Define the service set.
|
- Click Add new entry next
to Service Set.
- In the Name box, enter the
name that identifies the service set.
- In the Comment box, enter
the comment.
- In the Max Flows box, enter
the maximum number of flows.
- From the Tcp Mss list, select
the TCP Maximum Segment Size (MSS) allowed for the service set.
Range: 536 to 65535
- From the Application Identification
Profile list, select the application identification method.
- From the Idp Profile list,
select the Idp profile.
Note:
The IDP profile is a list of IDP policies as defined
in the Security > Idp > Idp policy assigned to
this device.
|
Configuring AACL rule and AACL
rule set.
|
- Click Aacl Rules next
to service-set.
- Select one of the following:
- aacl-rules—To specify the rule
the router uses when applying this service.
- aacl-rule-set—To specify the
rule set the router uses when applying this service.
- Click Add new entry.
- From the Name list, select
the identifier for the collection of terms that constitute this rule
set.
- In the Comment box, enter
the comment.
|
Allow multicast traffic to be sent
to the Adaptive Services or Multiservices PIC.
|
- Click Allow Multicast next
to service-set.
- In the Comment box, enter
the comment.
|
Specify the Class of Service (CoS)
service rule or rule set included in this service.
|
- Click Cos Rules next to service-set.
- Select one of the following:
- cos-rules—To specify cos-rules.
- cos-rule-set—To specify cos-rules
set.
- Click Add new entry.
- From the Name list, select the rule
or rule set name.
|
Define JUNOS SDK service set.
|
- Click Extension Service next to service-set.
- Click Add new entry next to
Extension Service.
- In the Name box, enter the
identifier for a provider-specific service.
- In the Comment box, enter
the comment.
|
Specify the intrusion detection
service (IDS) rules or rule set included in this service set.
|
- Click Ids Rules next to service-set.
- Select one of the following:
- ids—rules—To specify
the ids rules.
- ids-rule-sets—To specify the
ids-rule-sets.
- Click Add new entry.
- From the Name list, select the rule
or rule set name.
|
Specify the device name for the
interface service PIC.
|
- Click Interface Service next to service-set.
- Select one of the following:
- interface-service—To specify
the device name for the interface service Physical Interface Card.
- In the Comment box, enter the comment.
- In the Services Interface box, enter
the name of the service device associated with the interface-wide
service set.
- next-hop-service—To specify
interface names or a service interface pool for the forwarding next-hop
service set. You cannot specify both a service interface pool and
an inside or outside interface.
- In the Comment box, enter the comment.
- In the Inside Service Interface box,
enter the name and logical unit number of the service interface associated
with the service set applied inside the network.
- In the Outside Service Interface box,
enter the name and logical unit number of the service interface associated
with the service set applied outside the network
- From the Service Interface Pool list,
select the name of the pool of logical interfaces.
|
Specify the Network Address Translation
(NAT) rules or rule set included in this service set.
|
- Click Nat Rules next to service-set.
- Select one of the following:
- nat-rules—To specify the NAT
rules included in this service set.
- nat-rule-sets—To specify the
NAT rule set included in this service set.
- Click Add new entry.
- From the Name list, select the rule
or rule set name.
- In the Comment box, enter the comment.
|
Specify the Packet Gateway Control
Protocol (PGCP) rules or rule set included in this service set.
|
- Click Pgcp Rules next to service-set.
- Select one of the following:
- pgcp-rules—To specify the pgcp
rules included in this service set.
- pgcp-rule-set—To specify the
pgcp rule set included in this service set.
- Click Add new entry.
- From the Name list, select the rule
or rule set name.
- In the Comment box, enter the comment.
|
Configuring the policy decision
statistics profile.
|
- Click Policy Decision Statistics
Profile next to service-set.
- In the Comment box, enter
the comment.
- From the Profile Name list,
select the policy decision statistics profile.
|
Define the order in which services
are applied for this service set.
|
- Click Service Order next to service-set.
- In the Comment box, enter the comment.
- Click Forward Flow next to Service
Order.
- Click Add new entry next to Forward
Flow.
- In the New forward-flow window, enter
the service order for forward flow.
- Click Reverse Flow next to Service
Order.
- Click Add new entry next to Reverse
Flow.
- In the New reverse-flow window, enter
the service order for reverse flow.
|
Specify the stateful firewall rules
or rule set included in this service set.
|
- Click Stateful Firewall Rules next
to service-set.
- Select one of the following:
- stateful-firewall-rules—To
specify the stateful firewall rules.
- stateful-firewall-rule-sets—To
specify the stateful firewall rule set.
- Click Add new entry.
- From the Name list, select the rule
or rule set name.
- In the Comment box, enter the comment.
|
Configure generation of system
log messages for the service set.
|
- Click Syslog next to service-set.
- In the Comment box, enter the comment.
- Click Host next to Syslog.
- Click Add new entry next to Host.
- In the Name box, enter the name of the system
logging utility host machine.
- In the Comment box, enter the comment.
- From the Facility Override list,
select the name of the facility that overrides the default assignment.
- In the Log Prefix box, enter the
system logging prefix value.
- Click Contents next to host.
- From the Name list, select the service
set.
- In the Comment box, enter the comment.
- From the Any list, select the system
logging severity level.
|