16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 11: Policer <strong>Configuration</strong><br />

}<br />

}<br />

}<br />

}<br />

To use this classifier, you must configure the settings for the expedited-forwarding<br />

forwarding class at the [edit class-of-service forwarding-classes queue queue-number<br />

expedited-forwarding] hierarchy level.<br />

NOTE: Because the policer is executed before the filter, if an input policer is<br />

also configured on the logical interface, it cannot use the forwarding class<br />

and PLP of a multifield classifier associated with the interface.<br />

For more information about forwarding class and loss priority, see the Junos OS Class of<br />

Service <strong>Configuration</strong> <strong>Guide</strong>. For more information about policers, see the following<br />

sections:<br />

• Configuring Filter-Specific Policers on page 297<br />

• Configuring Policer Actions for Specific Address Prefixes on page 297<br />

• Examples: Classifying Traffic on page 302<br />

Configuring Filter-Specific Policers<br />

You can configure filter-specific policers within the firewall configuration. Filter-specific<br />

policers allow you to configure policers and counters for a specific filter name.<br />

When you configure the filter-specific statement, a single policer set is created for the<br />

entire filter. All traffic matching the terms of the firewall filter with the action policer goes<br />

through that single policer. The default is a term-specific policer in which a single policer<br />

set is created for each term within the filter. All traffic matching the terms of the firewall<br />

filter with the action policer goes through the part of the policer that is specific to that<br />

term.<br />

To configure filter-specific policers, include the filter-specific statement at the [edit<br />

firewall policer policer-name] hierarchy level:<br />

[edit firewall policer policer-name]<br />

filter-specific;<br />

If the filter-specific statement is not configured, then the policer defaults to a term-specific<br />

policer.<br />

You can apply the filter-specific policers to the family inet.<br />

Configuring Policer Actions for Specific Address Prefixes<br />

You can configure prefix-specific actions within the firewall configuration. Prefix-specific<br />

actions allow you to configure policers and counters for specific addresses or ranges of<br />

addresses. This allows you to essentially create policers and counters on a per-prefix<br />

level.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

297

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!