Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Example: Configuring VPLS Filters


This example shows how to configure VPLS filters.


Before you begin:


This example describes how to configure filtering and accounting for VPLS.


MPLS is disabled by default on SRX Series devices. You must explicitly configure your device to allow MPLS traffic. However, when MPLS is enabled, all flow-based security features are deactivated and the device performs packet-based processing. Flow-based services such as security policies, zones, NAT, ALGs, chassis clustering, screens, firewall authentication, and IPsec VPNs are unavailable on the device.


CLI Quick Configuration

To quickly configure VPLS filters, copy the following commands, paste them into a text file, remove any line breaks, change any details necessary to match your network configuration, copy and paste the commands into the CLI at the [edit] hierarchy level, and then enter commit from configuration mode.

Step-by-Step Procedure

To configure filters for VPLS:

  1. Configure a filter with a GE interface as the match condition and count as the action.
  2. Configure a filter with an FE interface as the match condition and count as the action.
  3. Configure the count.
  4. Configure the accounting profile to refer it to the counter.
  5. Configure the account file size.
  6. Configure the account transfer interval.
  7. Configure the filter for the accounting profile.
  8. Configure the filter for the interval.
  9. Configure the counter.
  10. Apply the filter to the interface.
  11. If you are done configuring the device, commit the configuration.


To verify the configuration is working properly, enter the show firewall and show accounting records commands.