Table 379: Supported Match Conditions Applicable to IPv4 Traffic for Firewall Filters on EX
Series Switches
(continued)
Supported Platforms and Bind Points
Description
Match Condition
Egress
Ingress
•
EX2200—not
supported
•
EX3200 and
EX4200—not
supported
•
EX4500—not
supported
•
EX8200—not
supported
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
One or more TCP flags:
•
bit-name—
fin
,
syn
,
rst
,
push
,
ack
,
urgent
•
logical operators—
&
(logical AND),
|
(logical OR),
!
(negation)
•
numerical value—0x01 through 0x20
•
text synonym—
tcp-initial
To specify multiple flags, use logical
operators.
tcp-flags [flags
tcp-initial]
•
EX2200—not
supported
•
EX3200 and
EX4200—not
supported
•
EX4500—not
supported
•
EX8200—not
supported
•
EX2200—ports, VLANs,
and Layer 3 interfaces
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—ports, VLANs,
and Layer 3 interfaces
•
EX8200—ports, VLANs,
and Layer 3 interfaces
Match the first TCP packet of a connection.
tcp-initial
is a synonym for the bit names
"(syn & !ack)"
.
tcp-initial
does not implicitly check whether
the protocol is TCP. To do so, specify the
protocol tcp
match condition.
tcp-initial
•
EX2200—not
supported
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—not
supported
•
EX8200—not
supported
•
EX2200—not
supported
•
EX3200 and
EX4200—ports, VLANs,
and Layer 3 interfaces
•
EX4500—not
supported
•
EX8200—not
supported
Differentiated Services code point (DSCP).
The DiffServ protocol uses the
type-of-service (ToS) byte in the IP header.
The most significant six bits of this byte form
the DSCP.
You can specify DSCP in hexadecimal,
binary, or decimal form.
In place of the numeric value, you can
specify one of the following text synonyms
(the field values are also listed):
•
ef (46)
—as defined in
RFC 2598
,
An
Expedited Forwarding PHB
.
•
af11 (10)
,
af12 (12)
,
af13 (14)
;
af21 (18)
,
af22 (20)
,
af23 (22)
;
af31 (26)
,
af32 (28)
,
af33 (30)
;
af41 (34)
,
af42 (36)
,
af43 (38)
These four classes, with three drop
precedences in each class, for a total of
12 code points, are defined in
RFC 2597
,
Assured Forwarding PHB
.
traffic-class
Copyright © 2010, Juniper Networks, Inc.
3018
Complete Software Guide for Junos
®
OS for EX Series Ethernet Switches, Release 10.3
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...