Table 81: Firewall Filter Match Conditions for VPLS Traffic (continued)
Description
Match Condition
Starting in Junos OS 14.2, flexible offset filters
are supported in firewall hierarchy
configurations.
Length of the data to be matched in bits, not
needed for string input (0..128)
bit-lengthflexible-match-mask value
Bit offset after the (match-start + byte) offset
(0..7)
bit-offset
Byte offset after the match start pointbyte-offset
Select a flexible match from predefined
template field
flexible-mask-name
Mask out bits in the packet data to be matchedmask-in-hex
Start point to match in packetmatch-start
Value data/string to be matchedprefix
Length of the data to be matched in bits (0..32)bit-lengthflexible-match-range value
Bit offset after the (match-start + byte) offset
(0..7)
bit-offset
Byte offset after the match start pointbyte-offset
Select a flexible match from predefined
template field
flexible-range-name
Start point to match in packetmatch-start
Range of values to be matchedrange
Do not match this range of valuesrange-except
Match the forwarding class. Specify assured-forwarding, best-effort, expedited-forwarding, or
network-control.
forwarding-class class
Do not match the forwarding class. For details, see the forwarding-class match condition.forwarding-class-except
class
1073Copyright © 2017, Juniper Networks, Inc.
Chapter 32: Configuring Firewall Filters