Table 379: Supported Match Conditions Applicable to IPv4 Traffic for Firewall Filters on EX
Series Switches
(continued)
Supported Platforms and Bind Points
Description
Match Condition
Egress
Ingress
•
EX2200—ports and
VLANs
•
EX3200 and
EX4200—ports and
VLANs
•
EX4500—ports and
VLANs
•
EX8200—ports and
VLANs
•
EX2200—ports and
VLANs
•
EX3200 and
EX4200—ports and
VLANs
•
EX4500—ports and
VLANs
•
EX8200—ports and
VLANs
Source MAC address.
You can define a source MAC address with
a prefix, such as
from
destination-mac-address
00:01:02:03:04:05/24
. If no prefix is
specified, the default value is taken as 48.
source-mac-address
mac-address
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
TCP or UDP
source-port
field. Typically, you
specify this match in conjunction with the
protocol
match statement to determine
which protocol is being used on the port. In
place of the numeric field, you can specify
one of the text synonyms listed under
destination-port
.
source-port number
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
IP source prefix list field.
You can define a list of IP address prefixes
under a prefix-list alias for frequent use. You
make this definition at the
[edit
policy-options]
hierarchy level.
source-prefix-list
prefix-list
•
EX2200—not
supported
•
EX3200 and
EX4200—not
supported
•
EX4500—not
supported
•
EX8200—not
supported
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
TCP packets of an established TCP
connection. This condition matches packets
other than the first packet of a connection.
tcp-established
is a synonym for the bit
names
"(ack | rst)"
.
tcp-established
does not implicitly check
whether the protocol is TCP. To do so,
specify the
protocol tcp
match condition.
tcp-established
3017
Copyright © 2010, Juniper Networks, Inc.
Chapter 100: Firewall Filters—Overview
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...