user@switch#
set family inet filter egress-router-corp-class term corp-expedite
then
forwarding-class expedited-forwarding
user@switch#
set family inet filter egress-router-corp-class term corp-expedite then
loss-priority low
3.
Define the term
not-to-corp
:
[edit firewall]
user@switch#
set family inet filter egress-router-corp-class term not-to-corp then
accept
4.
Apply the firewall filter
egress-router-corp-class
as an output filter for the port on
the switch's uplink module, which provides a Layer 3 connection to a router:
[edit interfaces]
user@switch#
set ge-0/1/0
description
"filter at egress router to expedite employee
traffic destined for corporate network"
user@switch#
set ge-0/1/0
unit
0 family inet address 103.104.105.1
user@switch#
set ge-0/1/0 unit 0 family inet filter output egress-router-corp-class
Results
Display the results of the configuration:
user@switch# show
firewall {
family inet {
filter egress-router-corp-class {
term corp-expedite {
from {
destination-address 192.0.2.16/28;
}
then {
forwarding-class expedited-forwarding;
loss-priority low;
}
}
term not-to-corp {
then {
accept;
}
}
}
}
}
interfaces {
ge-0/1/0 {
unit 0 {
description "filter at egress router interface to expedite employee traffic destined
for corporate network";
family inet {
source-address 103.104.105.1
filter {
output egress-router-corp-class;
}
}
}
}
}
3055
Copyright © 2010, Juniper Networks, Inc.
Chapter 101: Examples of Firewall Filters Configuration
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...