1. 程式人生 > >juniper設定流量控制(下載和上傳)

juniper設定流量控制(下載和上傳)

流量限制相關配置
 
配置命令:
set firewall policer 1k-policy if-exceeding bandwidth-limit 1m 允許特定IP通過的頻寬值(1k-policy為策略的名稱)
set firewall policer 1k-policy if-exceeding burst-size-limit 100k (一個包的長度限制,超過將不會通過防火牆)
set firewall policer 1k-policy then discard 超過流量限制的報文將丟棄
 
set firewall family inet filter 1K term 1 from source-address 192.168.0.159/32 (可選條件,1K為過濾模板的名稱)
set firewall family inet filter 1K term 1 from destination-address XX.XX.XX.XXX/24 (可選條件)
set firewall family inet filter 1K term 1 from protocol tcp (可選條件)
set firewall family inet filter 1K term 1 then policer 1k-policy
set firewall family inet filter 1K term 2 then accept
set interfaces fe-0/0/7 unit 0 family inet filter input 1K 在介面下的入方向啟用
 
檢視是否匹配到流量:
show firewall filter 1K