16.03.2014 Views

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

Policy Framework Configuration Guide - Juniper Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Junos 10.4 <strong>Policy</strong> <strong>Framework</strong> <strong>Configuration</strong> <strong>Guide</strong><br />

is to be sent. The router then forwards the packet toward its destination through the<br />

appropriate interface.<br />

NOTE: For transit packets exiting the router through the tunnel, forwarding<br />

table filtering is not supported on the interfaces you configure as the output<br />

interface for tunnel traffic.<br />

Configuring a Forwarding Table Filter<br />

A forwarding table filter allows you to filter data packets based on their components and<br />

to perform an action on packets that match the filter; it essentially controls which bearer<br />

packets the router accepts and forwards. To configure a forwarding table filter, include<br />

the firewall statement at the [edit] hierarchy level:<br />

[edit]<br />

firewall {<br />

family family-name {<br />

filter filter-name {<br />

term term-name {<br />

from {<br />

match-conditions;<br />

}<br />

then {<br />

action;<br />

action-modifiers;<br />

}<br />

}<br />

}<br />

}<br />

}<br />

family-name is the family address type: IPv4 (inet), IPv6 (inet6), Layer 2 traffic (bridge),<br />

or MPLS (mpls).<br />

term-name is a named structure in which match conditions and actions are defined.<br />

match-conditions are the criteria against which a bearer packet is compared; for example,<br />

the IP address of a source device or a destination device. You can specify multiple criteria<br />

in a match condition.<br />

action specifies what happens if a packet matches all criteria; for example, the gateway<br />

GPRS support node (GGSN) accepting the bearer packet, performing a lookup in the<br />

forwarding table, and forwarding the packet to its destination; discarding the packet;<br />

and discarding the packet and returning a rejection message.<br />

action-modifiers are actions that are taken in addition to the GGSN accepting or discarding<br />

a packet when all criteria match; for example, counting the packets and logging a packet.<br />

For more detailed information about configuring filters, see “Configuring Standard Firewall<br />

Filters” on page 193.<br />

To create a forwarding table, include the instance-type statement with the forwarding<br />

option at the [edit routing-instances instance-name] hierarchy level:<br />

272<br />

Copyright © 2010, <strong>Juniper</strong> <strong>Networks</strong>, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!