16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

Table 26: IPv6 Firewall Filter Match Conditions (continued)<br />

Match Condition<br />

Description<br />

interface-set<br />

interface-set-name<br />

(MX Series routers and routers with Enhanced IQ2 [IQ2E] PICs only) Interface set on which the packet<br />

was received. An interface set is a set of logical interfaces used to configure hierarchical class-of-service<br />

schedulers. For information about configuring an interface set, see the Junos Class of Service<br />

<strong>Configuration</strong> <strong>Guide</strong> and the Junos Network Interfaces <strong>Configuration</strong> <strong>Guide</strong>.<br />

loss-priority level<br />

Packet loss priority (PLP) level. Specify a single level or multiple levels: low, medium-low, medium-high,<br />

or high.<br />

Supported on MX Series routers; M120 and M320 routers; and M7i and M10i routers with the Enhanced<br />

CFEB (CFEB-E).<br />

On M320 routers, you must enable the tricolor statement at the [edit class-of-service] hierarchy level<br />

to commit a PLP configuration with any of the four levels specified. If the tricolor statement is not<br />

referenced, you can only configure the high and low levels. This applies to all protocol families.<br />

For information about using behavior aggregate (BA) classifiers to set the PLP level of incoming packets,<br />

see the Junos Class of Service <strong>Configuration</strong> <strong>Guide</strong>.<br />

loss-priority-except<br />

level<br />

Do not match on the packet loss priority level. Specify a single level or multiple levels: low, medium-low,<br />

medium-high, or high.<br />

For information about using behavior aggregate (BA) classifiers to set the PLP level of incoming packets,<br />

see the Junos Class of Service <strong>Configuration</strong> <strong>Guide</strong>.<br />

next-header bytes<br />

8-bit IP protocol field that identifies the type of header immediately following the IPv6 header. In place<br />

of the numeric value, you can specify one of the following text synonyms (the field values are also<br />

listed): ah (51), dstops (60), egp (8), esp (50), fragment (44), gre (47), hop-by-hop (0), icmp (1), icmpv6<br />

(1), igmp (2), ipip (4), ipv6 (41), no-next-header (59), ospf (89), pim (103), routing (43), rsvp (46),<br />

sctp (132), tcp (6), udp (17), or vrrp (112).<br />

packet-length bytes<br />

Length of the received packet, in bytes. The length refers only to the IP packet, including the packet<br />

header, and does not include any Layer 2 encapsulation overhead.<br />

port number<br />

TCP or UDP source or destination port field. You cannot specify both the port match and either the<br />

destination-port or source-port match conditions in the same term.<br />

Typically, you specify this match in conjunction with the protocol match statement to determine which<br />

protocol is being used on the port. For more information, see “Overview of Protocol Match Conditions”<br />

on page 217.<br />

In place of the numeric value, you can specify one of the text synonyms listed under destination-port.<br />

prefix-list name<br />

Source or destination prefixes in the specified list name. Specify the name of a list defined at the [edit<br />

routing-options prefix-list prefix-list-name] hierarchy level.<br />

service-filter-hit<br />

This condition matches if the packet is received from a filter where a service-filter-hit action was<br />

applied.<br />

source-address<br />

address<br />

Address of the source node sending the packet; 128 bits in length. The filter description syntax supports<br />

the text representations for IPv6 addresses as described in RFC 2373. For more information about IPv6<br />

address syntax, see the Junos OS Routing Protocols <strong>Configuration</strong> <strong>Guide</strong>.<br />

204<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!