Navigation
Table of Contents
Guide That Contains This Content
[+] Expand All
[-] Collapse All
Configuring TCP Conditions (SRC CLI)
Use the following configuration statements to add TCP conditions to a classify-traffic condition:
policies group name list name rule name traffic-condition name tcp-condition
{tcp-flags tcp-flags ; tcp-flags-mask tcp-flags-mask ; protocol protocol ; protocol-operation protocol-operation ; ip-flags ip-flags ; ip-flags-mask ip-flags-mask ; fragment-offset fragment-offset ; packet-length packet-length ; }
Because the protocol is already set to TCP, do not change the protocol or protocol-operation options.
policies group name list name rule name traffic-condition name tcp-condition
destination-port port {port-operation port-operation ; from-port from-port ;}
policies group name list name rule name traffic-condition name tcp-condition
source-port port {port-operation port-operation ; from-port from-port ;}
To add TCP conditions to a classify-traffic condition:
- From configuration mode, enter the TCP configuration.
For example: user@host# edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition
- (Optional) Configure the value of the TCP flags field
in the IP header. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition]user@host# set tcp-flags tcp-flags
- (Optional) Configure the mask associated with TCP flags. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition]user@host# set tcp-flags-mask tcp-flags-mask
- (Optional) Configure the value of the IP flags field in
the IP header.[edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition]user@host# set ip-flags ip-flags
- (Optional) Configure the mask that is associated with
the IP flag.[edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition]user@host# set ip-flags-mask ip-flags-mask
- (Optional) Configure the value of the fragment offset
field. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition]user@host# set fragment-offset fragment-offset
- (Optional) For Junos OS filter policies, configure the
packet length on which to match. The length refers only to the IP
packet, including the packet header, and does not include any layer
2 encapsulation overhead. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition]user@host# set packet-length packet-length
- (Optional) Enter the destination port configuration for
the TCP configuration. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition]user@host# edit destination-port port
- (Optional) Configure the policy to match packets with
a port that is either equal or not equal to the specified port. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition destination-port port]user@host# set port-operation port-operation
- (Optional) Configure the destination port. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition destination-port port]user@host# set from-port from-port
- (Optional) Enter the source port configuration for the
TCP configuration. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition destination-port port]user@host# up [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition]user@host# edit source-port port
- (Optional) Configure the policy to match packets with
a port that is either equal or not equal to the specified port. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition source-port port]user@host# set port-operation port-operation
- (Optional) Configure the source port. [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition source-port port]user@host# set from-port from-port [edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition source-port port]user@host# up
- (Optional) Verify the TCP condition configuration.
[edit policies group junos list tcpCondition rule pr traffic-condition ctc tcp-condition] user@host# show tcp-flags 0; tcp-flags-mask 0; protocol tcp; protocol-operation is; ip-flags 0; ip-flags-mask 0; destination-port { port { port-operation eq; from-port service_port; } } source-port { port { port-operation eq; from-port service_port; } }