16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

Configuring Firewall Filters<br />

• Example: Accepting OSPF Packets from Certain Addresses on page 248<br />

• Example: Matching Packets Based on Two Unrelated Criteria on page 248<br />

• Example: Counting Both Accepted and Rejected Packets on page 249<br />

• Example: Blocking TCP Connections to a Certain Port Except from BGP Peers on page 250<br />

• Example: Accepting Packets with Specific IPv6 TCP Flags on page 250<br />

• Example: Setting a Rate Limit for Incoming Layer 2 Control Packets on page 251<br />

• Configuring Service Filters on page 252<br />

• Configuring Simple Filters on page 253<br />

• Configuring Firewall Filters for Logical Systems on page 255<br />

• Configuring Accounting for Firewall Filters on page 268<br />

• Configuring Filter-Based Forwarding on page 269<br />

• Configuring Forwarding Table Filters on page 271<br />

• Configuring System Logging of Firewall Filter Operations on page 273<br />

This section shows the complete set of statements that can be configured at the [edit<br />

firewall] hierarchy level to create a firewall filter.<br />

[edit firewall]<br />

family family-name {<br />

filter filter-name {<br />

accounting-profile name;<br />

interface-specific;<br />

physical-interface-filter;<br />

term term-name {<br />

filter filter-name;<br />

from {<br />

match-conditions;<br />

}<br />

then {<br />

action;<br />

action-modifiers;<br />

}<br />

}<br />

}<br />

service-filter filter-name {<br />

term term-name {<br />

from {<br />

match-conditions;<br />

}<br />

then {<br />

action;<br />

action-modifiers;<br />

}<br />

}<br />

}<br />

simple-filter filter-name {<br />

term term-name {<br />

192<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!