Description

We see an issue when applying firewall filters to dynamic profiles, when applied traffic if not funneled through the filter and therefore not applying. the placement of the filter is: set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" filter input 2Mb-policer

set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" filter output 5Mb-policer

the policer and filter are as follows:

set firewall policer 2Mb-policer if-exceeding bandwidth-limit 2m

set firewall policer 2Mb-policer if-exceeding burst-size-limit 500k

set firewall policer 2Mb-policer then discard

set firewall filter 2Mb-policer interface-specific

set firewall filter 2Mb-policer term TRAFFIC then policer 2Mb-police

set firewall filter 2Mb-policer term TRAFFIC then accept and the same for 5Mb.

Symptoms

Subscribers unable to login.

Solution

First changed to used correct filter variables.

set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" family inet filter input "$junos-input-filter"
set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" family inet filter output "$junos-output-filter"
set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" family inet6 filter input "$junos-input-ipv6-filter"
set dynamic-profiles AUTO-QINQ-RCOS interfaces demux0 unit "$junos-interface-unit" family inet6 filter output "$junos-output-ipv6-filter"

Second, I changed each of the FWF filters to use “interface-specific”

brevaz@jnpr# run show configuration | compare rollback 2
[edit firewall family inet filter 2Mb]
+    interface-specific;
[edit firewall family inet6 filter 6_2Mb]
+    interface-specific;
[edit firewall family inet6 filter 6_5Mb]
+    interface-specific;


Also, you will need the logical-interface-policer if you want the policer to be used as a combined value for IPV4/IPV6. As of now, each policer will treat traffic unique for IPv4 and IPv6.

brevaz@NLTHHG1001LJ2# set firewall policer 2Mb-policer ?
Possible completions:
+ apply-groups        Groups from which to inherit configuration data
+ apply-groups-except Don't inherit configuration data from these groups
 filter-specific     Policer is filter-specific
> if-exceeding        Define rate limits
> if-exceeding-pps    Define pps limits
 logical-bandwidth-policer Policer uses logical interface bandwidth
  logical-interface-policer Policer is logical interface policer
 physical-interface-policer Policer is physical interface policer
 shared-bandwidth-policer Share policer bandwidth among bundle links
> then                Action to take if the rate limits are exceeded


Seems to be working and the FWF is applied to the VLAN.

brevaz@jnpr# run show subscribers routing-instance PROVIDER_RCOS extensive          
Type: VLAN
User Name: jnpr
Logical System: default
Routing Instance: PROVIDER_RCOS
Interface: demux0.3221425002
Interface type: Dynamic
Underlying Interface: ae1
Dynamic Profile Name: AUTO-QINQ-RCOS
Dynamic Profile Version: 17
State: Active
Radius Accounting ID: jnpr ae1.32767:201416
Session ID: 201416
PFE Flow ID: 200114
Stacked VLAN Id: 0x8100.1201
VLAN Id: 0x8100.334
Login Time: 2024-01-12 18:20:55 UTC
IPv4 Input Filter Name: 2Mb-demux0.3221425002-in
IPv4 Output Filter Name: 2Mb-demux0.3221425002-out
IPv6 Input Filter Name: 6_2Mb-demux0.3221425002-in
IPv6 Output Filter Name: 6_5Mb-demux0.3221425002-out
Accounting interval: 900
Dynamic configuration:
  junos-input-filter: 2Mb
 junos-input-interface-filter: 2Mb-policer
 junos-input-ipv6-filter: 6_2Mb
 junos-output-filter: 2Mb
 junos-output-interface-filter: 5Mb-policer
 junos-output-ipv6-filter: 6_5Mb

Type: DHCP
User Name: jnpr
IPv6 Address: x::x
Logical System: default
Routing Instance: PROVIDER_RCOS
Interface: demux0.3221425003
Interface type: Dynamic
Underlying Interface: demux0.3221425002
Dynamic Profile Name: DHCP-RCOS
Dynamic Profile Version: 13
MAC Address: x.x.x.x.x
State: Active
Radius Accounting ID: jnpr demux0.3221425002:201417
Session ID: 201417
PFE Flow ID: 200116
Stacked VLAN Id: 1201
VLAN Id: 334
Agent Circuit ID: QA-DSLAM eth 1/1/03/04
Login Time: 2024-01-12 18:20:55 UTC
DHCPV6 Options: len 44
00 08 00 02 00 00 00 01 00 0a 00 03 00 01 1c df 0f 6f ed e0
00 06 00 04 00 17 00 18 00 03 00 0c 00 0f 00 01 00 00 00 00
00 00 00 00
DHCPV6 Header: len 4                   
01 89 77 ed
Accounting interval: 900
Access Line Attributes:
 Agent Circuit ID: QA-DSLAM eth 1/1/03/04

