Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


Configuring Stateful Firewall Actions (SRC CLI)


You can configure stateful firewall actions for Junos OS ASP policy rules. Stateful firewall actions specify the action to take on packets that match the classify-traffic condition.

The type of action that you can create depends on the type of policy rule. See Policy Information Model.

Use the following configuration statements to configure stateful firewall actions:

To configure a stateful firewall action:

  1. From configuration mode, enter the stateful firewall action configuration.

  2. (Optional) Set the action to take on a packet to one of the following:

    • Filter.

    • Forward.

    • Reject. If you set the action to reject, configure the type of ICMP destination unreachable message sent to the client.

    • Parameter. Before you assign a parameter, you must create a parameter of type packetOperation and commit the parameter configuration.

  3. (Optional) Enter a description for the stateful firewall action.

  4. (Optional) Verify the stateful firewall action configuration.