This article explains the working conditions and limitations of policer configurations applied to lo0 and VLAN interfaces in EX legacy platforms.
The legacy platforms affected by this configuration are
EX4200
EX45xx
EX3200
How to tell if limitations apply:
When applied on IRB or VLAN interface, the configuration will only work for transit traffic from Junos 14.1X53-D40 and later releases
Error message:
root# commit [edit interfaces lo0 unit 0 family inet] 'filter' Referenced filter 'hostbound-policer-filter' can not be used as policer not supported on ingress loopback interface
error: configuration check-out failed
set firewall family inet filter hostbound-policer-filter term 1 from protocol icmp set firewall family inet filter hostbound-policer-filter term 1 from icmp-type echo-request set firewall family inet filter hostbound-policer-filter term 1 from icmp-type echo-reply set firewall family inet filter hostbound-policer-filter term 1 then policer policer-32k set firewall family inet filter hostbound-policer-filter term 1 then count 1-icmp-counter set firewall family inet filter hostbound-policer-filter term 1 then log >>>>> Will not work set firewall family inet filter hostbound-policer-filter term 1 then syslog >>>>>Will not work set firewall policer policer-32k if-exceeding bandwidth-limit 32k set firewall policer policer-32k if-exceeding burst-size-limit 1k set firewall policer policer-32k then discard
The above policer configuration will police traffic only for transit traffic. These are the current limitations; there is no fix.