On Saturday 10 May 2008, Joe Metzger wrote: > Does anybody have any suggestions about the best way to > manage a firewall > filter that is based on BGP community attributes?
Sounds like what you need is SCU (Source Class Usage) or DCU (Destination Class Usage). We do something like this, but for DCU; we have only tried it with firewall policers, though, but you should be able to accept and discard packets accordingly. Our requirement was to restrictively police traffic destined to a particular set of routes, while policing at a different rate for the rest of the routes. These routes were identified using BGP communities. Cheers, Mark.
signature.asc
Description: This is a digitally signed message part.
_______________________________________________ juniper-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/juniper-nsp

