Example: Subscriber Secure Policy Dynamic Profile
In this example, subscriber secure policy mirroring is configured for subscriber access using user-defined variables and JUNOS predefined variables. This example is for the flow-tap service configured on a router without a Tunnel Services PIC.
The user-defined variables equate to RADIUS settings as follows:
- variables {
- var ssp-intercept-id;
- var ssp-destination-addr;
- var ssp-destination-port;
- }
-
- interfaces {
-
- <*> {
-
- unit <*> {
-
- family inet {
-
- filter {
- input ssp;
- output ssp;
- }
- }
- }
- }
- }
-
- firewall {
-
- family inet {
-
- filter ssp {
-
- term $ssp-id {
-
- from {
- # optional classifiers.
- }
-
- then {
- flowtap-destination-address $ssp-destination-addr;
- flowtap-destination-port $ssp-destination-port;
- flowtap;
- }
- }
- }
- }
- }
