16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Firewall Filter <strong>Configuration</strong><br />

nonterminating-actions;<br />

}<br />

BEST PRACTICE: We strongly recommend that you always explicitly configure<br />

an action in the then statement. If you do not, or if you omit the then statement<br />

entirely, packets that match the conditions in the from statement are<br />

accepted.<br />

You can specify only one filter terminating action statement (or omit it), but you can<br />

specify any combination of nonterminating actions. For the action or nonterminating<br />

action to take effect, all conditions in the from statement must match. If you specify log<br />

as one of the actions in a term, this constitutes a terminating action; whether any<br />

additional terms in the filter are processed depends on the traffic through the filter.<br />

The nonterminating action operations carry a default accept action. For example, if you<br />

specify a nonterminating action and do not specify an action, the specified nonterminating<br />

action is implemented and the packet is accepted. To circumvent an implicit accept<br />

action and allow the Junos OS to the evaluate the following term in the filter, use the<br />

next term statement.<br />

The following actions are terminating actions:<br />

• accept<br />

• discard<br />

• reject<br />

• logical-system logical-system-name<br />

• routing-instance routing-instance-name<br />

• topology topology-name<br />

NOTE: You cannot configure the next term action with a terminating action<br />

in the same filter term. You can only configure the next term action with<br />

another nonterminating action in the same filter term.<br />

Policing uses a specific type of action, known as a policer action. For more information,<br />

see “Policer Actions” on page 278.<br />

For more information about forwarding classes and loss priority, see the Junos OS Class<br />

of Service <strong>Configuration</strong> <strong>Guide</strong>.<br />

Table 35 on page 228 shows the complete list of filter actions, both terminating and<br />

nonterminating.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

227

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!