We see an issue when applying firewall filters to dynamic profiles, when applied traffic if not funneled through the filter and therefore not applying. the placement of the filter is: set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" filter input 2Mb-policer
set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" filter output 5Mb-policer
the policer and filter are as follows:
set firewall policer 2Mb-policer if-exceeding bandwidth-limit 2m
set firewall policer 2Mb-policer if-exceeding burst-size-limit 500k
set firewall policer 2Mb-policer then discard
set firewall filter 2Mb-policer interface-specific
set firewall filter 2Mb-policer term TRAFFIC then policer 2Mb-police
set firewall filter 2Mb-policer term TRAFFIC then accept and the same for 5Mb.
Subscribers unable to login.
First changed to used correct filter variables.set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" family inet filter input "$junos-input-filter"set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" family inet filter output "$junos-output-filter"set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" family inet6 filter input "$junos-input-ipv6-filter"set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" family inet6 filter output "$junos-output-ipv6-filter"Second, I changed each of the FWF filters to use “interface-specific”brevaz@jnpr# run show configuration | compare rollback 2[edit firewall family inet filter 2Mb]+ interface-specific;[edit firewall family inet6 filter 6_2Mb]+ interface-specific;[edit firewall family inet6 filter 6_5Mb]+ interface-specific;Also, you will need the logical-interface-policer if you want the policer to be used as a combined value for IPV4/IPV6. As of now, each policer will treat traffic unique for IPv4 and IPv6.brevaz@NLTHHG1001LJ2# set firewall policer 2Mb-policer ?Possible completions:+ apply-groups Groups from which to inherit configuration data+ apply-groups-except Don't inherit configuration data from these groups filter-specific Policer is filter-specific> if-exceeding Define rate limits> if-exceeding-pps Define pps limits logical-bandwidth-policer Policer uses logical interface bandwidth logical-interface-policer Policer is logical interface policer physical-interface-policer Policer is physical interface policer shared-bandwidth-policer Share policer bandwidth among bundle links> then Action to take if the rate limits are exceededSeems to be working and the FWF is applied to the VLAN.brevaz@jnpr# run show subscribers routing-instance PROVIDER_RCOS extensive Type: VLANUser Name: jnprLogical System: defaultRouting Instance: PROVIDER_RCOSInterface: demux0.3221425002Interface type: DynamicUnderlying Interface: ae1Dynamic Profile Name: AUTO-QINQ-RCOSDynamic Profile Version: 17State: ActiveRadius Accounting ID: jnpr ae1.32767:201416Session ID: 201416PFE Flow ID: 200114Stacked VLAN Id: 0x8100.1201VLAN Id: 0x8100.334Login Time: 2024-01-12 18:20:55 UTCIPv4 Input Filter Name: 2Mb-demux0.3221425002-inIPv4 Output Filter Name: 2Mb-demux0.3221425002-outIPv6 Input Filter Name: 6_2Mb-demux0.3221425002-inIPv6 Output Filter Name: 6_5Mb-demux0.3221425002-outAccounting interval: 900Dynamic configuration: junos-input-filter: 2Mb junos-input-interface-filter: 2Mb-policer junos-input-ipv6-filter: 6_2Mb junos-output-filter: 2Mb junos-output-interface-filter: 5Mb-policer junos-output-ipv6-filter: 6_5MbType: DHCPUser Name: jnprIPv6 Address: x::xLogical System: defaultRouting Instance: PROVIDER_RCOSInterface: demux0.3221425003Interface type: DynamicUnderlying Interface: demux0.3221425002Dynamic Profile Name: DHCP-RCOSDynamic