Configure firewall filters for Layer 2 packets that are
part of bridging domain for MX series routers.
|
- Click Filter next to Bridge.
- Click Add new entry next to Filter.
- Expand Filter.
- In the name box, enter the name that
identifies the filter.
- In the Comment box, enter the comment.
- Select Interface Specific to configure
interface-specific names for firewall counters.
|
Define a firewall filter term.
|
- Click Add new entry next to Term.
- Expand Term.
- In the Name box, enter the name that
identifies the term.
- In the Comment box, enter the comment
for the term.
- From the Filter list, select the
name that identifies the filter.
- Expand From.
- In the Comment box, enter the comment.
- In the Tcp Flags box, enter the Tcp
flags.
- From the listed protocol-independent match conditions,
select the filters defined for the Bridge family type.
The protocol-independent match conditions are Destination Mac
Address, Destination port, DSCP, Ether Type, Forwarding Class, ICMP
Code, ICMP Type, Interface Group, Ip Address, Ip Destination Address,
Ip Precedence, Ip Protocol, Ip Source Address, Learn Vlan 1p Priority,
Learn Vlan Id, Loss priority, Port, Source Mac Address, Source Port,
Traffic Type, User Vlan 1p Priority, User Vlan Id, and Vlan Ether
Type.
- Expand Then.
- In the Comment box, enter the comment
for then.
- In the Count box, enter the number
of packets.
- From the Loss Priority list, set
the packet loss priority (PLP) to low, medium-low, medium-high, or
high.
- In the Forwarding Class box, enter
the packet forwarding class name.
- Select Port Mirror check box to port
mirror the packets.
- Click Accept next to Then.
- Select Accept to accept a packet.
- Select Discard to discard a packet
silently, without sending an ICMP message.
- Select Next to evaluate the next
term in the firewall filter.
- Click Policer next to Then.
- Select Policer to configure a new
policer for each filter and select the policer name.
- Select three-color-policer to configure
a tricolor marking policer,
- Expand Three Color Policer.
- Click Single Rate next to Three Color
Policer.
- Select single-rate if the named tricolor
policer is a single-rate policer.
- Select two-rate if the named tricolor
policer is a two-rate policer.
|