<html>
At 05:12 PM 1/15/2003, Jonathan
Tse wrote:<br>
<blockquote type=cite class=cite cite>Hi
Josef,<br><br>
just to double confirm. meaning
i can police up to 65536 hosts
per router if<br>
the destination-prefix-length
is /32?</blockquote><br>
Jonathan,<br><br>
the primarily restriction in
the number of policers comes
from the space<br>
of memory you have. If you have
an M20 with IPII
<font face="Arial, Helvetica" size=4>SSB-E-M20
you have<br>
</font>8Mbyte on DRAM on the
lookup Asic ( Internet
Processor II). Since the filter
programs and the<br>
active routes do share the same
memory you can run 400k
*active* routes<br>
and 65k policers. Please keep
in mind that every host in this
example<br>
gets its own policer. This is
the reason why the cli
restricted the amount<br>
of policers to a full class B
subnet. I would assume this is
already<br>
a lot and should meet most of
the requirements ....<br><br>
But if you have installed
SSB-E-16-M20 which is the
16Mbyte on DRAM<br>
which requires version 5.5 and
higher you can certainly
increase the<br>
number of policers extensively
more. <br><br>
<br>
hope this helps<br>
Josef<br><br>
<br><br>
<br>
<blockquote type=cite class=cite cite>regards,<br>
Jonathan.<br><br>
----- Original Message
-----<br>
From: &quot;Josef
Buchsteiner&quot;
&lt;josefb@juniper.net&gt;<br>
To: &quot;Jonathan Tse&quot;
&lt;jonathantse@pacific.net.sg&gt;;<br>
&lt;juniper-nsp@puck.nether.net&gt;<br>
Sent: Wednesday, January 15,
2003 11:56 PM<br>
Subject: Re: [j-nsp]
Prefix-Specific 
Action<br><br>
<br>
&gt; At 12:56 PM 1/15/2003,
Jonathan Tse wrote:<br>
&gt; &gt;Thanks Josef,<br>
&gt; &gt;<br>
&gt; &gt;Your explanation is
crystal clear! May be the
manual should follow your<br>
&gt; &gt;instead :)<br>
&gt; &gt;<br>
&gt; &gt;Is there any hardware
requirement like FPC-II to
enable such feature and<br>
how<br>
&gt; &gt;many subnet that a M20
can handle?<br>
&gt;<br>
&gt; If you use a /16 subnet
and you want to police on a
/32<br>
&gt;
destination-prefix-length<br>
&gt; you basically use 65536
policers which is the current
maximum you can<br>
configure<br>
&gt; for one subnet. You will
get a warning message in the
cli when you try to<br>
go<br>
&gt; beyond this number.<br>
&gt;<br>
&gt;<br>
&gt; thanks<br>
&gt; Josef<br>
&gt;<br>
&gt;<br>
&gt; &gt;Million thanks!<br>
&gt; &gt;Jonathan.<br>
&gt; &gt;<br>
&gt; &gt;----- Original Message
-----<br>
&gt; &gt;From: &quot;Josef
Buchsteiner&quot;
&lt;josefb@juniper.net&gt;<br>
&gt; &gt;To: &quot;Jonathan
Tse&quot;
&lt;jonathantse@pacific.net.sg&gt;;<br>
&gt;
&gt;&lt;juniper-nsp@puck.nether.net&gt;<br>
&gt; &gt;Sent: Wednesday,
January 15, 2003 7:38 PM<br>
&gt; &gt;Subject: Re: [j-nsp]
Prefix-Specific Action<br>
&gt; &gt;<br>
&gt; &gt;<br>
&gt; &gt; &gt; At 12:43 AM
1/15/2003, Jonathan Tse
wrote:<br>
&gt; &gt; &gt; &gt;Hi
Josef,<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt;that is
cool! lots of people would love
it! one more question: if
two<br>
&gt; &gt; &gt; &gt;interfaces
shares the same filter with
prefix-specific action
being<br>
used<br>
&gt; &gt; &gt; &gt;(let's say
1Mbps per /32 in a /24), does
the policy shape the
traffic<br>
per<br>
&gt; &gt; &gt; &gt;interface
(meaning max 1Mbps each
interface for that /32) 
or<br>
regardless<br>
&gt; &gt;of<br>
&gt; &gt; &gt; &gt;the number
of interfaces (meaning total
1Mbps thru the above two<br>
&gt; &gt;interfaces<br>
&gt; &gt; &gt; &gt;for that
/32)?<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; Jonathan,<br>
&gt; &gt;
&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
the prefix-specific is done per
address not per 
interface.<br>
&gt; &gt; &gt; i.e. you want to
police all http traffic to
certain host in /24 
subnet<br>
&gt; &gt;where<br>
&gt; &gt; &gt; all the host are
in a /30 range you do this for
all your host<br>
regardless<br>
&gt; &gt; &gt; of the
interface. You still can add an
interface-policer which
police<br>
&gt; &gt; &gt; at the aggregate
level for a specific interface.
