http://2526575.blog.51cto.com/2516575/999621
juniper srx240,版本12.1R2.9
对某个ip流量控制:(192.168.200.200)
set firewall policer policer-one if-exceeding bandwidth-limit 50k
set firewall policer policer-one if-exceeding burst-size-limit 50k
#最小为3000b
set firewall policer policer-one then discard
set firewall filter rate-limit term 1 from source-address 192.168.200.200/32
set firewall filter rate-limit term 1 from destination-address 0.0.0.0/0
set firewall filter rate-limit term 1 from source-port 0-65535
set firewall filter rate-limit term 1 from destination-port 0-65535
set firewall filter rate-limit term 1 then policer policer-one
set interfaces vlan unit 200 family inet filter input rate-limit #下载
set interfaces vlan unit 200 family inet filter output rate-limit #上传
流量限制相关配置
配置命令:
set firewall policer 1k-policy if-exceeding bandwidth-limit 1m 允许特定IP通过的带宽值(1k-policy为策略的名称)
set firewall policer 1k-policy if-exceeding burst-size-limit 100k (一个包的长度限制,超过将不会通过防火墙)
set firewall policer 1k-policy then discard 超过流量限制的报文将丢弃
set firewall family inet filter 1K term 1 from source-address 192.168.0.159/32 (可选条件,1K为过滤模板的名称)
set firewall family inet filter 1K term 1 from destination-address XX.XX.XX.XXX/24 (可选条件)
set firewall family inet filter 1K term 1 from protocol tcp (可选条件)
set firewall family inet filter 1K term 1 then policer 1k-policy
set firewall family inet filter 1K term 2 then accept
set interfaces fe-0/0/7 unit 0 family inet filter input 1K 在接口下的入方向启用
查看是否匹配到流量:
show firewall filter 1K