16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

Physical Interface Policers <strong>Configuration</strong><br />

A physical interface policer defines rate-limiting parameters for all the logical interfaces<br />

and protocol families configured on a physical interface. These logical interfaces can<br />

belong to different routing instances. You reference the policer within one or more firewall<br />

filters. You must also apply the physical interface policer as an action for each term used<br />

to define a set of match conditions for traffic on which you want to perform rate limiting.<br />

You apply the firewall filters as input or output filters to the logical interfaces configured<br />

on the physical interface referenced in the policer.<br />

The following sections describe how to configure a physical interface policer, reference<br />

the policer within a firewall filter, apply the policer as an action for a firewall filter, and<br />

apply (to a logical interface) a firewall filter that references a physical interface filter.<br />

• Configuring Physical Interface Policers on page 306<br />

• Configuring Firewall Filters That Reference Physical Interface Policers on page 307<br />

• Applying Firewall Filters That Reference Physical Interface Policers on page 308<br />

Configuring Physical Interface Policers<br />

To configure a policer for a physical interface:<br />

1. Include the physical-interface-policer statement at the [edit firewall policer<br />

policer-name] hierarchy level.<br />

2. Include the if-exceeding statement at the [edit firewall policer policer-name] hierarchy<br />

level to define rate-limiting parameters for the policer.<br />

For the if-exceeding statement, you must configure the following parameters:<br />

• bandwidth-limit bps—Traffic rate, in bits per second (bps)<br />

• burst-size-limit bytes—Maximum burst size, in bytes<br />

3. Include the then policer-action statement at the [edit firewall policer policer-name]<br />

hierarchy level to apply an action to the policer.<br />

For policer-action, you can apply the following:<br />

• discard—Discard a packet that exceeds the rate limits<br />

• loss-priority level—Set the loss priority level to low, medium-low, medium-high, high.<br />

• forwarding-class class-name—Specify the forwarding class for any class-name<br />

already configured.<br />

In the following example, a physical interface policer, shared-police1, is configured to<br />

rate-limit traffic at 100,000,000 bps and to permit a maximum burst of traffic of 500,000<br />

bytes. The discard action results in the discarding of packets that exceed the configured<br />

rate limits.<br />

[edit]<br />

firewall {<br />

306<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!