Juniper EX9200 Series Overview Manual page 50

Class of service overview and examples
Hide thumbs Also See for EX9200 Series:
Table of Contents

Advertisement

Class of Service Overview and Examples for EX9200 Switches
Common IPv4 Firewall Match Conditions
Common Layer 2 Firewall Match Conditions
36
This section lists statements that are valid at the following hierarchy levels, and is
referenced at those levels in
the statements being repeated.
[edit firewall family inet dialer-filter filter-name term term-name from]
exceptions noted at this level in
[edit firewall family inet filter filter-name term term-name from]
[edit firewall filter filter-name term term-name from]
The common IPv4 firewall match conditions are as follows:
(ah-spi [ values ] | ah-spi-except [ values ]);
(dscp [ code-point-values ] | dscp-except [ code-point-values ]);
(esp-spi [ values ] | esp-spi-except [ values ]);
first-fragment;
fragment-flags flag;
(fragment-offset [ offsets ] | fragment-offset-except [ offsets ]);
(ip-options [ option-names ] | ip-options-except [ option-names ]);
is-fragment;
(precedence [ precedence-names ] | precedence-except [ precedence-names ]);
(protocol [ protocol-names ] | protocol-except [ protocol-names ]);
(ttl [ ttl-values ] | ttl-except [ ttl-values ]);
This section lists statements that are valid at the following hierarchy levels, and is
referenced at those levels in
the statements being repeated.
[edit firewall family ethernet-switching filter filter-name term term-name from]
[edit firewall family vpls filter filter-name term term-name from]
The common Layer 2 firewall match conditions are as follows:
destination-mac-address {
mac-address <except>;
}
(destination-port [ port-names ] | destination-port-except [ port-names ]);
(dscp [ code-point-values ] | dscp-except [ code-point-values ]);
(ether-type [ protocol-types ] | ether-type-except [ protocol-types ]);
(forwarding-class [ class-names ] | forwarding-class-except [ class-names ]);
(icmp-code [ codes ] | icmp-code-except [ codes ]);
(icmp-type [ types ] | icmp-type-except [ types ]);
(interface-group [ group-names ] | interface-group-except [ group-names ]);
ip-address {
ip-prefix</prefix-length> <except>;
}
ip-destination-address {
ip-prefix</prefix-length> <except>;
}
"Complete [edit firewall] Hierarchy" on page 38
"Complete [edit firewall] Hierarchy" on page
"Complete [edit firewall] Hierarchy" on page 38
instead of
(with the
38)
instead of
Copyright © 2013, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

Table of Contents