16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

To configure a firewall filter:<br />

1. Include the family family-name statement at the [edit firewall] hierarchy level to specify<br />

the protocol family for which you want to filter traffic.<br />

For family-name, specify one of the following:<br />

• inet—IPv4<br />

• inet6—IPv6<br />

• ccc—Layer 2 circuit cross-connects<br />

• mpls—MPLS<br />

• any—Protocol-independent (Use this protocol family to apply a firewall filter to a<br />

physical interface.)<br />

• vpls—VPLS<br />

• bridge—(MX Series Ethernet Services Routers only) Layer 2 bridging<br />

2. Include the filter filter-name statement at the [edit firewall family family-name]<br />

hierarchy level to specify a name for the firewall filter.<br />

The filter name can contain letters, numbers, and hyphens (-) and be up to 64<br />

characters long. To include spaces in the name, enclose the entire name in quotation<br />

marks (“ ”).<br />

3. Include the term term-name statement at the [edit firewall family family-name filter<br />

filter-name] hierarchy level to configure a term.<br />

Each firewall filter consists of one or more terms. For each term you specify one or<br />

more match conditions and one or more actions. The term name can contain letters,<br />

numbers, and hyphens (-) and can be up to 74 characters long. To include spaces in<br />

the name, enclose the entire name in quotation marks (“ ”).<br />

You can specify multiple terms in a filter, effectively chaining together a series of<br />

match-action operations to apply to the packets on an interface.<br />

4. Include the from match-conditions statement at the [edit firewall family family-name<br />

filter filter-name term term-name] hierarchy level to specify the fields or values that<br />

the packet must contain (match conditions).<br />

For a match to occur, the packet must match all the conditions in the term. An<br />

individual match condition in a from statement can contain a list of values. For example,<br />

you can specify numeric range or multiple source and destination addresses. When<br />

a condition defines a list of values, a match occurs if any of the values matches the<br />

packet.<br />

194<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!