On Tuesday 27 April 2010 07:00:43 pm Walaa Abdel razzak 
wrote:

> I have EX-4200 switch with JUNOS 9.6R2.11. all interfaces
>  are put in VLAN 1 and L3 interface is configured in the
>  same VLAN for reachability. I need to know what is the
>  best place to put the firewall filter on the switch (lo0
>  or vlan.1 or uplink interface).

If the firewall is meant to filter traffic destined for the 
switch, e.g., SSH, TACACS+, e.t.c., place it on the Loopback 
interface in the inbound direction.

If the firewall is meant to filter traffic transiting the 
switch, e.g., BCP-38, filtering of user traffic, e.t.c., 
place it on the l3 interface in the appropriate direction.

Cheers,

Mark.

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
juniper-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/juniper-nsp

Reply via email to