16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 8: Introduction to Firewall Filters<br />

Table 24: Firewall Filter Application Points (continued)<br />

Application Point<br />

Filter Type<br />

Supported Hierarchy<br />

Comments<br />

Protocol family on<br />

interface—Filter is applied to<br />

a specific protocol family on<br />

the logical interface.<br />

Standard firewall filter you<br />

define for any of the following<br />

protocol families at the [edit<br />

firewall family family-name<br />

filter filter-name] hierarchy<br />

level: any, bridge, ccc, inet,<br />

inet6, mpls, and vpls<br />

• [edit interfaces interface-name<br />

unit unit-number family<br />

family-name filter input<br />

filter-name]<br />

• [edit interfaces interface-name<br />

unit unit-number family<br />

family-name filter output<br />

filter-name]<br />

The protocol family bridge<br />

is supported only on MX<br />

Series routers.<br />

• [edit interfaces interface-name<br />

unit unit-number family<br />

family-name filter input-list<br />

[ filter-names ]<br />

• [edit interfaces interface-name<br />

unit unit-number family<br />

family-name filter output-list [<br />

filter-names ]<br />

Protocol family on<br />

interface—Filter is applied to<br />

a specific protocol family on<br />

the logical interface.<br />

Simple filter you define at the<br />

[edit firewall family inet<br />

simple-filter filter-name]<br />

hierarchy level.<br />

[edit interfaces interface-name<br />

unit unit-number family inet<br />

simple-filter input filter-name]<br />

Supported for protocol<br />

family inet only on Gigabit<br />

Ethernet intelligent queuing<br />

(IQ2) PICs on the M120,<br />

M320, and T Series routers<br />

and on Enhanced Queueing<br />

Dense Port Concentrators<br />

(EQ DPC) on MX Series<br />

routers.<br />

Protocol family on<br />

interface—Filter is applied to<br />

a specific protocol family on<br />

the logical interface.<br />

Policer applied to incoming<br />

or outbound traffic that you<br />

define at the [edit firewall<br />

policer policer-name]<br />

hierarchy level.<br />

• [edit interfaces interface-name<br />

unit unit-number family<br />

family-name input filter-name]<br />

• [edit interfaces interface-name<br />

unit unit-number family<br />

family-name output<br />

filter-name]<br />

The protocol family bridge<br />

is supported only on MX<br />

Series routers.<br />

The following protocol families<br />

are supported: bridge, ccc, inet,<br />

inet6, mpls, tcc, and vpls.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

187

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!