On Saturday 10 May 2008, Joe Metzger wrote:

> Does anybody have any suggestions about the best way to
> manage a firewall
> filter that is based on BGP community attributes?

Sounds like what you need is SCU (Source Class Usage) or DCU 
(Destination Class Usage).

We do something like this, but for DCU; we have only tried 
it with firewall policers, though, but you should be able 
to accept and discard packets accordingly.

Our requirement was to restrictively police traffic destined 
to a particular set of routes, while policing at a 
different rate for the rest of the routes. These routes 
were identified using BGP communities.

Cheers,

Mark.

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
juniper-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/juniper-nsp

Reply via email to