gigabit Ethernet<br />

Enhanced Queuing MPC on<br />

MX Series routers.<br />

Logical interface—Filter<br />

applied affects all protocol<br />

families configured on the<br />

logical interface.<br />

Layer 2 policer you define at:<br />

• [edit firewall policer<br />

policer-name] hierarchy<br />

level for input policers and<br />

output policers<br />

• [edit firewall<br />

three-color-policer<br />

policer-name hierarchy<br />

level for input three color<br />

policers and output three<br />

color policers<br />

• [edit interfaces interface-name<br />

unit unit-number layer2-policer<br />

input-policer policer-name]<br />

• [edit interfaces interface-name<br />

unit unit-number layer2-policer<br />

output-policer policer-name]<br />

• [edit interfaces interface-name<br />

unit unit-number<br />

input-three-color policer-name]<br />

• [edit interfaces interface-name<br />

unit unit-number<br />

output-three-color<br />

policer-name]<br />

MX Series routers do not<br />

support layer 2 policers<br />

applied to a logical<br />

interface. On MX Series<br />

routers, layer 2 policers an<br />

only be applied as<br />

hierarchical policers.<br />

Logical interface—Filter<br />

applied affects all protocol<br />

families configured on the<br />

logical interface.<br />

Hierarchical policer you<br />

define at the [edit firewall<br />

hierarchical-policer<br />

hierarchical-policer-name]<br />

hierarchy level.<br />

[edit interfaces interface-name<br />

unit unit-number layer2-policer<br />

inputhierarchical-policer<br />

policer-name]<br />

Supported only on Gigabit<br />

Ethernet intelligent queuing<br />

(IQ2) PICs on the M120,<br />

M320 and T Series routers.<br />

186<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!