Firewall Filter Match Conditions for Protocol-Independent Traffic in Dynamic Service Profiles
You configure firewall filter match conditions to determine
which packets are filtered. Starting in Junos OS Release 16.1, you can configure match conditions
that are supported for protocol-independent traffic—that is,
configured under family any
—for filters in dynamic
service profiles. Table 1 describes
these match conditions.
Protocol-independent firewall filters in dynamic service profiles are supported only on MX Series routers with MPCs.
Match Condition |
Description |
---|---|
|
Match the forwarding class of the packet. Specify For information about forwarding classes and router-internal output queues, see Understanding How Forwarding Classes Assign Classes to Output Queues. |
|
Do not match on the forwarding class. For details, see
the |
|
Match the packet loss priority (PLP) level. Specify a single level or multiple levels: For information about the |
|
Do not match the PLP level. For details, see the |
|
Match the length of the received packet, in bytes. The length refers only to the IP packet, including the packet header, and does not include any Layer 2 encapsulation overhead. |
|
Do not match on the received packet length, in bytes.
For details, see the |
|
(Only if the Indicate to subsequent filters in the chain that the packet
was already processed. This match option, coupled with the |
family any
—for filters in dynamic
service profiles.