16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9: Firewall Filter <strong>Configuration</strong><br />

accept;<br />

}<br />

}<br />

}<br />

}<br />

}<br />

Configuring Firewall Filters for Logical Systems<br />

You can configure a separate set of firewall filters for each logical system on the router.<br />

To configure a firewall filter for a logical system, you must perform at least the following<br />

tasks:<br />

• Configure firewall filters for the logical system—To configure firewall filters for the<br />

logical system, include the firewall statement at the [edit local-systems<br />

logical-system-name] hierarchy level:<br />

[edit logical-systems logical-system-name]<br />

firewall {<br />

family family-name {<br />

filter filter-name {<br />

accounting-profile name;<br />

interface-specific;<br />

term term-name {<br />

from {<br />

match-conditions;<br />

}<br />

then {<br />

action;<br />

action-modifiers;<br />

}<br />

}<br />

}<br />

}<br />

}<br />

• Apply firewall filters to interfaces in the logical system—To have the firewall filter take<br />

effect, you must apply it to an interface in the logical system by including the filter<br />

statement at the [edit logical-systems logical-system-name interfaces interface-name<br />

unit logical-unit-number family family-name] hierarchy level:<br />

[edit logical-systems logical-system-name interfaces interface-name unit<br />

logical-unit-number family family-name]<br />

filter {<br />

input filter-name;<br />

output filter-name;<br />

}<br />

To identify firewall objects configured under logical systems, operational show commands<br />

and firewall-related SNMP MIB objects include a __logical-system-name/ prefix in the<br />

object name. For example, firewall objects configured under the ls1 logical system include<br />

an __ls1/ prefix.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

255

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!