Given the example<br>
above<br>
&gt; &gt; &gt; you could
also<br>
&gt; &gt; &gt; say that all the
http traffic to each hosts
should be 500kbps but the<br>
&gt; &gt;total<br>
&gt; &gt; &gt; of all http
traffic should never go higher
then 1Mbps which can be<br>
&gt; &gt;accomplished<br>
&gt; &gt; &gt; with the next
term statement ( aka multilevel
policer ... )<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; thanks<br>
&gt; &gt; &gt; Josef<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt;<br>
&gt; &gt; &gt; 
&gt;thanks!<br>
&gt; &gt; &gt;
&gt;Jonathan.<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt;-----
Original Message -----<br>
&gt; &gt; &gt; &gt;From:
&quot;Josef Buchsteiner&quot;
&lt;josefb@juniper.net&gt;<br>
&gt; &gt; &gt; &gt;To:
&quot;Jonathan Tse&quot;
&lt;jonathantse@pacific.net.sg&gt;;<br>
&gt; &gt; &gt;
&gt;&lt;juniper-nsp@puck.nether.net&gt;<br>
&gt; &gt; &gt; &gt;Sent:
Wednesday, January 15, 2003
4:25 AM<br>
&gt; &gt; &gt; &gt;Subject: Re:
[j-nsp] Prefix-Specific
Action<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt; &gt; At
05:31 AM 1/14/2003, Jonathan
Tse wrote:<br>
&gt; &gt; &gt; &gt; &gt;
&gt;Hi,<br>
&gt; &gt; &gt; &gt; &gt;
&gt;<br>
&gt; &gt; &gt; &gt; &gt;
&gt;Any idea what is this
Prefix-Specific Action
for?<br>
&gt; &gt; &gt; &gt; &gt;
&gt;<br>
&gt; &gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt;<br>
&gt;<a href="http://www.juniper.net/techpubs/software/junos/junos56/swconfig56-policy/ht" eudora="autourl">http://www.juniper.net/techpubs/software/junos/junos56/swconfig56-policy/ht</a><br>
&gt; &gt; &gt; &gt;m<br>
&gt; &gt; &gt; &gt; &gt;
&gt;l/policer-config9.html#1046287<br>
&gt; &gt; &gt; &gt; &gt;
&gt;<br>
&gt; &gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt;<br>
&gt;<a href="http://www.juniper.net/techpubs/software/junos/junos56/swconfig56-policy/ht" eudora="autourl">http://www.juniper.net/techpubs/software/junos/junos56/swconfig56-policy/ht</a><br>
&gt; &gt; &gt; &gt;m<br>
&gt; &gt; &gt; &gt; &gt;
&gt;l/policer-config10.html#1046825<br>
&gt; &gt; &gt; &gt; &gt;
&gt;<br>
&gt; &gt; &gt; &gt; &gt; &gt;In
layman's term, is it for
policing individual address
(like<br>
1Mbps<br>
&gt; &gt;per<br>
&gt; &gt; &gt; &gt;/32)<br>
&gt; &gt; &gt; &gt; &gt;
&gt;within a given prefixes
(/24)?<br>
&gt; &gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt; &gt; this
is exactly what the motivation
is as you stated<br>
&gt; &gt; &gt; &gt; &gt; to
police on a more granular
level<br>
&gt; &gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt; &gt;
regards<br>
&gt; &gt; &gt; &gt; &gt;
Josef<br>
&gt; &gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt; &gt;
&gt;Thanks,<br>
&gt; &gt; &gt; &gt; &gt;
&gt;Jonathan Tse<br>
&gt; &gt; &gt; &gt; &gt;
&gt;Senior Network Engineer,
Pacific Internet -
Singapore<br>
&gt; &gt; &gt; &gt; &gt;
&gt;NOC: +65 6872-1010 DID: +65
6771-0843 FAX: +65
6872-6674<br>
&gt; &gt; &gt; &gt; &gt;
&gt;<br>
&gt; &gt; &gt; &gt; &gt;
&gt;_______________________________________________<br>
&gt; &gt; &gt; &gt; &gt;
&gt;juniper-nsp mailing list
juniper-nsp@puck.nether.net<br>
&gt; &gt; &gt; &gt; &gt;
&gt;<a href="http://puck.nether.net/mailman/listinfo/juniper-nsp" eudora="autourl">http://puck.nether.net/mailman/listinfo/juniper-nsp</a><br>
&gt; &gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt; &gt;<br>
&gt; &gt; &gt;
&gt;_______________________________________________<br>
&gt; &gt; &gt; &gt;juniper-nsp
mailing list
juniper-nsp@puck.nether.net<br>
&gt; &gt; &gt;
&gt;<a href="http://puck.nether.net/mailman/listinfo/juniper-nsp" eudora="autourl">http://puck.nether.net/mailman/listinfo/juniper-nsp</a><br>
&gt; &gt; &gt;<br>
&gt; &gt;<br>
&gt;
&gt;_______________________________________________<br>
&gt; &gt;juniper-nsp mailing
list
juniper-nsp@puck.nether.net<br>
&gt;
&gt;<a href="http://puck.nether.net/mailman/listinfo/juniper-nsp" eudora="autourl">http://puck.nether.net/mailman/listinfo/juniper-nsp</a><br>
&gt;<br>
&gt;
_______________________________________________<br>
&gt; juniper-nsp mailing list
juniper-nsp@puck.nether.net<br>
&gt;
<a href="http://puck.nether.net/mailman/listinfo/juniper-nsp" eudora="autourl">http://puck.nether.net/mailman/listinfo/juniper-nsp</a><br>
&gt;<br><br>
_______________________________________________<br>
juniper-nsp mailing list
juniper-nsp@puck.nether.net<br>
<a href="http://puck.nether.net/mailman/listinfo/juniper-nsp" eudora="autourl">http://puck.nether.net/mailman/listinfo/juniper-nsp</a></blockquote></html>