IIRC, you need Junos 9.5 or later to use filter-specific feature. -Dan-
On Mon, Nov 16, 2009 at 1:22 PM, Felix Schueren < [email protected]> wrote: > Dan, > > > > > firewall { > > policer 500m { > > if-exceeding { > > bandwidth-limit 600m; > > burst-size-limit 15m; > > } > > then discard; > > } > > family inet { > > filter 500m-limit { > > term default { > > then policer 500m; > > } > > } > > } > > } > > > > > > [email protected]# show interfaces ge-0/0/4 > > description SERVER::mirror0.sov.uk; > > unit 0 { > > family inet { > > filter { > > input 500m-limit; > > } > > address x.x.x.x/y; > > } > > } > > > > > > if you apply that firewall-filter to multiple interfaces (or simply > reference the same policer from within different filters), they will all > share the same bucket. I.e. if one of those interfaces exceeds the > limit, all other interfaces using the same policer will drop packets, > even if they're different customers or different filters. If you want a > generic "500m" limit and reference that from different filters, on > M-series you can simply use "filter-specific" within the policer and it > will generate internal policers automatically for each reference within > a different filter - the EXes won't. > > Kind regards. > > Felix > > -- > Felix Schüren > Head of Network > > ----------------------------------------------------------------------- > Host Europe GmbH - http://www.hosteurope.de > Welserstraße 14 - 51149 Köln - Germany > Telefon: 0800 467 8387 - Fax: +49 180 5 66 3233 (*) > HRB 28495 Amtsgericht Köln - USt-IdNr.: DE187370678 > Geschäftsführer: > Uwe Braun - Alex Collins - Mark Joseph - Patrick Pulvermüller > > (*) 0,14 EUR/Min. aus dem dt. Festnetz, Mobilfunkpreise ggf. abweichend > _______________________________________________ > juniper-nsp mailing list [email protected] > https://puck.nether.net/mailman/listinfo/juniper-nsp > _______________________________________________ juniper-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/juniper-nsp

