Table 379: Supported Match Conditions Applicable to IPv4 Traffic for Firewall Filters on EX
Series Switches
(continued)
Supported Platforms and Bind Points
Description
Match Condition
Egress
Ingress
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports and
VLANs
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports and
VLANs
Differentiated Services code point (DSCP).
The DiffServ protocol uses the
type-of-service (ToS) byte in the IP header.
The most significant six bits of this byte form
the DSCP.
You can specify DSCP in hexadecimal,
binary, or decimal form.
In place of the numeric value, you can
specify one of the following text synonyms
(the field values are also listed):
•
ef (46)
—as defined in
RFC 2598
,
An
Expedited Forwarding PHB
.
•
af11 (10)
,
af12 (12)
,
af13 (14)
;
af21 (18)
,
af22 (20)
,
af23 (22)
;
af31 (26)
,
af32 (28)
,
af33 (30)
;
af41 (34)
,
af42 (36)
,
af43 (38)
These four classes, with three drop
precedences in each class, for a total of
12 code points, are defined in
RFC 2597
,
Assured Forwarding PHB
.
dscp number
•
EX2200—ports and
VLANs
•
EX3200 and
EX4200—ports and
VLANs
•
EX4500—ports and
VLANs
•
EX8200—not
supported.
•
EX2200—ports and
VLANs
•
EX3200 and
EX4200—ports and
VLANs
•
EX4500—ports and
VLANs
•
EX8200—ports and
VLANs
Ethernet type field of a packet. The
EtherType value
specifies what protocol is
being transported in the Ethernet frame. In
place of the numeric value, you can specify
one of the following text synonyms:
•
aarp
—EtherType value AARP (0x80F3)
•
appletalk
—EtherType value AppleTalk
(0x809B)
•
arp
—EtherType value ARP (0x0806)
•
ipv4
—EtherType value IPv4 (0x0800)
•
ipv6
—EtherType value IPv6 (0x08DD)
•
mpls multicast
—EtherType value MPLS
multicast (0x8848)
•
mpls unicast
—EtherType value MPLS
unicast (0x8847)
•
oam
—EtherType value OAM (0x88A8)
•
ppp
—EtherType value PPP (0x880B)
•
pppoe-discovery
—EtherType value
PPPoE Discovery Stage (0x8863)
•
pppoe-session
—EtherType value PPPoE
Session Stage (0x8864)
•
sna
—EtherType value SNA (0x80D5)
ether-type [aarp |
appletalk | arp | ipv4 |
ipv6 | mpls—multicast
| mpls-unicast | oam |
ppp | pppoe-discovery
| pppoe-session | sna
|value]
3013
Copyright © 2010, Juniper Networks, Inc.
Chapter 100: Firewall Filters—Overview
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...