16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9: Firewall Filter <strong>Configuration</strong><br />

then {<br />

count ce1;<br />

log;<br />

routing-instance ce1;<br />

}<br />

}<br />

term 1 {<br />

from {<br />

source-address {<br />

::10.34.2.0/120;<br />

}<br />

}<br />

then {<br />

count ce2;<br />

log;<br />

routing-instance ce2;<br />

}<br />

}<br />

term default {<br />

then {<br />

count default;<br />

accept;<br />

}<br />

}<br />

}<br />

}<br />

}<br />

Configuring Forwarding Table Filters<br />

The following sections describe the following topics:<br />

• Overview of Forwarding Table Filters on page 271<br />

• Configuring a Forwarding Table Filter on page 272<br />

Overview of Forwarding Table Filters<br />

Forwarding table filters are defined the same as other firewall filters, but you apply them<br />

differently:<br />

• Instead of applying forwarding table filters to interfaces, you apply them to forwarding<br />

tables, each of which is associated with a routing instance and a virtual private network<br />

(VPN).<br />

• Instead of applying input and output filters by default, you can apply an input forwarding<br />

table filter only.<br />

All packets are subjected to the input forwarding table filter that applies to the forwarding<br />

table. A forwarding table filter controls which packets the router accepts and then<br />

performs a lookup for the forwarding table, thereby controlling which packets the router<br />

forwards on the interfaces.<br />

When the router receives a packet, it determines the best route to the ultimate destination<br />

by looking in a forwarding table, which is associated with the VPN on which the packet<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

271

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!