Configuring Match Direction For Stateful Firewall Rules - Juniper ACX1000 Configuration Manual

Junos os; acx series universal access router
Hide thumbs Also See for ACX1000:
Table of Contents

Advertisement

ACX Series Universal Access Router Configuration Guide

Configuring Match Direction for Stateful Firewall Rules

1024
ACX500 Series routers do not support the following while configuring stateful firewall
rules:
(output | input-output)
match-direction
post-service-filter
at the interface service input hierarchy level.
IPv6 source address and destination address.
,
application-sets
application
hierarchy level.
Application Layer Gateways (ALGs).
Chaining of services within Multiservices Modular Interfaces Card (MS-MIC) and with
inline-services (-si).
Class of service.
The following
show services stateful-firewall
show services stateful-firewall conversations
show services stateful-firewall flow-analysis
show services stateful-firewall redundancy-statistics
show services stateful-firewall sip-call
show services stateful-firewall sip-register
show services stateful-firewall subscriber-analysis
The following sections explain how to configure the components of stateful firewall
rules:
Configuring Match Direction for Stateful Firewall Rules on page 1024
Configuring Match Conditions in Stateful Firewall Rules on page 1025
Configuring Actions in Stateful Firewall Rules on page 1026
Each rule must include a
match-direction
the rule match is applied. To configure where the match is applied, include the
match-direction
statement at the
level:
[edit services stateful-firewall rule rule-name]
match-direction (input | output | input-output);
NOTE:
ACX500 Series routers do not support
.
input-output)
If you configure
match-direction input-output
might match this rule.
,
at the [
allow-ip-options
edit services stateful-firewall
CLI commands are not supported:
—Show conversations
—Show flow table entries
—Show SIP call information
—Show SIP register information
—Show subscriber table entries
statement that specifies the direction in which
[edit services stateful-firewall rule rule-name]
, sessions initiated from both directions
Copyright © 2017, Juniper Networks, Inc.
—Show redundancy statistics
hierarchy
match-direction (output |
]

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Acx5048Acx5096Acx500Acx1100Acx2000Acx2100 ... Show all

Table of Contents