Table 78: Firewall Filter Configuration Details - Juniper NETWORK AND SECURITY MANAGER 2010.4 - M-SERIES AND MX-SERIES DEVICES GUIDE REV 1 Manual

Network and security manager
Table of Contents

Advertisement

M-series and MX-series Devices
Related
Documentation
162

Table 78: Firewall Filter Configuration Details

Task
Configure firewall filters for
protocol-independent
match conditions.
Configuring the Firewall Filter for Bridge Family Type (NSM Procedure) on page 163
Your Action
1.
Expand Any.
2. In the Comment box, enter the comment for Any.
3. Click Filter next to Any.
4. Click Add new entry next to Filter.
5. In the name box, enter the name that identifies the filter.
6. In the Comment box, enter the comment for the filter.
7. Expand Filter.
8. Click Term next to Filter.
9. Click Add new entry next to Term.
10. Expand Term.
11. In the Name box, enter the name that identifies the term.
12. In the Comment box, enter the comment for the term.
13. Expand From.
14. From the listed protocol-independent match conditions, select
the filters defined for the any family type.
The protocol-independent match conditions are Forwarding
Class, Interface, Interface Set, Loss Priority, and Packet Length.
15. Expand Then.
16. In the Comment box, enter the comment for then.
17. In the Count box, enter the number of packets.
18. From the Loss Priority list, set the packet loss priority (PLP) to
low, medium-low, medium-high, or high.
19. In the Forwarding Class box, enter the packet forwarding class
name.
20. Click Accept next to Then.
21. Select one of the following:
Accept—To accept a packet.
Discard—To discard a packet silently, without sending an
ICMP message.
Next—To evaluate the next term in the firewall filter.
22. Click Policer next to Then.
23. Select one of the following:
policer—To configure a new policer for each filter and select
the policer name.
three-color-policer—To configure a tricolor marking policer.
a. Expand Three Color Policer.
b. Click Single Rate next to Three Color Policer.
c. Select one of the following:
single-rate—if the named tricolor policer is a single-rate
policer.
two-rate—if the named tricolor policer is a two-rate
policer.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

M-seriesMx-series

Table of Contents