16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

Table 33: Layer 2 Bridging Firewall Filter Match Conditions (MX Series Ethernet Services Routers<br />

Only) (continued)<br />

Match Condition<br />

isid-priority-code-point-except<br />

number<br />

Description<br />

(Supported with PBB) Do not match internet service identifier priority code point.<br />

learn-vlan-1p-priority<br />

value<br />

(Supported with bridging, VPLS, and Layer 2 circuit cross-connect [CCC] traffic only) IEEE 802.1p<br />

learned VLAN priority field. Specify a single value or multiple values from 0 through 7.<br />

learn-vlan-1p-priority-except<br />

value<br />

(Supported with bridging, VPLS, and Layer 2 circuit cross-connect [CCC] traffic only) Do not match<br />

on the IEEE 802.1p learned VLAN priority field. Specify a single value or multiple values from 0 through<br />

7.<br />

learn-vlan-dei number<br />

(Supported with bridging) Match user virtual LAN (VLAN) identifier DEI bit.<br />

learn-vlan-dei-except<br />

number<br />

(Supported with bridging) Do not match user VLAN identifier DEI bit.<br />

learn-vlan-id number<br />

VLAN identifier used for MAC learning.<br />

learn-vlan-id-except<br />

number<br />

Do not match on the VLAN identifier used for MAC learning.<br />

loss-priority level<br />

Packet loss priority (PLP) level. Specify a single level or multiple levels: low, medium-low, medium-high,<br />

or high.<br />

For information about using behavior aggregate (BA) classifiers to set the PLP level of incoming<br />

packets, see the Junos Class of Service <strong>Configuration</strong> <strong>Guide</strong>.<br />

loss-priority-except<br />

level<br />

Do not match on the packet loss priority level. Specify a single level or multiple levels: low, medium-low,<br />

medium-high, or high.<br />

For information about using behavior aggregate (BA) classifiers to set the PLP level of incoming<br />

packets, see the Junos Class of Service <strong>Configuration</strong> <strong>Guide</strong>.<br />

port number<br />

TCP or UDP source or destination port. You cannot specify both the port match condition and either<br />

the destination-port or source-port match conditions in the same term.<br />

source-mac-address<br />

address<br />

Source MAC address of a Layer 2 packet.<br />

source-port number<br />

TCP or UDP source port field. You cannot specify the port and source-port match conditions in the<br />

same term.<br />

tcp-flags flags<br />

One or more of the following TCP flags:<br />

• Bit-name: fin, syn, rst, push, ack, urgent<br />

• Numerical value: 0x01 through 0x20<br />

• Text synonym: tcp-established, tcp-initial<br />

You can string together multiple flags using logical operators.<br />

Configuring the tcp-flags match condition requires that you configure the next-header-tcp match<br />

condition.<br />

216<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!