16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

How to Specify Firewall Filter Match Conditions<br />

Because firewall filter match conditions can match a variety of criteria, including packet<br />

fields and IP addresses, you can specify the following types of values in a single match<br />

condition:<br />

• Numeric value or range of values<br />

• Single text value or multiple text values<br />

• Multiple numeric and text values<br />

• Single prefix value or multiple prefix values<br />

• Single bit-field value<br />

• Multiple bit-field values using logical operators<br />

This topic covers:<br />

• Numeric and Text Values in Match Conditions on page 220<br />

• Prefixes in Match Conditions on page 221<br />

• Bit-Field Values in Match Conditions on page 224<br />

Numeric and Text Values in Match Conditions<br />

Numerous match conditions can be configured with numeric or text values or a<br />

combination of the two.<br />

Numeric Values<br />

You can specify numeric values in one of the following ways:<br />

• Single number. A match occurs if the value of the field matches the number. For<br />

example:<br />

source-port 25;<br />

• Range of numbers. A match occurs if the value of the field falls within the specified<br />

range. The following example matches source ports 1024 through 65,535, inclusive:<br />

source-port 1024-65535;<br />

Text Values<br />

You can specify a text value as a synonym for a numeric value. A match occurs if the<br />

value of the field matches the number that corresponds to the synonym. For example:<br />

source-port smtp;<br />

A match occurs if the value of the field is 25 because that numeric value corresponds to<br />

the text synonym smtp.<br />

Multiple Numeric and Text Values<br />

220<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!