Routers - Juniper ACX1000 Configuration Manual

Junos os; acx series universal access router
Hide thumbs Also See for ACX1000:
Table of Contents

Advertisement

Table 73: Standard Firewall Filter Match Conditions for IPv4 Traffic on ACX Series
Routers (continued)
Match Condition
tcp-flags value
tcp-initial
ttl number
Related
Documentation
Standard Firewall Filter Match Conditions for IPv6 Traffic on ACX Series Routers
Copyright © 2017, Juniper Networks, Inc.
Description
Match one or more of the low-order 6 bits in the 8-bit TCP flags field in the TCP header.
To specify individual bit fields, you can specify the following text synonyms or hexadecimal
values:
(0x01)
fin
syn
(0x02)
rst
(0x04)
(0x08)
push
(0x10)
ack
(0x20)
urgent
In a TCP session, the SYN flag is set only in the initial packet sent, while the ACK flag is set in
all packets sent after the initial packet.
You can string together multiple flags using the bit-field logical operators.
For combined bit-field match conditions, see the
If you configure this match condition, we recommend that you also configure the
match statement in the same term to specify that the TCP protocol is being used on the port.
Match the initial packet of a TCP connection. This is an alias for
This condition does not implicitly check that the protocol is TCP. If you configure this match
condition, we recommend that you also configure the
term.
Match the IPv4 time-to-live number. Specify a TTL value or a range of TTL values. For
you can specify one or more values from 2 through 255.
Guidelines for Configuring Firewall Filters on page 1044
Standard Firewall Filter Match Conditions and Actions on ACX Series Routers Overview
on page 1052
Standard Firewall Filter Terminating Actions on ACX Series Routers on page 1063
Standard Firewall Filter Nonterminating Actions on ACX Series Routers on page 1064
You can configure a firewall filter with match conditions for Internet Protocol version 6
(IPv6) traffic (
).
family inet6
configure at the
[edit firewall family inet6 filter filter-name term term-name from]
level.
tcp-initial
protocol tcp
Table 74 on page 1058
describes the match conditions you can
Chapter 32: Configuring Firewall Filters
match conditions.
protocol tcp
.
tcp-flags "(!ack & syn)"
match condition in the same
number
hierarchy
,
1057

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Acx5048Acx5096Acx500Acx1100Acx2000Acx2100 ... Show all

Table of Contents