Junos
Junos

firewall policier restrict bandwidth, "discard" vs "loss priority"

‎09-05-2019 09:25 PM

I need to restrict the bandwidth of one of the interface. A firewall policier will set like below

# set firewall policer policer-1mb if-exceeding bandwidth-limit 1m
# set firewall policer policer-1mb if-exceeding burst-size-limit 625000
# set firewall policer policer-1mb then discard

According to the help explanation. "discard" mean discard the packet. Is that mean the current connection will interrupt?

Lets say the user download file from google drive with extreme high speed. As the interface connected to that user's PC was restricted to 1Mbps. Will the download speed lower to 1Mbps or all the connection to that interface will interrupt?

4 REPLIES 4
Junos
Solution
Accepted by topic author jlotag
‎09-10-2019 12:39 AM

Re: firewall policier restrict bandwidth, "discard" vs "loss priority"

‎09-06-2019 02:45 AM

Hi Jlotag,

 

Answering to your query, if you apply the policing to an interface without any firewall filter specifying the Source IP and Destination IP then it will restrict the bandwidth to 1 Mbps for all the traffic coming towards that interface.



Thanks,
π00bm@$t€®.
Please, Mark My Solution Accepted if it Helped, Kudos are Appreciated too!!!
Junos

Re: firewall policier restrict bandwidth, "discard" vs "loss priority"

‎09-08-2019 10:43 PM

Thanks noobmaster. Restrict all traffic to have only 1Mbps on an interface is what I need. I just need to make sure "discard" doesn't mean block/disconnect the traffic.

Do you know the effect of "loss priority"?

Junos

Re: firewall policier restrict bandwidth, "discard" vs "loss priority"

‎09-08-2019 11:20 PM

Hi jlotag, 

 

You may wish to refere to the following techpub document to understand loss-ppriority:- 

In a nutshell,  it defines prioritizing what traffic to be dropped.

 

Defination:-

https://www.juniper.net/documentation/en_US/junos/topics/concept/cos-packet-loss-priority-understand...

Example:-

https://www.juniper.net/documentation/en_US/junos/topics/example/cos-behavior-aggregate-classifier-c...

 

-Rahul

Regards,
Rahul
Junos

Re: firewall policier restrict bandwidth, "discard" vs "loss priority"

‎09-10-2019 12:40 AM

Hello ScreenJun. Thanks for the tips. Seems that "loss priority" is the advanced version of "discard". I'm going to try the "discard" action first.