Standard Firewall Filter Nonterminating Actions On Acx Series Routers - Juniper ACX1000 Configuration Manual

Junos os; acx series universal access router
Hide thumbs Also See for ACX1000:
Table of Contents

Advertisement

ACX Series Universal Access Router Configuration Guide
Table 76: Terminating Actions for Standard Firewall Filters on ACX Series Routers (continued)
Terminating
Action
Description
reject message-type
Reject the packet and return an ICMPv4 or ICMPv6 message:
If no message type is specified, a
default.
If
tcp-reset
is a TCP packet. Otherwise, the
value of 13, is returned.
If any other message type is specified, that message is returned.
NOTE:
Rejected packets can be sampled or logged if you configure the
action.
This action is supported on ingress only.
The
message-type
administratively-prohibited
fragmentation-needed
network-prohibited
port-unreachable
source-host-isolated
Direct the packet to the specified routing instance.
routing-instance
routing-instance-name
Related
Documentation

Standard Firewall Filter Nonterminating Actions on ACX Series Routers

1064
is specified as the message type,
administratively-prohibited
option can have one of the following values:
,
bad-host-tos
,
host-prohibited
,
network-unknown
,
precedence-cutoff
,
source-route-failed
Guidelines for Configuring Firewall Filters on page 1044
Standard Firewall Filter Match Conditions and Actions on ACX Series Routers Overview
on page 1052
Standard Firewall Filter Nonterminating Actions on ACX Series Routers on page 1064
Standard stateless firewall filters support different sets of nonterminating actions for
each protocol family.
NOTE:
ACX Series routers do not support the
ACX Series routers support log and syslog actions in ingress and egress
directions for family
Table 77 on page 1065
describes the nonterminating actions you can configure for a standard
firewall filter term.
message is returned by
destination-unreachable
is returned only if the packet
tcp-reset
message, which has a
address-unreachable
,
,
bad-network-tos
beyond-scope
,
,
host-unknown
host-unreachable
,
,
network-unreachable
no-route
,
,
precedence-violation
protocol-unreachable
, or
tcp-reset
.
inet
and family
bridge
Protocols
family inet
sample
or
syslog
,
,
,
,
,
family inet
action.
next term
.
Copyright © 2017, Juniper Networks, Inc.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Acx5048Acx5096Acx500Acx1100Acx2000Acx2100 ... Show all

Table of Contents