Type: DHCP
User Name: jnpr
IP Address: 139.92.249.101
Logical System: default
Routing Instance: PROVIDER_RCOS
Interface: demux0.3221425005
Interface type: Dynamic
Underlying Interface: demux0.3221425002
Dynamic Profile Name: DHCP-RCOS
Dynamic Profile Version: 13
MAC Address: 1c:df:0f:6f:ed:f0
State: Active
DHCP Relay IP Address: 139.92.250.125
Radius Accounting ID: jnpr demux0.3221425002:201419
Session ID: 201419
PFE Flow ID: 200118
Stacked VLAN Id: 1201
VLAN Id: 334
Agent Circuit ID: QA-DSLAM eth 1/1/03/04
Login Time: 2024-01-12 18:21:05 UTC
DHCP Options: len 73
35 01 01 39 02 04 b0 3d 20 00 63 69 73 63 6f 2d 31 63 64 66
2e 30 66 36 66 2e 65 64 66 30 2d 45 74 30 2f 31 2f 30 2e 33
35 0c 0a 71 61 6c 61 62 5f 31 39 32 31 37 08 01 06 0f 2c 03
21 96 2b 3c 08 63 69 73 63 6f 70 6e 70
DHCP Header: len 44
01 01 06 00 00 00 22 66 00 00 80 00 00 00 00 00 00 00 00 00
00 00 00 00 00 00 00 00 1c df 0f 6f ed f0 00 00 00 00 00 00
00 00 00 00
Accounting interval: 900
Access Line Attributes:
 Agent Circuit ID: QA-DSLAM eth 1/1/03/04



VLAN interface:

brevaz@jnpr# run show interfaces demux0.3221425002 extensive   
  Logical interface demux0.3221425002 (Index 537071026) (SNMP ifIndex 200200114) (Generation 200081)
   Flags: Up VLAN-Tag [ 0x8100.1201 0x8100.334 ] Encapsulation: ENET2
   Demux:
     Underlying interface: ae1 (Index 130)
   Link:
     xe-0/1/7
   Bandwidth: 0
   Traffic statistics:
    Input bytes :               14590
    Output bytes :               19218
    Input packets:                 148
    Output packets:                 189
    IPv6 transit statistics:
    Input bytes :               12194
    Output bytes :               11084
    Input packets:                 135
    Output packets:                  87
   Local statistics:
    Input bytes :                1658
    Output bytes :                4160
    Input packets:                  12
    Output packets:                  28
   Transit statistics:
    Input bytes :               12932                 344 bps
    Output bytes :               15058                 568 bps
    Input packets:                 136                   0 pps
    Output packets:                 161                   0 pps
    IPv6 transit statistics:
     Input bytes :              11828                 344 bps
     Output bytes :               9004                 568 bps
     Input packets:                133                   0 pps
     Output packets:                 65                   0 pps
   Protocol inet, MTU: 9078
   Max nh cache: 0, New hold nh limit: 0, Curr nh cnt: 0, Curr new hold cnt: 0, NH drop cnt: 0
   Generation: 0, Route table: 8
     Flags: Unnumbered
     Donor interface: lo0.3 (Index 333)
      Input Filters: 2Mb-demux0.3221425002-in
     Output Filters: 2Mb-demux0.3221425002-out
     Addresses, Flags: Is-Primary
       Destination: Unspecified, Local: x.x.x.x, Broadcast: Unspecified, Generation: 0
   Protocol inet6, MTU: 9078
   Max nh cache: 0, New hold nh limit: 0, Curr nh cnt: 0, Curr new hold cnt: 0, NH drop cnt: 0
   Generation: 0, Route table: 8
     Flags: Unnumbered
     Donor interface: lo0.3 (Index 333)
      Input Filters: 6_2Mb-demux0.3221425002-in
     Output Filters: 6_5Mb-demux0.3221425002-out
     Addresses, Flags: Is-Primary

       Destination: Unspecified, Local: 2001:1be0:e080:f100::32

   Generation: 0

       Destination: Unspecified, Local: fe80::c609:b7ff:feb3:8f54

   Protocol pppoe, Generation: 0      

      Dynamic Profile: jnpr-PPPOE,

     Service Name Table: None,

     Max Sessions: 5, Max Sessions VSA Ignore: Off,

     Duplicate Protection: On, Short Cycle Protection: Off,

     Direct Connect: Off,

     AC Name: jnpr

   Generation: 0, Route table: 65535

     Addresses, Flags: None

       Destination: Unspecified, Local: Unspecified, Broadcast: Unspecified, Generation: 0

 

Modification History

2024-01-22 : Article Created