Juniper EX9200 Features Manual page 118

Vpls feature guide ex series
Hide thumbs Also See for EX9200:
Table of Contents

Advertisement

VPLS Feature Guide for EX9200 Switches
Table 5: Firewall Filter Match Conditions for VPLS Traffic (continued)
Match Condition
source-prefix-list name
source-prefix-list name
except
tcp-flags flags
traffic-type type-name
traffic-type-except
type-name
user-vlan-1p-priority number
user-vlan-1p-priority-except
number
user-vlan-id number
100
Description
(MX Series routers and EX Series switches only) Match the source prefixes in the specified prefix
list. Specify a prefix list name defined at the
level.
NOTE:
VPLS prefix lists support only IPV4 addresses. IPV6 addresses included in a VPLS prefix
list will be discarded.
(MX Series routers and EX Series switches only) Do not match the source prefixes in the specified
prefix list. For more information, see the
Match one or more of the low-order 6 bits in the 8-bit TCP flags field in the TCP header.
To specify individual bit fields, you can specify the following text synonyms or hexadecimal values:
(0x01)
fin
(0x02)
syn
rst
(0x04)
push
(0x08)
(0x10)
ack
(0x20)
urgent
In a TCP session, the SYN flag is set only in the initial packet sent, while the ACK flag is set in all
packets sent after the initial packet.
You can string together multiple flags using the bit-field logical operators.
If you configure this match condition for IPv6 traffic, we recommend that you also configure the
match condition in the same term to specify that the TCP protocol is being used
next-header tcp
on the port.
(MX Series routers and EX Series switches only) Traffic type. Specify
, or
unknown-unicast
known-unicast
(MX Series routers and EX Series switches only) Do not match on the traffic type. Specify
,
,
broadcast
multicast
unknown-unicast
(MX Series routers, M320 router, and EX Series switches only) Match on the IEEE 802.1p user
priority bits in the customer VLAN tag (the inner tag in a dual-tag frame with 802.1Q VLAN tags).
Specify a single value or multiple values from
Compare with the
learn-vlan-1p-priority
NOTE:
This match condition supports the presence of a control word for MX Series routers and
the M320 router.
(MX Series routers, M320 rouer, and EX Series switches only) Do not match on the IEEE 802.1p
user priority bits. For details, see the
NOTE:
This match condition supports the presence of a control word for MX Series routers and
the M320 router.
(MX Series routers and EX Series switches only) Match the first VLAN identifier that is part of the
payload.
[edit policy-options prefix-list prefix-list-name]
match condition.
source-prefix-list
.
, or
.
known-unicast
through
.
0
7
match condition.
match condition.
user-vlan-1p-priority
Copyright © 2016, Juniper Networks, Inc.
hierarchy
,
,
broadcast
multicast

Advertisement

Table of Contents
loading

Table of Contents