[j-nsp] problem with policer
Rafał Szarecki
rszarecki at gmail.com
Sat Jan 6 06:04:23 EST 2007
Can You configure firewall filters: family inet matching any packet with
actions : policer 350m; count; accept;
and apply them on ae if on output.
Do U have MPLS on this intrface? If so add dame filter for family mpls.
The name of policer 350m-ae1.514-log_int-o, looks strange... I do not expect
"log_"...
Look at chassisd log and messages during commiting.
What is HW platform and is this ae interface is in VRF?
Full config can be usefull, to understand context.
open JTAC case.
rafal
2007/1/5, Lukasz Trabinski <lukaszt at atm.com.pl>:
>
> Hello
>
> We have strange problem with policer on etherchannel interface
>
> There is configuration
>
> lukasz at r2-re1> ...cal-routers tpnet interfaces ae1 unit 514
>
> description "xxx [cat5-d13:Gi2/0/1] xxx";
> vlan-id 514;
> family inet {
> policer {
> input 175m;
> output 350m;
> }
> address xxx.xxx.xx.xxx/30;
> }
>
>
> lukasz at r2-re1> show configuration firewall policer 350m
> logical-interface-policer;
> if-exceeding {
> bandwidth-limit 350m;
> burst-size-limit 650k;
> }
> then discard;
>
>
> below is output from show interfaces ae1.514 extensive:
>
>
> lukasz at r2-re1> show interfaces ae1.514 extensive
> Logical interface ae1.514 (Index 127) (SNMP ifIndex 621) (Generation
> 194)
> Description: xxx [cat5-d13:Gi2/0/1] xxx
> Flags: SNMP-Traps VLAN-Tag [ 0x8100.514 ] Encapsulation: ENET2
> Statistics Packets pps Bytes bps
> Bundle:
> Input : 49652726334 98080 16305656634443 206869120
> Output: 56668694351 111049 28066800393407 428369072
> Link:
> ge-4/0/0.514
> Input : 12364812455 24467 4048362723330 51926808
> Output: 14187994897 28442 7017873295930 110316088
> ge-4/0/4.514
> Input : 12414159614 24601 4077845428268 52018640
> Output: 14150801027 27720 6992847311403 107773872
> ge-4/1/4.514
> Input : 12466507576 24949 4117274836674 52820680
> Output: 14170174949 27322 7043901269464 99596368
> ge-4/1/5.514
> Input : 12407246689 24063 4062173646171 50102992
> Output: 14159723478 27565 7012178516610 110682744
> Marker Statistics: Marker Rx Resp Tx Unknown Rx Illegal Rx
> ge-4/0/0.514 0 0 0 0
> Marker Statistics: Marker Rx Resp Tx Unknown Rx Illegal Rx
> ge-4/0/0.514 0 0 0 0
> ge-4/0/4.514 0 0 0 0
> ge-4/1/4.514 0 0 0 0
> ge-4/1/5.514 0 0 0 0
> Protocol inet, MTU: 1500, Generation: 224, Route table: 6
> Flags: None
> Filters: Input: sampling, Output: sampling
> Policer: Input: 175m-ae1.514-inet-i, Output: 350m-ae1.514-log_int-o
> Addresses, Flags: Is-Preferred Is-Primary
> Destination: xxx.xxx.xx.xxx/30, Local: xxx.xxx.xx.xx,
> Broadcast: xxx.xxx.xxx.xxx, Generation: 349
>
>
> when we check policer, we can see that policer on output doesn't work
>
>
> lukasz at r2-re1> show policer 350m-ae1.514-log_int-o
> Policers:
> Name Packets
> 350m-ae1.514-log_int-o 0
>
> lukasz at r2-re1> show policer 175m-ae1.514-inet-i
> Policers:
> Name Packets
> 175m-ae1.514-inet-i 900429573
>
>
> Any idea, bug soft, wrong configuration?
>
>
> lukasz at r2-re1> show version
> Hostname: r2-re1
> Model: m320
> JUNOS Base OS boot [8.0R2.8]
> JUNOS Base OS Software Suite [8.0R2.8]
> JUNOS Kernel Software Suite [8.0R2.8]
> JUNOS Packet Forwarding Engine Support (M320) [8.0R2.8]
> JUNOS Routing Software Suite [8.0R2.8]
> JUNOS Online Documentation [8.0R2.8]
> JUNOS Crypto Software Suite [8.0R2.8]
>
>
>
> --
> Lukasz Trabinski
> _______________________________________________
> juniper-nsp mailing list juniper-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/juniper-nsp
>
--
Rafał Szarecki JNCIE
+48602418971
More information about the juniper-nsp
mailing list