16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

Configuring MPLS Match Conditions<br />

Table 29 on page 208, Table 30 on page 208, and Table 31 on page 209 describe the firewall<br />

filter match conditions supported for MPLS traffic.<br />

To configure firewall filter match conditions for MPLS traffic, include the match-conditions<br />

statement at one of the hierarchy levels described below.<br />

• At the [edit firewall family mpls filter filter-name term term-name from] hierarchy level:<br />

Table 29: MPLS Firewall Filter Match Conditions (Hierarchy Level 1)<br />

Match Condition<br />

exp number<br />

Description<br />

Experimental (EXP) bit number or range of bit numbers in the MPLS header. For number, you can specify<br />

one or more values from 0 through 7 in decimal, binary, or hexadecimal format.<br />

exp-except number<br />

Do not match on the EXP bit number or range of bit numbers in the MPLS header. For number, you can<br />

specify one or more values from 0 through 7.<br />

forwarding-class class<br />

Forwarding class. Specify assured-forwarding, best-effort, expedited-forwarding, or network-control.<br />

forwarding-class-except<br />

class<br />

Do not match on the forwarding class. Specify assured-forwarding, best-effort, expedited-forwarding,<br />

or network-control.<br />

interface<br />

interface-name<br />

Interface on which the packet was received. You can configure a match condition that matches packets<br />

based on the interface on which they were received.<br />

interface-set<br />

interface-set-name<br />

(MX Series routers and routers with Enhanced IQ2 [IQ2E] PICs only) Interface set on which the packet<br />

was received. An interface set is a set of logical interfaces used to configure hierarchical class-of- service<br />

schedulers. For information about configuring an interface set, see the Junos Class of Service <strong>Configuration</strong><br />

<strong>Guide</strong> and the Junos Network Interfaces <strong>Configuration</strong> <strong>Guide</strong>.<br />

ip-version number<br />

(MPLS-tagged IPv4 packets only) Inner IP version.<br />

• (MPLS-tagged IPv4 packets only) At the [edit firewall family mpls filter filter-name<br />

term term-name from ip-version ipv4] hierarchy level:<br />

Table 30: MPLS Firewall Filter Match Conditions (Hierarchy Level 2)<br />

Match Condition<br />

destination-addressaddress<br />

Description<br />

Destination prefix.<br />

protocol number<br />

IP protocol field. In place of the numeric value, you can specify one of the following text synonyms (the<br />

field values are also listed): ah (51), egp (8), esp (50), gre (47), icmp (1), igmp (2), ipip (4), ipv6 (41),<br />

ospf (89), pim (103), rsvp (46), tcp (6), or udp (17).<br />

source-addressaddress<br />

Address of the source node sending the packet in IPv4 address format; 32 bits in length.<br />

• (MPLS-tagged IPv4 packets only) At the [edit firewall family mpls filter filter-name<br />

term term-name from ip-version ipv4 protocol protocol-name] hierarchy level:<br />

208<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!