16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9: Firewall Filter <strong>Configuration</strong><br />

Table 35: Firewall Filter Actions (continued)<br />

Action<br />

Description<br />

ipsec-sa ipsec-sa<br />

(Family inet only) Use the specified IPsec security association.<br />

NOTE: This action is not supported on MX Series routers.<br />

load-balance<br />

group-name<br />

(Family inet only) Use the specified load-balancing group.<br />

log<br />

(Family inet and inet6 only) Log the packet header information in a buffer within the Packet Forwarding<br />

Engine. You can access this information by issuing the show firewall log command at the command-line<br />

interface (CLI).<br />

logical-system<br />

logical-system-name<br />

Specify a logical system to which packets are forwarded.<br />

loss-priority (high<br />

| medium-high |<br />

medium-low| low)<br />

Set the loss priority level for packets.<br />

Supported on MX Series routers; M120 and M320 routers; and M7i and M10i routers with the Enhanced<br />

CFEB (CFEB-E).<br />

On M320 routers, you must enable the tricolor statement at the [edit class-of-service] hierarchy level to<br />

commit a PLP configuration with any of the four levels specified. If the tricolor statement is not referenced,<br />

you can only configure the high and low levels. This applies to all protocol families.<br />

You cannot also configure the three-color-policer nonterminating action for the same firewall filter term.<br />

These two nonterminating actions are mutually exclusive.<br />

next term<br />

Continue to the next term for evaluation.<br />

next-hop-group<br />

group-name<br />

(Family inet only) Use the specified next-hop group.<br />

policer<br />

policer-name<br />

Rate-limit packets based on the specified policer.<br />

port-mirror<br />

(Family bridge, ccc, inet, inet6, and vpls only) Port-mirror packets based on the specified family. Supported<br />

on M120 routers, M320 routers configured with Enhanced III FPCs, and MX Series routers only.<br />

prefix-action name<br />

(Family inet only) Count or police packets based on the specified action name.<br />

reject<br />

message-type<br />

Discard a packet, sending an ICMPv4 or an ICMPv6 destination unreachable message. Rejected packets<br />

can be logged or sampled if you configure either the sample or the syslog action modifier. You can specify<br />

one of the following message codes: administratively-prohibited (default), bad-host-tos, bad-network-tos,<br />

host-prohibited, host-unknown, host-unreachable, network-prohibited, network-unknown,<br />

network-unreachable, port-unreachable, precedence-cutoff, precedence-violation, protocol-unreachable,<br />

source-host-isolated, source-route-failed, or tcp-reset. If you specify tcp-reset, a Transmission Control<br />

Protocol (TCP) reset is returned if the packet is a TCP packet. Otherwise, the default code of<br />

administratively-prohibited, which has a value of 13, is returned.<br />

Supported for family inet and inet6 only.<br />

routing-instance<br />

routing-instance<br />

(Family inet and inet6 only) Specify a routing instance to which packets are forwarded.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

229

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!