I would like to do the same thing described in this article, except with an SRX:
[MX] Example: Configuring a layer2-policer for rate limiting on a physical port in Access Mode
The trouble is that when I try to do the equivalent of this line:
set interfaces ge-1/3/9 unit 0 filter input TEST-L2-POLICER
...there is no "filter" argument available just under the "unit" level. Here's what happens when I try:
"[edit interfaces fe-0/0/2 unit 0]
root@meadowlark-fw# set fil[hitting tab here]
^
unknown command."
I've added filter and policer stuff to other parts of the configuration. Commit works, but the rate limit doesn't ever seem to trigger when testing it. Some excerpts of things I've already set:
interfaces {
fe-0/0/2 {
unit 0 {
family bridge {
filter {
input filter-56k;
output filter-56k;
}
policer {
input policer-56k;
output policer-56k;
}
interface-mode access;
vlan-id 1;
}
}
}
}
firewall {
family bridge {
filter filter-56k {
term 1 {
then {
policer policer-56k;
count policer-56k-packets;
}
}
}
}
policer policer-56k {
if-exceeding {
bandwidth-limit 56k;
burst-size-limit 100k;
}
then discard;
}
}
Advice appreciated!