16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

Instead of logical-interface-policer, you can use physical-interface-policer. Physical<br />

interface policers are for policers that you reference in firewall filters.<br />

3. (Optional) Reference the policer in a firewall filter, for all traffic types or for a specific<br />

traffic type.<br />

[edit firewall]<br />

user@host# set filter limit-hosts term term1 then three-color-policer single-rate<br />

srTCM1-ca<br />

[edit firewall]<br />

user@host# set family mpls filter limit-hosts term term1 then three-color-policer<br />

single-rate srTCM1-ca<br />

4. Apply the policer to an interface.<br />

If you referenced the policer in a firewall filter, apply the filter to an interface.<br />

[edit interfaces so-1/0/0 unit 0 family inet]<br />

user@host# set filter input srTCM1-ca<br />

On some platforms, you can apply a Layer 2 policer to all traffic types on Gigabit<br />

Ethernet (ge or xe) interfaces. Layer 2 policers must include the logical-interface-policer<br />

statement discussed in Step 2.<br />

[edit interfaces ge-1/0/0 unit 0]<br />

user@host# set layer2-policer input-three-color srTCM1-ca<br />

To apply a policer to outgoing packets, include the output-three-color statement<br />

instead of the input-policer statement.<br />

[edit interfaces ge-1/0/0 unit 0]<br />

user@host# set layer2-policer output-three-color srTCM1-ca<br />

5. For input policers on MX Series platforms only, configure a fixed classifier.<br />

A fixed classifier reclassifies all incoming packets, regardless of any preexisting<br />

classification.<br />

[edit class-of-service interfaces ge-0/0/0]<br />

user@host# set forwarding-class af<br />

The classifier name can be a configured classifier or one of the default classifiers.<br />

6. Verify that the policer is working as expected.<br />

user@host> show interfaces ge-0/0/0.0 detail<br />

user@host> show interfaces ge-0/0/0.0 statistics detail<br />

user@host> show policer<br />

Related<br />

Documentation<br />

• Physical Interface Policers <strong>Configuration</strong> on page 306<br />

• show interfaces (Gigabit Ethernet) command in the Junos Interfaces Command<br />

Reference<br />

• show interfaces statistics command in the Junos Interfaces Command Reference<br />

• show policer command in the Junos Routing Protocols and Policies Command Reference<br />

288<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!