16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

Related<br />

Documentation<br />

• How to Specify Firewall Filter Match Conditions on page 220<br />

• Overview of Protocol Match Conditions on page 217<br />

• Overview of Class-Based Match Conditions on page 219<br />

Configuring Protocol-Independent Match Conditions<br />

Table 27 on page 206 describes the firewall filter match conditions for protocol-independent<br />

traffic.<br />

To configure firewall filter match conditions for protocol-independent traffic:<br />

• Include the match-conditions statement at the [edit firewall family any filter filter-name<br />

term term-name from] hierarchy level.<br />

Table 27: Protocol-Independent Firewall Filter Match Conditions<br />

Match Condition<br />

forwarding-class<br />

class<br />

Description<br />

Forwarding class. Specify assured-forwarding, best-effort, expedited-forwarding, or network-control.<br />

forwarding-class-except<br />

class<br />

Do not match on the forwarding class. Specify assured-forwarding, best-effort, expedited-forwarding,<br />

or network-control.<br />

interface<br />

interface-name<br />

Interface on which the packet was received. You can configure a match condition that matches packets<br />

based on the interface on which they were received.<br />

interface-set<br />

interface-set-name<br />

(MX Series routers and routers with Enhanced IQ2 [IQ2E] PICs only) Interface set on which the packet<br />

was received. An interface set is a set of logical interfaces used to configure hierarchical class of service<br />

schedulers. For information about configuring an interface set, see the Junos Class of Service <strong>Configuration</strong><br />

<strong>Guide</strong> and the Junos Network Interfaces <strong>Configuration</strong> <strong>Guide</strong>.<br />

packet-length bytes<br />

Length of the received packet, in bytes. The length refers only to the IP packet, including the packet<br />

header, and does not include any Layer 2 encapsulation overhead.<br />

packet-length-except<br />

bytes<br />

Do not match on the received packet length, in bytes.<br />

Configuring Layer 2 Circuit Cross-Connect Match Conditions<br />

Table 28 on page 207 describes the firewall filter match conditions for Layer 2 circuit<br />

cross-connect (CCC) traffic.<br />

206<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!