16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Firewall Filter <strong>Configuration</strong><br />

[edit]<br />

routing-instances instance-name {<br />

instance-type forwarding;<br />

}<br />

To apply a forwarding table filter to a VPN routing and forwarding (VRF) table, include<br />

the filter and input statements at the [edit routing-instance instance-name<br />

forwarding-options family family-name] hierarchy level:<br />

[edit routing-instances instance-name]<br />

instance-type forwarding;<br />

forwarding-options {<br />

family family-name {<br />

filter {<br />

input filter-name;<br />

}<br />

}<br />

}<br />

To apply a forwarding table filter to a forwarding table, include the filter and input<br />

statements at the [edit forwarding-options family family-name] hierarchy level:<br />

[edit forwarding-options family family-name]<br />

filter {<br />

input filter-name;<br />

}<br />

To apply a forwarding table filter to the default forwarding table inet.0, which is not<br />

associated with a specific routing instance, include the filter and input statements at the<br />

[edit forwarding-options family inet] hierarchy level:<br />

[edit forwarding-options family inet]<br />

filter {<br />

input filter-name;<br />

}<br />

For more information about applying forwarding table filters, see “Applying Filters to<br />

Forwarding Tables” on page 363. For information about routing instances, see the Junos<br />

OS Routing Protocols <strong>Configuration</strong> <strong>Guide</strong>.<br />

Configuring System Logging of Firewall Filter Operations<br />

System logging can be configured for the firewall filter process. You can set system<br />

logging to record messages of a particular level or all levels. The messages are sent to a<br />

system logging file.<br />

The following is a sample system logging configuration for the firewall filter icmp-syslog.<br />

For more information about configuring system logging, see the Junos OS System Basics<br />

<strong>Configuration</strong> <strong>Guide</strong>.<br />

[edit]<br />

system {<br />

syslog {<br />

file filter {<br />

firewall any;<br />

archive no-world-readable;<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

273

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!