Verify Enhanced Hierarchical Policer Configuration
Purpose
To verify the configuration and operational status of firewall filters, policers, and counters applied to dynamic subscriber sessions. This helps confirm that the enhanced hierarchical policer and firewall filters are correctly applied and functioning on subscriber interfaces and sessions.
Action
Use the show subscribers firewall command to view the results.
show subscribers firewall
Filter: __junos_adf_23-pp0.3221225490-inet-in
Filter: __junos_adf_23-pp0.3221225490-inet6-in
Filter: v4-DT-DP_UID1094-pp0.3221225490-in
Counters:
Name Bytes Packets
_implct_hpolicer-in_UID1092-High-pp0.3221225490-in 303237200 216598
implct_hpolicer-in_UID1092-Medium-High-pp0.3221225490-in 0 0
implct_hpolicer-in_UID1092-Medium-Low-pp0.3221225490-in 0 0
_implct_hpolicer-in_UID1092-Low-pp0.3221225490-in 227685335 162636
Enhanced Hierarchical Policers:
Name Bytes Packets
High 123935000 88525
Medium-High 0 0
Medium-Low 0 0
Low 47866000 34190
Filter: v6-DT-DP_UID1098-pp0.3221225490-in
Counters:
Name Bytes Packets
_implct_hpolicer-in_UID1092-High-pp0.3221225490-in 303237200 216598
implct_hpolicer-in_UID1092-Medium-High-pp0.3221225490-in 0 0
implct_hpolicer-in_UID1092-Medium-Low-pp0.3221225490-in 0 0
_implct_hpolicer-in_UID1092-Low-pp0.3221225490-in 227685335 162636
Enhanced Hierarchical Policers:
Name Bytes Packets
High 123935000 88525
Medium-High 0 0
Medium-Low 0 0
Low 47866000 34190 Meaning
The output indicates which firewall filters and policers are active on subscriber sessions, the amount of traffic matched or dropped by these filters, and the counters associated with each filter term.
If you do not configure a counter for the enhanced hierarchical policer, the system displays implicit counter statistics as shown in the output above.