To create a firewall exception for a subscriber:
The Create Exception dialog box appears. Figure 28 shows the appearance of the dialog box when Enterprise Manager Portal is set to Advanced mode.
Figure 28: Create Exception Dialog Box for Stateless Firewalls

See Fields for Exceptions to Stateless Firewalls in Enterprise Manager Portal.
Which protocols you select determines which associated protocol fields are available for editing.
![]() |
Note: If a user changes the value for a protocol when the configuration level for the portal is set to Normal mode, values for the following fields may be deleted: TCP Flags, Fragmentation Flags, Fragmentation Offset, Packet Length, ICMP Type, and ICMP Code. If the value of a protocol is changed to the original setting, the portal restores the associated field values that were previously removed. |
The Firewall page shows the exception configured. Figure 29 shows three exceptions configured for a brickwall firewall service. The exceptions appear in priority order.
Figure 29: Firewall Page with Firewall Service Applied and Exceptions Configured

Use the fields in this topic to configure rules for exceptions to stateless firewalls.
Rule Name
IP Protocols
ToS Byte
Use an x to indicate a bit to be ignored.
Specify the ToS byte in this field if you want to specify a specific type of service. If you want to specify all types of service, leave this field empty.
Source IP Addresses
Source Ports
Destination IP Addresses
For information about how JUNOS routing platforms evaluate prefixes, see the JUNOS Policy Framework Configuration Guide.
Destination Ports
TCP Flags
You can enter a logical expression that contains the symbols for the six TCP flags: urgent, ack, push, rst, syn, and fin. You can use the following logical operators in the list of flags:
You can use the following expression instead of the entire expression:
The interface displays text synonyms for expressions if stored data matches the expression.
This field appears enabled only if the configuration level is set to Advanced. Although the value can be changed when the configuration level is set to Normal, we recommend that the value of this field not be changed if the field appears disabled.
Fragmentation Flags
Fragment Offset
Packet Length
ICMP Type
The following list shows the symbolic name and associated numbers for ICMP types. The ICMP types are the same as those on JUNOS routing platforms with the addition of traceroute.
This field appears enabled only if the configuration level is set to Advanced. Although the value can be changed when the configuration level is set to Normal, we recommend that the value of this field not be changed if the field appears disabled.
ICMP Code
This field appears enabled only if the configuration level is set to Advanced. Although the value can be changed when the configuration level is set to Normal, we recommend that the value of this field not be changed if the field appears disabled.
Priority
Direction
Action
Enabled