Hardware
This section covers filter and policing limitations.
•
On SRX1400, SRX3400 and SRX3600 devices, the following feature is not supported
by a simple filter:
•
Forwarding class as match condition
•
On SRX1400, SRX3400 and SRX3600 devices, the following features are not supported
by a policer or a three-color-policer:
•
Color-aware mode of a three-color-policer
•
Filter-specific policer
•
Forwarding class as action of a policer
•
Logical interface policer
•
Logical interface three-color policer
•
Logical interface bandwidth policer
•
Packet loss priority as action of a policer
•
Packet loss priority as action of a three-color-policer
•
On SRX1400, SRX3400, SRX3600, SRX5600, and SRX5800 devices, the following
features are not supported by a firewall filter:
•
Policer action
•
Egress FBF
•
FTF
•
SRX1400, SRX3400, and SRX3600 devices have the following limitations of a simple
filter:
•
In the packet processor on an IOC, up to 100 logical interfaces can be applied with
simple filters.
•
In the packet processor on an IOC, the maximum number of terms of all simple filters
is 4000.
•
In the packet processor on an IOC, the maximum number of policers is 4000.
•
In the packet processor on an IOC, the maximum number of three-color-policers is
2000.
•
The maximum burst size of a policer or three-color-policer is 16 MB.
•
1G half-duplex mode of operation is not supported in the autonegotiation mode for
the following devices:
Copyright © 2010, Juniper Networks, Inc.136
JUNOS OS 10.4 Release Notes