16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Firewall Filter <strong>Configuration</strong><br />

NOTE: The from statement is optional. If you omit it, the actions specified<br />

in the term’s then statement are optional.<br />

5. Include the then actions statement at the [edit firewall family family-name filter<br />

filter-name term term-name hierarchy level] to specify an action to perform on traffic<br />

that matches the conditions specified in the term.<br />

BEST PRACTICE: We strongly recommend that you always explicitly<br />

configure an action in the then statement. If you do not, or if you omit the<br />

then statement entirely, packets that match the conditions in the from<br />

statement are automatically accepted.<br />

You can specify the following filter actions:<br />

• accept<br />

• count counter-name<br />

• discard<br />

• dscp code-point (family inet only)<br />

• forwarding-class class-name<br />

• ipsec-sa ipsec-sa (family inet only)<br />

• load-balance group-name (family inet only)<br />

• log (family inet and inet6 only)<br />

• logical-system logical-system-name (family inet and inet6 only)<br />

• loss-priority (high | medium-high | medium-low | low)<br />

• next term<br />

• next-hop-group group-name (family inet only)<br />

• policer policer-name<br />

• port-mirror (family bridge, ccc, inet, inet6, and vpls only)<br />

• prefix-action action-name (family inet only)<br />

• reject (family inet and inet6 only)<br />

• routing-instance routing-instance-name (family inet and inet6 only)<br />

• sample (family inet, inet6, and mpls only)<br />

• service-accounting (service filters and family inet or inet6 only)<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

195

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!