16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Firewall Filter <strong>Configuration</strong><br />

Table 37: Unsupported Firewall Actions and Action Modifiers for Logical Systems (continued)<br />

Action or Action<br />

Modifier<br />

Example<br />

Description<br />

sample<br />

[edit]<br />

logical-systems {<br />

ls1 {<br />

firewall {<br />

family inet {<br />

filter foo {<br />

term one {<br />

from {<br />

source-address 10.1.0.0/16;<br />

}<br />

then {<br />

sample;<br />

}<br />

}<br />

}<br />

}<br />

}<br />

}<br />

}<br />

In this example, the sample action<br />

depends on the sampling configuration<br />

defined under the [edit<br />

forwarding-options] hierarchy.<br />

Therefore, the sample action is not<br />

supported.<br />

syslog<br />

[edit]<br />

logical-systems {<br />

ls1 {<br />

firewall {<br />

family inet {<br />

filter icmp-syslog {<br />

term icmp-match {<br />

from {<br />

address {<br />

192.168.207.222/32;<br />

}<br />

protocol icmp;<br />

}<br />

then {<br />

count packets;<br />

syslog;<br />

accept;<br />

}<br />

}<br />

term default {<br />

then accept;<br />

}<br />

}<br />

}<br />

}<br />

}<br />

}<br />

In this example, there must be at least<br />

one system log (system syslog file<br />

filename) with the firewall facility<br />

enabled for the icmp-syslog filter's logs<br />

to be stored.<br />

Because this firewall configuration<br />

relies on a configuration outside the<br />

logical system, the syslog action<br />

modifier is not supported.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

267

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!