16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

Table 32 on page 210 describes the firewall filter match conditions supported for VPLS.<br />

For more information about how to configure Layer 2 services on the MX Series routers,<br />

see the Junos OS Network Interfaces <strong>Configuration</strong> <strong>Guide</strong>, the Junos Layer 2 <strong>Configuration</strong><br />

<strong>Guide</strong>, and the Junos OS MX Series Ethernet Services Routers Solutions <strong>Guide</strong>.<br />

Table 32: VPLS Firewall Filter Match Conditions<br />

Match Condition<br />

destination<br />

mac-address address<br />

Description<br />

Destination media access control (MAC) address of a VPLS packet.<br />

destination-port<br />

number<br />

(MX Series routers only) TCP or UDP destination port field. You cannot specify both the port and<br />

destination-port match conditions in the same term.<br />

destination-port-except<br />

number<br />

(MX Series routers only) Do not match on the TCP or UDP destination port field. You cannot specify<br />

both the port and destination-port match conditions in the same term.<br />

destination-prefix-list<br />

name<br />

(MX Series routers only) Destination prefixes in the specified list name. Specify the name of a prefix list<br />

defined at the [edit policy-options prefix-list prefix-list-name] hierarchy level.<br />

NOTE: VPLS prefix lists support only IPV4 addresses. IPV6 addresses included in a VPLS prefix list will<br />

be discarded.<br />

dscp number<br />

(MX Series routers only) Differentiated Services code point (DSCP). The DiffServ protocol uses the<br />

type-of-service (ToS) byte in the IP header. The most significant 6 bits of this byte form the DSCP. For<br />

more information, see the Junos OS Class of Service <strong>Configuration</strong> <strong>Guide</strong>.<br />

You can specify a numeric value from 0 through 63. To specify the value in hexadecimal form, include<br />

0x as a prefix. To specify the value in binary form, include b as a prefix.<br />

In place of the numeric value, you can specify one of the following text synonyms (the field values are<br />

also listed):<br />

• RFC 3246, An Expedited Forwarding PHB (Per-Hop Behavior), defines one code point: ef (46).<br />

• RFC 2597, Assured Forwarding PHB Group, defines 4 classes, with 3 drop precedences in each class,<br />

for a total of 12 code points:<br />

af11 (10), af12 (12), af13 (14),<br />

af21 (18), af22 (20), af23 (22),<br />

af31 (26), af32 (28), af33 (30),<br />

af41 (34), af42 (36), af43 (38)<br />

dscp-except number<br />

(MX Series routers only) Do not match on the DSCP.<br />

ether-type number<br />

Ethernet type field of a VPLS packet.<br />

ether-type-except<br />

number<br />

Do not match on the Ethernet type field of a VPLS packet.<br />

forwarding-class<br />

class<br />

Forwarding class. Specify assured-forwarding, best-effort, expedited-forwarding, or network-control.<br />

210<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!