This article describes the three options to monitor firewall filter traffic on EX-series switches.
Three options for monitoring firewall filter traffic on the EX-series Switch
Perform the following task to monitor the number of packets and bytes that matched the firewall filters and monitor the number of packets that exceeded policer rate limits: Action
user@switch> show firewall Filter: egress-vlan-watch-employee // (filter-name) Counters: Name Bytes Packets counter-employee-web 3348 27 Filter: ingress-port-voip-class-limit-tcp-icmp Counters: Name Bytes Packets icmp-counter 4100 49 Policers: Name Packets icmp-connection-policer 0 tcp-connection-policer 0 Filter: ingress-vlan-rogue-block Filter: ingress-vlan-limit-guest
Monitoring Traffic for a Specific Firewall Filter : Perform the following task to monitor the number of packets and bytes that matched a firewall filter and monitor the number of packets that exceeded the policer rate limits.
Monitoring Traffic for a Specific Policer
user@switch> show policer <policers-name> (In that example - tcp-connection-policer) Filter: ingress-port-voip-class-limit-tcp-icmp Policers: Name Packets tcp-connection-policer 0