Table 345: Match Conditions
(continued)
Description
Option
Tag value in the dot1q header, in the range
0
through
4095
.
source-dot1q-tag tag
Address of the final destination node.
destination-ip ip-address
IPv4 protocol value. In place of the numeric value, you can specify one of the
following text synonyms:
ah
,
egp (8)
,
esp (50
,
gre (47)
,
icmp (1)
,
igmp (2)
,
ipip (4)
,
ipv6 (41)
,
ospf (89)
,
pim (103)
,
rsvp (46)
,
tcp (6)
, or
udp (17)
ip-protocol protocol-id
TCP or User Datagram Protocol (UDP) source port field. Normally, you specify
this match statement in conjunction with the
ip-protocol
match statement
to determine which protocol is being used on the port. In place of the numeric
field, you can specify one of the text options listed under
destination-port
.
source-port port
TCP or UDP destination port field. Normally, you specify this match in
conjunction with the
ip-protocol
match statement to determine which protocol
is being used on the port. In place of the numeric value, you can specify one
of the following text synonyms (the port numbers are also listed):
afs (1483)
,
bgp (179)
,
biff (512)
,
bootpc (68)
,
bootps (67)
,
cvspserver (2401)
,
cmd (514)
,
dhcp (67)
,
domain (53)
,
eklogin (2105)
,
ekshell (2106)
,
exec (512)
,
finger (79)
,
ftp (21)
,
ftp-data (20)
,
http (80)
,
https (443)
,
ident (113)
,
imap
(143)
,
kerberos-sec (88)
,
klogin (543)
,
kpasswd (761)
,
krb-prop (754)
,
krbupdate (760)
,
kshell (544)
,
ldap (389)
,
login (513)
,
mobileip-agent (434)
,
mobilip-mn (435)
,
msdp (639)
,
netbios-dgm (138)
,
netbios-ns (137)
,
netbios-ssn (139)
,
nfsd (2049)
,
nntp (119)
,
ntalk (518)
,
ntp (123)
,
pop3 (110)
,
pptp (1723)
,
printer (515)
,
radacct (1813)
,
radius (1812)
,
rip (520)
,
rkinit (2108)
,
smtp (25)
,
snmp (161)
,
snmptrap (162)
,
snpp (444)
,
socks (1080)
,
ssh (22)
,
sunrpc (111)
,
syslog (514)
,
telnet (23)
,
tacacs-ds (65)
,
talk (517)
,
tftp (69)
,
timed (525)
,
who (513)
,
xdmcp (177)
,
zephyr-clt (2103)
,
zephyr-hm (2104)
destination-port port
When you define one or more terms that specify the filtering criteria, you also define the
action to take if the packet matches all criteria. Table 346 on page 2627 shows the actions
that you can specify in a term.
Table 346: Actions for VSAs
Description
Option
Accept a packet or discard a packet silently without sending an Internet Control
Message Protocol (ICMP) message.
(
allow
|
deny
)
(Optional) Classify the packet in one of the following forwarding classes:
•
assured-forwarding
•
best-effort
•
expedited-forwarding
•
network-control
forwarding-class class-of-service
2627
Copyright © 2010, Juniper Networks, Inc.
Chapter 83: Configuring Access Control
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...