On Tuesday 27 April 2010 07:00:43 pm Walaa Abdel razzak wrote: > I have EX-4200 switch with JUNOS 9.6R2.11. all interfaces > are put in VLAN 1 and L3 interface is configured in the > same VLAN for reachability. I need to know what is the > best place to put the firewall filter on the switch (lo0 > or vlan.1 or uplink interface).
If the firewall is meant to filter traffic destined for the switch, e.g., SSH, TACACS+, e.t.c., place it on the Loopback interface in the inbound direction. If the firewall is meant to filter traffic transiting the switch, e.g., BCP-38, filtering of user traffic, e.t.c., place it on the l3 interface in the appropriate direction. Cheers, Mark.
signature.asc
Description: This is a digitally signed message part.
_______________________________________________ juniper-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/juniper-nsp

