16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

Firewall Filter Types<br />

Supported Standards<br />

In addition to standard firewall filters, the Junos OS firewall filter implementation also<br />

supports two other firewall filter types: service filters and simple filters.<br />

Service Filters<br />

Service filters enable you to define filters associated with a defined set of services. Service<br />

filters are supported on services interfaces, which provide specific capabilities for<br />

manipulating traffic before it is delivered to its destination. You use service filters to refine<br />

the target of the set of services and also to process traffic. Only IPv4 and IPv6 traffic are<br />

supported on service filters. No other protocol families are supported.<br />

Simple Filters<br />

Simple filters are supported on Gigabit Ethernet intelligent queuing (IQ2) and Enhanced<br />

Queuing Dense Port Concentrator (EQ DPC) interfaces only. Unlike standard filters,<br />

simple filters support IPv4 traffic only and have a number of restrictions. For example,<br />

you cannot configure a terminating action for a simple filter. Simple filters always accept<br />

packets. Also, simple filters can be applied only as input filters. They are not supported<br />

on outbound traffic. Simple filters are recommended for metropolitan Ethernet<br />

applications.<br />

The Junos OS supports the following RFCs related to filtering:<br />

• RFC 792, Internet Control Message Protocol<br />

• RFC 2460, Internet Protocol, Version 6 (IPv6)<br />

• RFC 2474, Definition of the Differentiated Services (DS) Field<br />

• RFC 2475, An Architecture for Differentiated Services<br />

• RFC 2597, Assured Forwarding PHB Group<br />

• RFC 3246, An Expedited Forwarding PHB (Per-Hop Behavior)<br />

• RFC 4291, IP Version 6 Addressing Architecture<br />

• RFC 4443, Internet Control Message Protocol (ICMPv6) for the Internet Protocol Version<br />

6 (IPv6) Specification<br />

190<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!