16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 15: Traffic Forwarding and Monitoring <strong>Configuration</strong><br />

}<br />

}<br />

Applying Filters to Forwarding Tables<br />

A forwarding table filter allows you to filter data packets based on their components and<br />

perform an action on packets that match the filter. You can apply a filter on the ingress<br />

or egress packets of a forwarding table. You configure the filter at the [edit firewall family<br />

family-name] hierarchy level; for more information, see “Configuring Forwarding Table<br />

Filters” on page 271.<br />

To apply a forwarding table filter on ingress packets of a forwarding table, include the<br />

filter and input statements at the [edit forwarding-options family family-name] hierarchy<br />

level:<br />

[edit forwarding-options family family-name]<br />

filter {<br />

input filter-name;<br />

}<br />

On the MX Series router only, to apply a forwarding table filter for a virtual switch, include<br />

the filter and input statements at the [edit routing-instances routing-instance-name<br />

bridge-domains bridge-domain-name forwarding-options] hierarchy level:<br />

[edit routing-instances routing-instance-name bridge-domains bridge-domain-name<br />

forwarding-options]<br />

filter {<br />

input filter-name;<br />

}<br />

For more information about how to configure a virtual switch, see the Junos Layer 2<br />

<strong>Configuration</strong> <strong>Guide</strong>.<br />

You can filter based upon destination-class information by applying a firewall filter on<br />

the egress packets of the forwarding table. By applying firewall filters to packets that<br />

have been forwarded by a routing table, you can match based on certain parameters<br />

that are decided by the route lookup. For example, routes can be classified into specific<br />

destination and source classes. Firewall filters used for policing and mirroring are able<br />

to match based upon these classes.<br />

To apply a firewall filter on egress packets of a forwarding table, include the filter and<br />

output statements at the [edit forwarding-options family family-name] hierarchy level:<br />

[edit forwarding-options family family-name]<br />

filter {<br />

output filter-name;<br />

}<br />

NOTE: The egress forwarding table filter is applied on the ingress interface<br />

of the Flexible PIC Concentrator (FPC). If different packets to the same<br />

destination arrive on different FPCs, they might encounter different policers.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

363

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!