Juniper ACX1000 Configuration Manual page 1140

Junos os; acx series universal access router
Hide thumbs Also See for ACX1000:
Table of Contents

Advertisement

ACX Series Universal Access Router Configuration Guide
1082
a firewall or other security device before the traffic continues on its path. To configure a
stateless firewall filter to direct traffic to a routing instance, configure a term with the
routing-instance routing-instance-name
hierarchy level to specify the routing instance to which matching packets will
| inet6>]
be forwarded. You can apply a forwarding table filter to a routing instance of type
forwarding and also to the default routing instance
traffic to the master routing instance, use the
[edit firewall family <inet | inet6>]
The following limitations apply to filter-based forwarding table configured on routing
instances:
You cannot configure any of the following actions in a firewall filtering term when the
filtering term contains the
count counter-name
discard
forwarding-class class-name
log
loss-priority (high | medium-high | low)
policer policer-name
port-mirror
reject message-type
syslog
three-color-policer (single-rate | two-rate) policer-name
You cannot configure the
You cannot attach a filter that is either default or physical interface-specific.
You cannot attach a filter to the egress direction of routing instances.
IPv6 filter-based forwarding does not support the following L4 matches:
source-port
destination-port
icmp-type
icmp-code
Although you can configure forwarding of packets from one VRF to another VRF, you
cannot configure forwarding from a VRF to the global routing instance.
The maximum number of routing instances supported is 64, which is the same as the
maximum number of virtual routers supported. Forwarding packets to the global table
(default VRF) is not supported for filter-based forwarding.
terminating action at the
inet.0
routing-instance default
hierarchy level.
routing-instance routing-instance-name
fragment-flags number
match condition in the filter term.
[edit firewall family <inet
. To configure the filter to direct
statement at the
terminating action:
Copyright © 2017, Juniper Networks, Inc.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Acx5048Acx5096Acx500Acx1100Acx2000Acx2100 ... Show all

Table of Contents