Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asean Region (Vietnam, Indonesia, Singapore, Malaysia)
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

Technical Documentation

Download Software
Research a Problem Login required
Case Management Login required
Contract & Product Management Login required
Technical Documentation
Documentation Archive
Enterprise MIBs
File Format Help
Glossary
Portable Libraries
End-of-Life Products
Contact Support
Guidelines and Policies
Security Resources
Home > Support > Technical Documentation > Junos OS > Example: Configuring Filtering of Frames by MAC Address
Print
Rate and give feedback:  Feedback Received. Thank You!
Rate and give feedback: 
Close
This document helped resolve my issue.  Yes No

Additional Comments

800 characters remaining

May we contact you if necessary?

Name:  
E-mail: 
Submitting...
 

Related Documentation

  • MX Series
  • Firewall Filters for Bridge Domains and VPLS Instances
  • Example: Configuring Policing and Marking of Traffic Entering a VPLS Core
  • Example: Configuring Filtering of Frames by IEEE 802.1p Bits
  • Example: Configuring Filtering of Frames by Packet Loss Priority
  • Additional Information
  • Layer 2 Firewall Filters
 

Example: Configuring Filtering of Frames by MAC Address

This example firewall filter finds frames with a certain source MAC address (88:05:00:29:3c:de/48), then counts and silently discards them. For more information about configuring firewall filter match conditions, see the Junos OS Routing Policy Configuration Guide PDF Document. The filter is applied to the VLAN configured as vlan100200 as an input filter on Router 1.

Note: This example does not present exhaustive configuration listings for all routers in the figures. However, you can use this example with a broader configuration strategy to complete the MX Series router network Ethernet Operations, Administration, and Maintenance (OAM) configurations.

To configure filtering of frames by MAC address:

  1. Configure evil-mac-address, the firewall filter:

    [edit firewall]family bridge {filter evil-mac-address {term one {from {source-mac-address 88:05:00:29:3c:de/48;}then {count evil-mac-address; # Counts frame with the bad source MAC addressdiscard;}term two {then accept; # Make sure to accept other traffic}}}}
  2. Apply evil-mac-address as an input filter to vlan100200 on Router 1:

    [edit routing-instances]virtual-switch-R1-1 {bridge-domains {vlan100200 {domain-type bridge;forwarding-options {filter {input evil-mac-address;}}}}}
 

Related Documentation

  • MX Series
  • Firewall Filters for Bridge Domains and VPLS Instances
  • Example: Configuring Policing and Marking of Traffic Entering a VPLS Core
  • Example: Configuring Filtering of Frames by IEEE 802.1p Bits
  • Example: Configuring Filtering of Frames by Packet Loss Priority
  • Additional Information
  • Layer 2 Firewall Filters
 

Published: 2011-11-01

 
  • About Juniper
  • The New Network
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out