[j-nsp] inbound policing

Jeff Wheeler jeff at reflected.net
Mon Aug 30 09:41:54 EDT 2004


On Mon, 2004-08-30 at 06:33, Przemekk wrote:
> -- Hello There,
> I've noticed (via snmp/mrtg) that input rate on the interface exceeds
> the rate i've set.

You are probably polling layer 2 ethernet port tx/rx octet counters,
while the IP-II is policing traffic based on layer 3 packet size.  I do
not believe the IP-II has knowledge of what the packet will look like in
the egress interface's layer 2 protocol, because that framing is done on
the PIC when the packet is ready to be transmitted.

-- 
Jeff at Reflected Networks



More information about the juniper-nsp mailing list