Service Set Configuration Guidelines
A service set is a collection of services to be performed by an Adaptive Services (AS) or Multiservices PIC. To configure service sets, include the following statements at the [edit services] hierarchy level:
[edit services]service-set service-set-name {(ids-rules rule-names | ids-rule-sets rule-set-name);(ipsec-vpn-rules rule-names | ipsec-vpn-rule-sets rule-set-name);(nat-rules rule-names | nat-rule-sets rule-set-name);(pgcp-rules rule-names | pgcp-rule-sets rule-set-name);(ptsp-rules rule-names | ptsp-rule-sets rule-set-name); (stateful-firewall-rules rule-names | stateful-firewall-rule-sets rule-set-name);allow-multicast;extension-service service-name {provider-specific rules;}interface-service {service-interface interface-name;}ipsec-vpn-options {anti-replay-window-size bits;clear-dont-fragment-bit;ike-access-profile profile-name;local-gateway address;no-anti-replay;passive-mode-tunneling;trusted-ca [ ca-profile-names ];tunnel-mtu bytes;}max-flows number;next-hop-service {inside-service-interface interface-name.unit-number;outside-service-interface interface-name.unit-number;service-interface-pool name;}syslog {host hostname {services severity-level;facility-override facility-name;log-prefix prefix-value;}}}adaptive-services-pics {traceoptions {file filename <files number> <match regex> <size size> <(world-readable | no-world-readable)>;flag flag;}}logging {traceoptions {file filename <files number> <match regex> <size size> <(world-readable | no-world-readable)>;flag flag;}}
This chapter contains the following sections:
- Configuring Service Sets to be Applied to Services Interfaces
- Configuring Service Rules
- Configuring IPsec Service Sets
- Configuring Service Set Limitations
- Configuring System Logging for Service Sets
- Enabling Services PICs to Accept Multicast Traffic
- Tracing Services PIC Operations
- Example: Configuring Service Sets
Hide Navigation Pane
Show Navigation Pane
Download
SHA1