Profile Version: 13MAC Address: x.x.x.x.xState: ActiveRadius Accounting ID: jnpr demux0.3221425002:201417Session ID: 201417PFE Flow ID: 200116Stacked VLAN Id: 1201VLAN Id: 334Agent Circuit ID: QA-DSLAM eth 1/1/03/04Login Time: 2024-01-12 18:20:55 UTCDHCPV6 Options: len 4400 08 00 02 00 00 00 01 00 0a 00 03 00 01 1c df 0f 6f ed e000 06 00 04 00 17 00 18 00 03 00 0c 00 0f 00 01 00 00 00 0000 00 00 00DHCPV6 Header: len 4 01 89 77 edAccounting interval: 900Access Line Attributes: Agent Circuit ID: QA-DSLAM eth 1/1/03/04Type: DHCPUser Name: jnprIP Address: 139.92.249.101Logical System: defaultRouting Instance: PROVIDER_RCOSInterface: demux0.3221425005Interface type: DynamicUnderlying Interface: demux0.3221425002Dynamic Profile Name: DHCP-RCOSDynamic Profile Version: 13MAC Address: 1c:df:0f:6f:ed:f0State: ActiveDHCP Relay IP Address: 139.92.250.125Radius Accounting ID: jnpr demux0.3221425002:201419Session ID: 201419PFE Flow ID: 200118Stacked VLAN Id: 1201VLAN Id: 334Agent Circuit ID: QA-DSLAM eth 1/1/03/04Login Time: 2024-01-12 18:21:05 UTCDHCP Options: len 7335 01 01 39 02 04 b0 3d 20 00 63 69 73 63 6f 2d 31 63 64 662e 30 66 36 66 2e 65 64 66 30 2d 45 74 30 2f 31 2f 30 2e 3335 0c 0a 71 61 6c 61 62 5f 31 39 32 31 37 08 01 06 0f 2c 0321 96 2b 3c 08 63 69 73 63 6f 70 6e 70DHCP Header: len 4401 01 06 00 00 00 22 66 00 00 80 00 00 00 00 00 00 00 00 0000 00 00 00 00 00 00 00 1c df 0f 6f ed f0 00 00 00 00 00 0000 00 00 00Accounting interval: 900Access Line Attributes: Agent Circuit ID: QA-DSLAM eth 1/1/03/04VLAN interface:brevaz@jnpr# run show interfaces demux0.3221425002 extensive Logical interface demux0.3221425002 (Index 537071026) (SNMP ifIndex 200200114) (Generation 200081) Flags: Up VLAN-Tag [ 0x8100.1201 0x8100.334 ] Encapsulation: ENET2 Demux: Underlying interface: ae1 (Index 130) Link: xe-0/1/7 Bandwidth: 0 Traffic statistics: Input bytes : 14590 Output bytes : 19218 Input packets: 148 Output packets: 189 IPv6 transit statistics: Input bytes : 12194 Output bytes : 11084 Input packets: 135 Output packets: 87 Local statistics: Input bytes : 1658 Output bytes : 4160 Input packets: 12 Output packets: 28 Transit statistics: Input bytes : 12932 344 bps Output bytes : 15058 568 bps Input packets: 136 0 pps Output packets: 161 0 pps IPv6 transit statistics: Input bytes : 11828 344 bps Output bytes : 9004 568 bps Input packets: 133 0 pps Output packets: 65 0 pps Protocol inet, MTU: 9078 Max nh cache: 0, New hold nh limit: 0, Curr nh cnt: 0, Curr new hold cnt: 0, NH drop cnt: 0 Generation: 0, Route table: 8 Flags: Unnumbered Donor interface: lo0.3 (Index 333) Input Filters: 2Mb-demux0.3221425002-in Output Filters: 2Mb-demux0.3221425002-out Addresses, Flags: Is-Primary Destination: Unspecified, Local: x.x.x.x, Broadcast: Unspecified, Generation: 0 Protocol inet6, MTU: 9078 Max nh cache: 0, New hold nh limit: 0, Curr nh cnt: 0, Curr new hold cnt: 0, NH drop cnt: 0 Generation: 0, Route table: 8 Flags: Unnumbered Donor interface: lo0.3 (Index 333) Input Filters: 6_2Mb-demux0.3221425002-in Output Filters: 6_5Mb-demux0.3221425002-out Addresses, Flags: Is-Primary
Destination: Unspecified, Local: 2001:1be0:e080:f100::32
Generation: 0
Destination: Unspecified, Local: fe80::c609:b7ff:feb3:8f54
Protocol pppoe, Generation: 0
Dynamic Profile: jnpr-PPPOE,
Service Name Table: None,
Max Sessions: 5, Max Sessions VSA Ignore: Off,
Duplicate Protection: On, Short Cycle Protection: Off,
Direct Connect: Off,
AC Name: jnpr
Generation: 0, Route table: 65535
Addresses, Flags: None
Destination: Unspecified, Local: Unspecified, Broadcast: Unspecified, Generation: 0