Related
Documentation
Firewall Filter Configuration Statements Supported by Junos OS for EX Series Switches
on page 3090
•
•
Example: Configuring Firewall Filters for Port, VLAN, and Router Traffic on EX Series
Switches on page 3039
•
Example: Using Filter-Based Forwarding to Route Application Traffic to a Security
Device on EX Series Switches on page 3058
•
Understanding Firewall Filter Match Conditions on page 3032
•
Understanding How Firewall Filters Are Evaluated on page 3030
•
Understanding How Firewall Filters Test a Packet's Protocol on page 3036
•
Understanding the Use of Policers in Firewall Filters on page 3036
•
Understanding Filter-Based Forwarding for EX Series Switches on page 3037
Understanding How Firewall Filters Are Evaluated
A firewall filter consists of one or more terms, and the order of the terms within a firewall
filter is important. Before you configure firewall filters, you should understand how Juniper
Networks EX Series Ethernet Switches evaluate the terms within a firewall filter and how
packets are evaluated against the terms.
When a firewall filter consists of a single term, the filter is evaluated as follows:
•
If the packet matches all the conditions, the action in the
then
statement is taken.
•
If the packet matches all the conditions, and no action is specified in the
then
statement,
the default action
accept
is taken.
When a firewall filter consists of more than one term, the firewall filter is evaluated
sequentially:
1.
The packet is evaluated against the conditions in the
from
statement in the first term.
2.
If the packet matches all the conditions in the term, the action in the
then
statement
is taken and the evaluation ends. Subsequent terms in the filter are not evaluated.
3.
If the packet does not match all the conditions in the term, the packet is evaluated
against the conditions in the
from
statement in the second term.
This process continues until either the packet matches the conditions in the
from
statement in one of the subsequent terms or there are no more terms in the filter.
4.
If a packet passes through all the terms in the filter without a match, the packet is
discarded.
Figure 78 on page 3031 shows how an EX Series switch evaluates the terms within a firewall
filter.
Copyright © 2010, Juniper Networks, Inc.
3030
Complete Software Guide for Junos
®
OS for EX Series Ethernet Switches, Release 10.3
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...