Configuring the Firewall Filter for Any Family Type (NSM Procedure)

You can specify any to filter packets based upon protocol-independent fields.

To configure firewall filter in NSM:

  1. In the NSM navigation tree, select Device Manager > Devices.
  2. Click the Device Tree tab, and then double-click the device to select it.
  3. Click the Configuration tab. In the configuration tree, expand Firewall > Family > Any.
  4. Add or modify settings as specified in Table 214.
  5. Click one:
    • OK—Saves the changes.
    • Cancel—Cancels the modifications.

Table 214: Firewall Filter Configuration Details

Task

Your Action

Configure firewall filters for protocol-independent match conditions.

  1. Expand Any.
  2. In the Comment box, enter the comment for Any.
  3. Click Filter next to Any.
  4. Click Add new entry next to Filter.
  5. In the name box, enter the name that identifies the filter.
  6. In the Comment box, enter the comment for the filter.
  7. Expand Filter.
  8. Click Term next to Filter.
  9. Click Add new entry next to Term.
  10. Expand Term.
  11. In the Name box, enter the name that identifies the term.
  12. In the Comment box, enter the comment for the term.
  13. Expand From.
  14. From the listed protocol-independent match conditions, select the filters defined for the any family type.

    The protocol-independent match conditions are Forwarding Class, Interface, Interface Set, Loss Priority, and Packet Length.

  15. Expand Then.
  16. In the Comment box, enter the comment for then.
  17. In the Count box, enter the number of packets.
  18. From the Loss Priority list, set the packet loss priority (PLP) to low, medium-low, medium-high, or high.
  19. In the Forwarding Class box, enter the packet forwarding class name.
  20. Click Accept next to Then.
  21. Select one of the following:
    • Accept—To accept a packet.
    • Discard—To discard a packet silently, without sending an ICMP message.
    • Next—To evaluate the next term in the firewall filter.
  22. Click Policer next to Then.
  23. Select one of the following:
    • policer—To configure a new policer for each filter and select the policer name.
    • three-color-policer—To configure a tricolor marking policer.
      1. Expand Three Color Policer.
      2. Click Single Rate next to Three Color Policer.
      3. Select one of the following:
        • single-rate—if the named tricolor policer is a single-rate policer.
        • two-rate—if the named tricolor policer is a two-rate policer.

Related Documentation