16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 9: Firewall Filter <strong>Configuration</strong><br />

then {<br />

log;<br />

discard;<br />

}<br />

}<br />

}<br />

filter filter1 {<br />

term term1 {<br />

filter common-filter;<br />

}<br />

}<br />

filter filter2 {<br />

term term1 {<br />

filter common-filter;<br />

}<br />

}<br />

}<br />

Applying Firewall Filters to Interfaces<br />

For a firewall filter to work, you must apply it to at least one interface. To do this, include<br />

the filter statement when configuring the logical interface at the [edit interfaces<br />

interface-name unit logical-unit-number family family-name] hierarchy level:<br />

[edit interfaces interface-name unit logical-unit-number family family-name]<br />

filter {<br />

input filter-name;<br />

input-list [ filter-names ];<br />

output filter-name;<br />

output-list [ filter-names ];<br />

}<br />

In the input statement, list the name of one firewall filter to be evaluated when packets<br />

are received on the interface. Input filters applied to the loopback interface, lo0, affect<br />

only inbound traffic destined for the Routing Engine.<br />

In the output statement, list the name of one firewall filter to be evaluated when packets<br />

are transmitted on the interface. Output filters applied to the loopback interface, lo0,<br />

affect only outbound traffic sent from the Routing Engine.<br />

NOTE: When you create an additional loopback interface, it is important to<br />

apply a filter to it so the Routing Engine is protected. We recommend that<br />

when you apply a filter to the loopback interface lo0, you include the<br />

apply-groups statement. Doing so ensures that the filter is automatically<br />

inherited on every loopback interface, including lo0 and other loopback<br />

interfaces. For more information, see the Junos OS CLI User <strong>Guide</strong>.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

235

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!