16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 11: Policer <strong>Configuration</strong><br />

user@host# set action loss-priority high then discard<br />

3. Configure the policer type.<br />

[edit firewall policer trTCM1-ca]<br />

user@host# set logical-interface-policer<br />

Instead of logical-interface-policer, you can use physical-interface-policer. Physical<br />

interface policers are for policers that you reference in firewall filters.<br />

4. (Optional) Reference the policer in a firewall filter, for all traffic types or for a specific<br />

traffic type.<br />

[edit firewall]<br />

user@host# set filter limit-hosts term term1 then three-color-policer two-rate<br />

trTCM1-ca<br />

[edit firewall]<br />

user@host# set family mpls filter limit-hosts term term1 then three-color-policer<br />

two-rate trTCM1-ca<br />

5. Apply the policer to an interface.<br />

If you referenced the policer in a firewall filter, apply the filter to an interface.<br />

[edit interfaces ge-0/0/0 unit 0 family inet]<br />

user@host# set filter input trTCM1-ca<br />

On some platforms, you can apply a Layer 2 policer to all traffic types on Gigabit<br />

Ethernet (ge or xe) interfaces. Layer 2 policers must include the logical-interface-policer<br />

statement discussed in Step 3.<br />

[edit interfaces ge-1/0/0 unit 0]<br />

user@host# set layer2-policer input-three-color trTCM1-ca<br />

To apply a policer to outgoing packets, include the output-three-color statement<br />

instead of the input-policer statement.<br />

[edit interfaces ge-1/0/0 unit 0]<br />

user@host# set layer2-policer output-three-color trTCM1-ca<br />

6. For input policers on MX Series platforms only, configure a fixed classifier.<br />

A fixed classifier reclassifies all incoming packets, regardless of any preexisting<br />

classification.<br />

The classifier name can be a configured classifier or one of the default classifiers.<br />

[edit class-of-service interfaces ge-0/0/0]<br />

user@host# set forwarding-class af<br />

7. Verify that the policer is working as expected.<br />

user@host> show interfaces ge-0/0/0.0 detail<br />

user@host> show interfaces ge-0/0/0.0 statistics detail<br />

user@host> show policer<br />

Related<br />

Documentation<br />

• show interfaces (Gigabit Ethernet) command in the Junos Interfaces Command<br />

Reference<br />

• show interfaces statistics command in the Junos Interfaces Command Reference<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

291

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!