Configure firewall filter to filter IPv6 packets.
|
- Click Filter next to Inet6.
- Click Add new entry next to Filter.
- Expand Filter.
- In the Name box, enter the name that
identifies the filter.
- In the Comment box, enter the comment.
- Select the Interface Specific check
box to configure interface-specific names for firewall counters.
|
Define firewall filter term.
|
- Click Term next to Accounting Profile.
- Click Add new entry next to Term.
- Expand Term.
- In the Name box, enter the name that
identifies the term.
- In the Comment box, enter the comment
for the term.
- From the Filter list, select the
name that identifies the filter.
- Expand From.
- In the Comment box, enter the comment.
- Select the Tcp Initial check box
if it matches the first TCP packet of a connection.
- Select the Tcp established check
box if it matches the TCP packets other than the first packet of a
connection.
- In the Tcp Flags box, enter the TCP
flags.
- From the listed protocol-independent match conditions,
select the filters defined for the inet family type.
The protocol-independent match conditions are Address, Destination
Address, Destination Class, Destination port, Destination prefix List,
Dscp, Forwarding Class, Fragment offset, Icmp Code, Icmp Type, Interface,
Interface Group, Interface Set, Ip Options, Loss Priority, Packet
Length, Port, prefix List, Protocol, Source Address, Source Port,
Source Prefix List, and traffic list.
- Expand Then.
- In the Comment box, enter the comment
for then.
- In the Count box, enter the number
of packets.
- Select the Log check box to store
the header information of a packet on the Routing Engine.
- Select the Syslog check box to log
an alert for the packet.
- Select the Sample check box to sample
the packet traffic.
- Select the Port Mirror check box
to port-mirror the packets.
- From the Loss Priority list, set
the packet loss priority (PLP) to low, medium-low, medium-high, or
high.
- In the Forwarding Class box, enter
the packet forwarding class name.
- From the Prefix Action list, select
the prefix specific action.
- Click Accept next to Then.
- Select one of the following:
- Accept—To accept a packet.
- Discard—To discard a packet silently, without
sending an ICMP message.
- Next—To evaluate the next term in the firewall
filter.
- Click Policer next to Then.
- Select one of the following:
- policer—To configure a new policer for
each filter and select the policer name.
- three-color-policer—To configure a tricolor
marking policer,
- Expand Three Color Policer.
- Click Single Rate next to Three Color
Policer.
- Select one of the following:
- Select single-rate if the named tricolor
policer is a single-rate policer.
- Select two-rate if the named tricolor
policer is a two-rate policer.
|