You can enforce per-VNI egress rate limits on VXLAN tunnel-initiated traffic to prevent congestion, mitigate denial-of-service (DoS) risk, and prioritize critical services. This configuration targets traffic entering the VXLAN tunnel. This does not rate limit locally switched or routed traffic. We added a new egress VLAN ACL filter profile to support the egress rate limit per VNI feature. You enable this profile with "set system packet-forwarding-options firewall profiles ethernet-switching egress profile1". Changing the filter profile triggers a Packet Forwarding Engine restart. Create the filter using "set firewall family ethernet-switching filter
| Product / Application | Software | Introduced Release |
|---|---|---|
| QFX5130-32CD | Junos OS Evolved | 25.4R1 |
| QFX5130-32CD | Junos OS Evolved | 25.2X100-D20 |
| QFX5130E-32CD | Junos OS Evolved | 25.4R1 |
| QFX5130E-32CD | Junos OS Evolved | 25.2X100-D20 |
| QFX5130-48C | Junos OS Evolved | 25.4R1 |
| QFX5130-48C | Junos OS Evolved | 25.2X100-D20 |
| QFX5130-48CM | Junos OS Evolved | 25.4R1 |
| QFX5130-48CM | Junos OS Evolved | 25.2X100-D20 |
| QFX5700 | Junos OS Evolved | 25.4R1 |
| QFX5700 | Junos OS Evolved | 25.2X100-D20 |
| QFX5700E | Junos OS Evolved | 25.4R1 |
| QFX5700E | Junos OS Evolved | 25.2X100-D20 |