16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9: Firewall Filter <strong>Configuration</strong><br />

Table 37: Unsupported Firewall Actions and Action Modifiers for Logical Systems (continued)<br />

Action or Action<br />

Modifier<br />

Example<br />

Description<br />

ipsec-sa<br />

[edit]<br />

logical-systems {<br />

ls1 {<br />

firewall {<br />

family inet {<br />

filter foo {<br />

term one {<br />

from {<br />

source-address 10.1.0.0/16;<br />

}<br />

then {<br />

ipsec-sa barney;<br />

}<br />

}<br />

}<br />

}<br />

}<br />

}<br />

}<br />

Because the ipsec-sa action modifier<br />

references barney, a security<br />

association defined outside the local<br />

logical system, this action is not<br />

supported.<br />

logical-system<br />

[edit]<br />

logical-systems {<br />

ls1 {<br />

firewall {<br />

family inet {<br />

filter foo {<br />

term one {<br />

from {<br />

source-address 10.1.0.0/16;<br />

}<br />

then {<br />

logical-system fred;<br />

}<br />

}<br />

}<br />

}<br />

}<br />

}<br />

}<br />

Because the logical-system action<br />

refers to fred, a logical system defined<br />

outside the local logical system, this<br />

action is not supported.<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

265

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!