Table 379: Supported Match Conditions Applicable to IPv4 Traffic for Firewall Filters on EX
Series Switches
(continued)
Supported Platforms and Bind Points
Description
Match Condition
Egress
Ingress
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
ICMP packet type field. Typically, you specify
this match in conjunction with the
protocol
match statement to determine which
protocol is being used on the port. In place
of the numeric value, you can specify one of
the following text synonyms (the field values
are also listed):
echo-reply (0)
,
echo-request (8)
,
info-reply
(16)
,
info-request (15)
,
mask-request (17)
,
mask-reply (18)
,
parameter-problem (12)
,
redirect (5)
,
router-advertisement (9)
,
router-solicit (10)
,
source-quench (4)
,
time-exceeded (11)
,
timestamp (13)
,
timestamp-reply (14)
,
unreachable (3)
icmp-type number
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
Interface on which the packet is received.
You can specify the wildcard character (
*
)
as part of an interface name.
interface
interface-name
•
EX2200—not
supported
•
EX3200 and
EX4200—not
supported
•
EX4500—not
supported
•
EX8200—not
supported
•
EX2200—Layer 3
interfaces
•
EX3200 and
EX4200—Layer 3
interfaces
•
EX4500—Layer 3
interfaces
•
EX8200—Layer 3
interfaces
Presence of the options field in the IP
header.
ip-options
•
EX2200—not
supported
•
EX3200 and
EX4200—not
supported
•
EX4500—not
supported
•
EX8200—not
supported
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
If the packet is a trailing fragment, this
match condition does not match the first
fragment of a fragmented packet. Use two
terms to match both first and trailing
fragments.
is-fragment
3015
Copyright © 2010, Juniper Networks, Inc.
Chapter 100: Firewall Filters—Overview
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...