Configuring Firewall Filters On Shared Interfaces - Juniper JUNOS OS 10.4 - PROTECTED SYSTEM DOMAIN Configuration Manual

Protected system domain configuration
Table of Contents

Advertisement

JUNOS 10.4 Protected System Domain Configuration Guide
Related
Documentation

Configuring Firewall Filters on Shared Interfaces

102
}
}
Shared Interfaces on page 5
Before You Configure Shared Interfaces on page 94
Interfaces Hierarchy on page 93
Configuring Shared Interfaces on the RSD on page 95
Example: Configuring Shared Interfaces (SONET) on page 136
Example: Configuring Shared Interfaces (Ethernet) on page 147
To allow equitable bandwidth sharing between all logical interfaces on a single shared
physical interface, you configure firewall filters on the logical interfaces in the PSD
configuration.
Whereas the RSD controls the physical shared interface and allocates a logical interface
on it to the PSD, the PSD controls the configuration under the logical interface, including
the protocol family. The shared interface on the RSD is not aware of the protocol family
information associated with the logical interface. Therefore, on the PSD, the firewall filter
must be configured under the
to the entire logical interface (as opposed to a protocol family under the interface). With
Junos OS Release 9.4, only output filters are supported.
To configure a firewall filter on the PSD, create the filter conditions and apply the filter
to the logical interfaces:
Configure the firewall filter conditions:
1.
a. Include the
filter filter-name
level.
b. Include the
term term-name
hierarchy level.
filter-name]
c. Include the
from match-conditions
filter-name term term-name]
d. Include the
then action
hierarchy level.
term term-name]
e. Include the
then action-modifiers
filter-name term term-name]
Apply the firewall filter to the logical interface on the shared interface by including
2.
the
filter output filter-name
hierarchy level.
logical-unit-number]
hierarchy level and the filter applied
[edit firewall family any]
statement at the
[edit firewall family any]
statement at the
[edit firewall family any filter
statement at the
hierarchy level.
statement at the
[edit firewall family any filter filter-name
statement at the
hierarchy level.
statement at the
[edit interfaces interface-name unit
Copyright © 2010, Juniper Networks, Inc.
hierarchy
[edit firewall family any filter
[edit firewall family any filter

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents